3 ms·
On the one hand, eIDAS (the e-signature part) is definitely a good thing as it will replace a lot of weak national signature laws with something modestly safe.
by cleeus 10y ago
On the one hand, eIDAS (the e-signature part) is definitely a good thing as it will replace a lot of weak national signature laws with something modestly safe. On the other hand it will also replace strict signature laws (e.g. german) with something much weaker.
In the core of e-signatures is the so called human-machine transfer (Schneiers term). A human expresses his legal declaration of intent through a machine.
In germany this required a (certified) qualified signature unit and software which de-facto meant
certified smartcard from certified trustcenter with secure pin entry (on the card-reader, not the computer).
According to eIDAS this can be replaced with much more weaker forms like server-side keys and signature after 2FA.
And this is where folks from DocuSign (and others) will come in and place cryptographic signature on documents exchange for username+password+click (maybe with 2FA, I doubt that).
So you formerly needed smartcard (possession) with PIN (knowledge).
Now you may only need username+password (knowledge) and maybe a second factor like mobile phone.
I doubt that having control over a smartphone is on the same security level as control over a class 2/class 3 smartcard reader.
- hvidgaard 10y agoThat is the my main issue with EU law making. They're aiming low to get everyone onboard, but countries that have already laws like that are likely to be overruled to something less. It's great for creating a united marked withing EU, but I just wish they would aim higher. Why settle for less when state of the art already exists and is widely used.
- Loic 10y agoeIDAS has different levels of trust and a service (from a country or company) can require a high level of trust to perform an operation, for example using a smartcard. For German speaking people, you have some pretty well put together documentation on the new eIDAS directives here: https://www.bsi.bund.de/DE/Themen/DigitaleGesellschaft/eIDAS/eIDAS_node.html https://www.bsi.bund.de/DE/Themen/DigitaleGesellschaft/eIDAS...
- cleeus 10y agoI didn't read anything about the notion of trust levels in the directives text. Can you point me to the law? As far as I can see, any signature that is/appears to be qualified (regardless how it came to life) is considered equal to a signature under notary oversight (at least in germany) and shifts the burden of proof. This is heavy!
- pkzip 10y agoeIDAS is not downgrading signature laws with weaker technology - it merely allows more "flavors" of technology to participate in the e-signature market which has been stalling in EU due to the eSign directive from 1999. eIDAS will allow for more companies to go paperless because most signatures do not require security level of smart card backed qualified electronic signature (QES) - so in those instances DocuSign approach with username/password would be sufficient. For the transactions that require high level of trust (think notarized) QES from eID will still be needed e.g. at least one startup (Crayonic.com) is trying to make eIDAS QES as usable while making it more secure.