4 ms·
I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mo
by Jwarder 5y ago
I see two issues at play.
Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc).
There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a fancy logo makes the site any safer.
- kjetil 5y agoAre the TSP audit requirements less strict than what the browsers’ root programs require?
- Jwarder 5y agoMozilla says so. https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPBzavyQ/view?usp=sharing https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB... I can't speak with authority, but my reading of PKI issues suggests Google is just as strict, while Microsoft and Apple are less strict. However, that just might be because MS and Apple are less public with their root programs.
- Jensson 5y ago> Not all European CAs meet browsers' root programs requirements. That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.
- Jwarder 5y agoI think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal PKI to the root store.
- Jensson 5y agoTrust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.
- Jwarder 5y agoMozilla has identified issues with CAs that are part of eIDAS. The severity of these issues can be debated, but the nice part of Mozilla's root program is that these are publicly debated. For example, the community identified repeated issues with the CA Certinomis and after failures to improve they were distrusted. Is it a good thing that the EU says that doesn't matter and Certinomis certs must be trusted as part of eIDAS? https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPBzavyQ/view?usp=sharing https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB... https://wiki.mozilla.org/CA/Certinomis_Issues https://wiki.mozilla.org/CA/Certinomis_Issues
- syrrim 5y agoMozilla argues in their paper that once governments in one part of the world start forcing browsers include root certificates, governments in other parts of the world will start doing the same shortly after. You might trust your government more, but you certainly wouldn't trust arbitrary governments more. Furthermore, I have seen nothing wrong in mozilla's stewardship of the root certificate program in the decades it's been running, whereas mozilla points to deficiencies in the EU's certificate programs. This is to be expected since running a root store is not one of the EU's specialties. I would trust that government most that defers to private companies in areas where they lack expertise.
- xorcist 5y ago> Who should users trust more: Mozilla or their local government? Is that really a question to be taken seriously? One is a private organization, completely unaccounted for and in a foreign jurisdiction, who sets their own rules and follows up on themselves. The other is accountable and audited by independent auditors in a system which upholds separation of power and keeps independent media? (Just to clarify: Neither Mozilla or anyone else should accept QWAC or any other standard in the face of legitimate concerns, of course. That's not what trust means.)
- CircleSpokes 5y agoNo one said they should. The EU should at least meet the same if not better standards. Instead they are trying to make an objectively less secure system.
- phicoh 5y agoI doubt there is any text that browsers have to enable those certs by default outside the EU. It could weaken protection for people in the EU, but then the way forward is to make requirements for root certs mandatory in the EU. Maybe I missed it, but did the document require special UI elements for EU certs?
- sleevi 5y agoYes. It requires the EU Trustmark, a logo designed through a secondary-school competition, to be displayed with certain colors and sizing, as directed through Implementing Acts (which have the force of law, but decided at the Commission level).
- deleted 5y ago[deleted]