Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

1–10 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#3
From:

https://data.consilium.europa.eu/doc/document/ST-14959-2022-...

Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services."

Article 45a(3): "A qualified electronic attestation of attributes issued in one Member State shall be recognised as a qualified electronic attestation of attributes in any other Member State".

Article 45a(4): "An attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be recognised as an attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in all Member States."

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#4

From: https://data.consilium.europa.eu/doc/document/ST-14959-2022-... Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certific…

[deleted]

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#6
India is also preparing legislation for OS and browser having their CA, they also launched their own web browser challenge https://iwbdc.in/ .They were earlier removed due to unauthorised issuances https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-cert...

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#8
There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security.

For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a risk.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#9
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked.

This is still very bad.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#10
post #7

I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?

Western security services are what we call secret police in other parts of the world. Its goal is to protect the local status quo. That's it, and thats why it can assert so much influence.
Post reply on HN