20 ms·
Last Chance to fix eIDAS: Secret EU law threatens Internet security
- Jacobinians 3y ago[flagged]
- dtech 3y agoI have no idea if you are right, but calling people liars as the first statement and extensively using capitalisation greatly undermines your message.
- pagutierrezn 3y agoHe might be right. Browsers come with CAs from EU states (or agencies controlled by states) for the last 10 years (at least). I work for a public admin in Spain and our site uses one of such CAs and browsers accept it without problems. So I believe that eIDAS has to do with personal identification rather than TLS.
- Jacobinians 3y agoSee something, say something.
- nvm0n2 3y agoIt's not. Read the documents linked to from the article. The law clearly refers to certificates with domain names in them, not client certificates. Actually the bigger impact of this seems to be that you wouldn't be able to host websites anonymously anymore, making WHOIS privacy meaningless, because the law appears to mandate that all certificates contain legal identities in them. Annex IV: Qualified certificates for website authentication shall contain: (b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and: — for a legal person: the name and, where applicable, registration number as stated in the official records, — for a natural person: the person’s name; ... (e) the domain name(s) operated by the natural or legal person to whom the certificate is issued;
- Jacobinians 3y agoDomains are there so you do not send those certificates to UAE website. But only to EU websites.....
- Jacobinians 3y agoIt is interface between webservice and member state for sending authentication data to member state for purpose of auth. Think OAUTH so webservice does not have to save any auth data.
- g-b-r 3y agoWow. So you don't need to know anything to use all-caps and throw around LIARS. Article 45 Requirements for qualified certificates for WEBSITE AUTHENTICATION 1. Qualified certificates for WEBSITE AUTHENTICATION shall meet the requirements laid down in Annex IV. Evaluation of compliance with the requirements laid down in Annex IV shall be carried out in accordance with the specifications and standards referred to in paragraph 4. 2. Qualified certificates for WEBSITE AUTHENTICATION referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for WEBSITE AUTHENTICATION referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services.
- jruohonen 3y agoOh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.
- mbwgh 3y agoI guess this is where client attestation comes into play.
- g_p 3y agoOr, proliferation of the English (US) or English (UK) versions of browsers, which refuse to (and are not obliged to) include any of these CAs... I suspect if this ever does play out, it could result in fewer people using "EU spec" browsers, and more people using the international overseas version, thus undermining the entire intention of the policy proposal. It seems a pretty safe bet no browser maker would ship these CAs to users outside of the EU (and maybe EEA).
- mbwgh 3y agoThat's great if you are not going to be legally and technically required to use these EU spec browsers to be able to access your online banking or any platform registered as doing business in Europe. The EU is playing the long game here I believe.
- jahav 3y agoI suspect such versions won't comply with Cyber Resilience Act (=company would be on hook for a fine). Browsers are in category 2 iirc. Edit: rest of world might be fine(big maybe, these things have tendency to proliferate),eu citizens... screws are tightening.
- justinclift 3y agoNew Firefox plugin: "Disable EU Certs"
- jruohonen 3y agoFrom: https://data.consilium.europa.eu/doc/document/ST-14959-2022-INIT/en/pdf https://data.consilium.europa.eu/doc/document/ST-14959-2022-... Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services." Article 45a(3): "A qualified electronic attestation of attributes issued in one Member State shall be recognised as a qualified electronic attestation of attributes in any other Member State". Article 45a(4): "An attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source shall be recognised as an attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source in all Member States."
- deleted 3y ago[deleted]
- execveat 3y agoAllow the eIDAS certificates, but limit them to the country code TLDs to match the jurisdiction of the certificate issuer.
- agwa 3y agoThat text is almost a year old. The recent trilogue negotiations added paragraph 45(2a) which is not public yet (hence the complaints about secrecy) but is alluded to in the open letter (https://eidas-open-letter.org https://eidas-open-letter.org): > The proposed legislation also prevents the introduction of security checks when verifying the certificates used for encrypted web traffic in Art 45, (2a). As written, this language requires that the EU’s website certificates not be subjected to any mandatory requirements beyond those specified in ETSI standards. This is awful, as it would forbid browsers from requiring Certificate Transparency, or banning a weak hash algorithm (like SHA-1), or requiring post-quantum keys unless the EU agrees to it.
- shuiling 3y ago[dead]
- judiisis 3y agoIndia is also preparing legislation for OS and browser having their CA, they also launched their own web browser challenge https://iwbdc.in/ https://iwbdc.in/ .They were earlier removed due to unauthorised issuances https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-certificate-issuance-by-the-indian-ca-nic-can-government-cas-still-be-considered-trusted-third-parties/ https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-cert...
- Tenemo 3y agoThese are some of the requirements: "Ability to digitally sign documents in the browser using a crypto token" and "Support for Web3". What does that even mean? This is a serious, government-backed competition?
- whynotmaybe 3y agoWhile reading the site, I wondered what is this format? ₹ 3,41,00,000 This brought me to discover the Indian numbering system [1] , another brick on the "localization is hard" wall. https://en.m.wikipedia.org/wiki/Indian_numbering_system https://en.m.wikipedia.org/wiki/Indian_numbering_system
- pxeger1 3y agoI’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?
- derelicta 3y agoWestern security services are what we call secret police in other parts of the world. Its goal is to protect the local status quo. That's it, and thats why it can assert so much influence.
- kossTKR 3y agoThis is one of the most important and least talked about power dynamics. This is because that world is hidden to most people but would have just 20 years ago been covered by classical research journalism, namely the intersections between power, fiscal policy, law, the security state, foreign policy and mass media or other systems of control. Politics and policy making is downstream from mostly non public clubs of people. Become a part of the security apparatus to gain power and draft plans for whole regions of the world and the future of society. The rest of us get to see their own self branding in Hollywood romantizations and ideological "event driven" smokescreens that cover the realpolitcal battles of power and resources that actually drive history. That way the masses end up seeing the good fights for "Democracy", "Child safety", "Necessary financial bailouts" or "Primitive stupid people in X country need intervention" while these are all covering a big old game of Risk or Civilization ie. resource plundering, land grabs, violent exploitation of foreign markets, siphoning of wealth from the masses to the few, and panopticon-level systems of control implemented to keep dissent and enlightenment about these fact as much in the dark as possible. Theres a reason the richest European families already took an interest in controlling the emerging postal services of several hundreds years ago just like early pamphlet media but somehow these very old facts have been so memoryholed everyone thinks we live in a somewhat meritocratic or even democratic society these days.
- nvm0n2 3y agoProbably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that they don't like much, namely successful American companies. The EU loves passing extra-territorial laws and seeing people jump, it makes them feel like a big power bloc which is the whole aim of the EU project to begin with. 2. The revenue from it. Tech companies either fight or they try to obey, but the laws are vague and easily reinterpreted. This yields massive fines which go straight into the EU coffers, money which is then spent on purchasing loyalty both of the elected political elites (via post-election-loss sinecures and enormous "pensions" that start being paid out long before retirement), and the population itself (via EU branded projects and grants). 3. The unaccountability of it. EU law is created by the Commission which does whatever it wants. By treaty it is accountable to nothing except itself and it is the highest power in Europe. In that situation why not spend all your time on easily achieved upper-class luxury agenda items like internet regulation, which feels futuristic and cool, instead of messy stuff that bothers the regular citizens like illegal immigration, where you don't want to do it and failure comes easy? That's why there's a constant flood of tech-related regulation coming from the EU. Seeing this specific act in isolation is a mistake, it's just the continuation of a long term trend.
- Jensson 3y agoThere is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a risk.
- no_time 3y agoIf "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.
- galadran 3y agohttps://last-chance-for-eidas.org/ https://last-chance-for-eidas.org/
- fuoqi 3y agoIf certificates issued by those CAs will be tied to independent (from EU) certificate transparency (CT) services and to specific national top-level domains, then I am completely fine with this. After a big number of websites in Russia (including the biggest bank in the country) have effectively lost access to the CA infrastructure used by commonly used browsers, I don't think any honest person can say that the current status quo is robust enough. So it looks like EU simply hedges against this potential infrastructure risk. To mitigate the MitM risk I believe that CT and limiting CA to specific top-level domains (so a hypothetical RU CA would not be able to issue certificates for .eu or .com) should be sufficient enough.
- eps 3y agoRe: Russia - SberBank, which is used by the vast majority of population, voluntarily switched to a new Russian government-controlled CA. This move aimed to coerse people to install this CA's cert under false premises and to let the state splice https if needs be. The goal was bloody obvious and it has never been about the "robustness" of infrastructure. They just want to take away people's Internet privacy.
- fuoqi 3y agoI hope you are simply not familiar with the situation and not FUDing around. The "false premise" was that GlobalSign has refused to issue new certificates for Sberbank and there were several cases of CAs revoking existing certificates. They eventually have found a CA (Harica DV) which was willing to issue new certificates, but it was not clear at the time that such CA will be found and the new certificates can be revoked at any moment after a new wave of sanctions or simply after a strongly worded warning from Washington or Brussels. Relying on a relatively minor Greek CA for bank operations is clearly not a good strategy in their situation.
- nulld3v 3y agoLeaving a source for other readers: https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/ https://www.bleepingcomputer.com/news/security/russia-create...
- calgoo 3y agoSo what happens to open source browsers? Will they be forced to implement it? Are the governments going to audit the code to make sure no one is releasing a version that has removed the government certs or are they going to outlaw open source browsers? Again, this is not going to catch anyone with half a braincell that is trying to do something. This is just going to catch everyone else. I wonder if this will tie into the BS that Google was trying to implement that would make it impossible to modify the webpage using adblockers etc. making it so you can't navigate the web if you are using a uncertified browser.
- supriyo-biswas 3y ago> I wonder if this will tie into the BS that Google was trying to implement that would make it impossible to modify the webpage using adblocker Very likely, yes. Also note that a similar client-side CSAM scanning feature was rolled out by Apple with a similar anticipation, and shortly after we saw the proposal of Chatcontrol and the like. > So what happens to open source browsers? See my other comment on the same thread[1]. [1] https://news.ycombinator.com/item?id=38110667 https://news.ycombinator.com/item?id=38110667
- matthews2 3y agoHow will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?
- supriyo-biswas 3y agoPeople get very hung up on what people can technically do, but the domains of the browser or OS that doesn’t follow these rules will simply be blocked at the DNS level so that you can’t download them any more. The relevant entities such as companies developing or using said non-compliant projects will be fined, and any natural persons jailed outright, à la Stallman’s The Right To Read.
- execveat 3y agoYou can't block a browser at the DNS level.
- supriyo-biswas 3y agoI meant domains offering downloads of the non-compliant browser/OS; updated. Thanks!
- subbz 3y agoUnfortunately the whole world population is addicted to ~5 sites/apps on the web who will play the game. If Debian patches this out, you won't be able to access those sites. That's a living edge case for them.
- jonathanstrange 3y agoI think the right way of dealing with this is to have a button to switch between secure mode and insecure/government mode.
- g-b-r 3y agothe law can be interpreted as making it illegal, even for end users (it deals with "web-browsers", not "web browser vendors")
- verisimi 3y agoLololol "We need to be able to break security so we can see all your data, to keep you safe! Terrorists! Child abuse!" "hmm yeah, but who's going to keep me safe from you?"
- galadran 3y agoTitle should probably be: "Last Chance to fix eIDAS: Secret EU law threatens Internet security"
- Maxion 3y agoThe Secret Law bit is quite clickbaity.
- runnedrun 3y agoDoes anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?
- g_p 3y agoI believe that the stated/claimed intent is to create cross-country, bloc-wide digital signature interoperability and acceptance standards. The theory being that you can "digitally sign" things with a national ID (e.g. a smart card), and have that recognised anywhere in the EU. That would, in theory, help to reduce and simplify bureaucracy, especially for people moving between countries in the EU (a process which can be quite complex even with freedom of movement, due to totally different cultural norms around government systems, forms, languages, etc.) Something better than typing your name and trusting a third party to do email verification for a digital signature certainly sounds like it could have advantages for doing business though. I believe the issues identified here seem to stem from a (very) over-enthusiastic desire to have certificate acceptance everywhere (i.e. prevent discriminating against one country's citizens by excluding their ID card CA), without understanding the different types of trust chains and certificate chains. Presumably scattered with a bit of technical naivety as well. The concept itself is (probably?) fine, as long as it doesn't try to force browsers or SSL verifiers to accept or trust certificates they don't want to.
- jruohonen 3y agoIndeed: the goals are justifiable and very much welcome, in my opinion. Yet, I do not understand what CAs and the global TLS/PKI ecosystem have to do with the goals.
- Jensson 3y ago> Yet, I do not understand what CAs and the global TLS/PKI ecosystem have to do with the goals. Technically that is also digital signing. The regulators probably thought that all kinds of digital signing should be included in this bill and just slapped something down for browsers while they were at it.
- rvz 3y ago[flagged]
- miohtama 3y agoChat control has intercepted this forum post and flagged you as a terrorist. Your bank account is now frozen. Please report at your local police station tomorrow at 10am.
- sirwitti 3y agoI'd like to see what the european court of justice will have to say about this, should this actually become law.
- mbwgh 3y agoThe following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Juncker https://en.wikiquote.org/wiki/Jean-Claude_Juncker
- graemep 3y agoWow, a lot of those quotes are damning.
- SiempreViernes 3y agoDoubt it is a particularly unbiased sample though, so probably not a good idea to draw any strong conclusions from reading it.
- deleted 3y ago[deleted]
- belter 3y ago“it is a historic mistake to not want to tax at the appropriate levels the profits of multinational companies which act globally and don’t pay the taxes they owe.” - Jean-Claude Juncker ...Prime minister of ....Luxembourg
- SiempreViernes 3y agoMr LuxLeaks said that eh? I mean, I'm not saying Juncker is great, just that reading the random collection of quotes on wikiquotes might not be the best way to judge his work.
- vanderZwan 3y agoThe worst part is that this is still better than how most governments currently work. At least there is a chance to give feedback. Also, keep in mind that this is in the context of getting all member states of the EU to agree on something. People kicking up a fuss is the default situation because of conflicting interests between different states. Make no mistake about how I feel about this though: it's still pretty horrible even with that context in mind. And as graemep pointed out the rest of the quotes on that page will tell you all you need to know about Juncker too.
- galadran 3y agohttps://eidas-open-letter.org https://eidas-open-letter.org The open letter signed by 300+ researchers, professors and experts.
- diego_sandoval 3y agoThe proposal is so obscene that I doubt Apple, Google or even Microsoft would ever comply with it.
- neodypsis 3y agoI guess Europe would have to fund its own browser development. The rest of the world won't participate.
- supriyo-biswas 3y agoDeveloping a browser these days mostly involves slapping on their own branding over Firefox or Chromium though, so hardly the end of the world for EU.
- datpiff 3y agoIt's a market of nearly half a billion people, two-tier browsers seem more likely. IIRC Netscape did this in the past over US export laws on cryptography.
- justinclift 3y agoThey'd probably be fined into submission if they don't though.
- diego_sandoval 3y agoIf it gets to that point, one alternative would be creating some ad-hoc non profits that are on paper not controlled by them (but in practice they are) and then giving up the control of their respective browsers to said non-profits. But it won't get to that point. I don't really think the US government would be ok with a regulation like this, either, and they have even more bargaining power than tech companies.
- g-b-r 3y agothen the non-profits would be breaking the law
- NoboruWataya 3y agoVery concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps them impress the urgency of the matter on the public but frankly it just makes me doubt the veracity of the claims made in the article (though in this case I trust Mozilla and would hope that they are not misrepresenting the content of the law itself).
- ratg13 3y agoThey’ve had entire programs around trying to get the public engaged in this topic. I’ve watched many of their YouTube presentations.. all with less than 100 views when I watched them, despite them being uploaded for some time.
- junofan 3y agoWhy can’t Mozilla publish the agreed-upon changes? Are the drafts currently classified? If so, I think it’s okay to bell ring.
- phasmantistes 3y agoI don't think "classified" is the right word, but they haven't been published. They were leaked to various third parties, who got them to Mozilla / EFF / the other folks writing letters of protest today. Those parties haven't published the full text themselves, to protect the identity of the leaker.
- sofixa 3y agoAlso, this: > and will be presented to the public and parliament for a rubber stamp before the end of the year That's not how the EU parliament works, they're not just a rubber stamp. The topic is sufficiently grave without the need for clickbait and painfully obvious exaggerations.
- supriyo-biswas 3y agoFor anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/ https://notes.valdikss.org.ru/jabber.ru-mitm/
- Jensson 3y agoeIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all of those usecases are a part of eIDAS. That is the core of the standard and there you really want to see all the certificate information to be sure it is the right origin, since unlike browsers there is no list of trusted CAs, you just see that some organization accepted it. Edit: Browsers already had their own standard that they think is better than eIDAS, so they don't want this to apply to them. But Occam's razor says that EU just added "and browsers should also do this" instead of there being some conspiracy behind it, it was simple to just add everything instead of leaving just browsers out.
- supriyo-biswas 3y ago> Browsers already had their own standard that they think is better than eIDAS Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest. > "and browsers should also do this" instead of there being some conspiracy behind it The law isn’t RFC 2119 where there is a distinction between SHOULD and MUST: the law is all about what an entity MUST do, so bringing up “should” in this context isn’t helping the point you’re typing to make.
- Jensson 3y agoI don't get what your point is here, you said this and that is what I argued against, your points here does nothing to defend this: "For anyone who’s about to say that surveillance isn’t the point of this legislation". > Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest. I didn't say this was subjective. My argument was that it is easy to see why EU would do this without having surveillance in mind. They just wanted all certificates to follow the same standard, the main part of these standards were document signing and they thought web sites are documents so we add them as well to the standard. > so bringing up “should” in this context isn’t helping the point you’re typing to make. I didn't make a distinction between should and must there, that wasn't my point at all. What was hard to understand there? This bill is first and foremost about document signing, and then they added a clause that it also applies to browsers. That is the main part of my argument. A bill that first and foremost targets document signing doesn't seem like it was obviously made to add spying on browsers, if that is what they wanted they would have labeled it "web protection bill" or something like they did with the chat one, they aren't afraid of saying it is about spying when that is what they want.
- varispeed 3y agoSeems like some politicians from EU commission had parents in Stasi, KGB and other organisations and became allured by the stories of watching other people, learning they secrets or perhaps even seeing their naked photographs. So these pervs now want to do the same. For what?
- johnfonesca 3y agoeIDAS is a cartel created to protect the business interests of EU biggest certification authorities.
- Jensson 3y agoIt is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.
- johnfonesca 3y ago>it makes it easy to switch document signer provider etc since they all are forced to implement the same interface. eIDAS was introduced in 2016. Now 7 years later there still isn't a API specification for interoperability (there are drawings though https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ ) In the meantime, any digital signature done in EU must be done with a certificate issued only by the "select" CA to be considered "valid".
- Jensson 3y ago> Now 7 years later there still isn't a API specification for interoperability The standard existed 2016, I did a short stint for a company that was implemented eIDAS back then. They even have a test suite you can use to check how well you comply with the standard: https://ec.europa.eu/digital-building-blocks/wikis/display/DIGITAL/ETSI+Signature+Conformance+Checker https://ec.europa.eu/digital-building-blocks/wikis/display/D... It is very archaic to work with though, but at least they try to have a standard.
- johnfonesca 3y agoThe ETSI checker you have linked doesn't have anything to do with CA API interoperability and "switch document signer provider". That's just a basic tool which validates if a signature is PADES/ETSI compliant or not. The real value in eIDAS would be "unlocked" if they would release a proper API specification with which a digital signatures application would integrate with any EIDAS CA to emit/sign certificates. And then enforce that any eIDAS compliant CA would implement this API. In practice that means any company/digital signatures product could do a integration with this API once and then be able to use ANY certification authority they want/need/offer best prices for certificates. Without this API, eIDAS is just a marketing moniker because the power belongs to the selected Certification Authorities. They set the prices, they choose WHOM can integrate with them to isse certificates and there is NO interoperability between them. This doesnt allow for a open market and makes the top players control everything while shouting "standards" and "eIDAS".....
- algesten 3y agoTo protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?
- Snawoot 3y agoTLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.
- darkarmani 3y agoInstead of a pihole, you'd run a https proxy that doesn't trust the certs i guess.
- Snawoot 3y agoWhich https proxy you're referring to? HTTP proxies capable of forwarding HTTPS just offer HTTP CONNECT method, which allows client to tunnel regular TCP connection and HTTPS inside it. These proxies do not do anything with certificates.
- archi42 3y agoThat's illegal then. But the pihole won't do the trick, you need to remove the mandated certs from your browsers certstore. If these certs are used for legitimate places (e.g. EU or state websites, and I'll bet they will) you then will get a certificate error. Of course there is still HSTS, but that's not supported by all tech using TLS.
- hn8305823 3y ago> If these certs are used for legitimate places (e.g. EU or state websites, and I'll bet they will) you then will get a certificate error. Prediction: If this passes, users having to bypass cert errors will be the new cookie popup.
- bjornsing 3y agoI’m so tired of this shitstorm of crap EU regulation. Death by a thousand cuts…
- agarsev 3y agoJust adding a perspective (not necessarily mine, I'm still on the fence) supporting this legislation from a tech-literate person in the EU. The digital administration in my country has made my life so much easier. We all have mandatory ID cards since decades ago, but now they have a chip with some certs for auth, signing, etc. I can check my taxes, fill government forms, see any traffic tickets, sign official documents from my home thanks to this. However, as far as I understand, this relies on my user agent accepting some particular CAs. This is critical, to the point of my browser preventing me access to some parts of the administration if the CA is not up to date or recognised or whatever. What this legislation proposes, if I understand it correctly, is putting in the hands of the government the power to administer (part of) this CA infrastructure. As with many EU-related legislation, this forcefully transfers power from private (often American) entities to EU governments. I guess when trust in your government is higher or equal to trust on private firms, this doesn't sound so bad. Not saying this is right or wrong, but maybe this helps understand why many people in the EU may not be so against this type of legislation.
- galangalalgol 3y agoThis isn't adding a few CAs s your browser trusts the tax website. This appears to be replacing all of them so the eu can see the contents of all traffic that is proxied in and out of the country. None of that seems likely to work for actual bad people.
- kreetx 3y agoIf the root CA is installed in my browser then the government can MITM any connection at will.
- whelp_24 3y agoYou should read the letter, it's worse than that. It makes these gov CA's unrejectable, along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic. They could have reduced scope, but looking at effects perhaps that's not what they actual want.
- deleted 3y ago[deleted]
- perihelions 3y agoIgnorant question: what happens if Mozilla or Brave or whoever says fuck that, we're not complying? What's the enforcement mechanism for non-EU-based devs publishing FOSS freely on the global internet?
- yaris 3y agoThe enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.
- perihelions 3y agoHow do you ban a FOSS?
- yaris 3y ago"One cannot hang a song, sure, but one can hang a singer". There are not so many places where people can get Firefox or Chromium, even fewer places where they can get source code of the named browsers. [EDIT] grammar
- deleted 3y ago[deleted]
- lakomen 3y agoYou criminalize the platform where it's published. The laws for that have been conjured in 2018.
- darkarmani 3y agoThe second they do that the entire internet is going to download it to see what the fuss is about. While they could legally do that, it's going to blow up in their face if they did it. I remember the old crypto export wars in the US and OpenBSD being based in Canada so they could ship string crypto in SSH.
- dang 3y agoRelated: https://mullvad.net/en/blog/2023/11/2/eu-digital-identity-framework-eidas-another-kind-of-chat-control/ https://mullvad.net/en/blog/2023/11/2/eu-digital-identity-fr... https://alecmuffett.com/article/108139 https://alecmuffett.com/article/108139 (via https://news.ycombinator.com/item?id=38109581 https://news.ycombinator.com/item?id=38109581 and https://news.ycombinator.com/item?id=38109731 https://news.ycombinator.com/item?id=38109731 respectively, but we merged the comments hither)
- pandastronaut 3y agoCandid question : if this is european legislation, how browser editor would handle this regional specific requirement ? Provide several flavor of their browser ? I doubt people and companies from outside europe would agree to use a european flavored version of their browser.
- GTP 3y agoIn the past, browsers needed to have "export-grade cryptography", because the USA considered ciphers a weapon, thus subject to export rescriction. And this ended up playing a crucial role in downgrade attacks later on. So I would say yes, they already had to handle a similar situation in the past.
- radicalbyte 3y agoIt's worth noting that the technical team have a github where issue such as this can be raised. https://github.com/eu-digital-identity-wallet https://github.com/eu-digital-identity-wallet
- account42 3y agoWhy are they hosting this on GitHub and not on EU infrastructure?
- radicalbyte 3y ago1. The EU infrastructure sucks. 2. Reach. Lower the barrier = easier for everyone to contribute.
- JanisErdmanis 3y agoContrary to the majority of opinions here, I see this as a reasonable development for the state’s sovereignty, which will positively affect the decentralisation of certificate authorities. I hope that unprofessional negligence by European authorities will produce enough precedents and evidence to show that certificate authorities can’t be trusted blindly, and we will end up with transparent certificate authorities and web browsers which will audit every certificate with public logs with the help of History Trees.
- Hard_Space 3y agoWow - this one really crept up on me, after years of seeing it shot down in flames by people who actually understand the technology, and the implications (not least, the security implications). I wonder if the recent passing of the UK act emboldened them..?
- ryukoposting 3y agoI've generally been supportive of the EU's web regulations, but this is utter insanity.
- 5ersi 3y agoIf you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you and see all your traffic if they: 1. have ability to capture IP traffic (requires cooperation with ISP) 2. have ability to generate rogue certificate via cooperation with CA
- agwa 3y agoYes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory checks (such as Certificate Transparency) on certificates unless the EU agrees to them. That creates a system that is very viable for government MitM attacks.
- andyjohnson0 3y ago> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?
- jeremiahlee 3y agoEU citizens wanting to oppose the current eIDAS proposal can use my edit of the open letter to send to their Members of European Parliament: https://www.jeremiahlee.com/posts/2023-eu-eidas-feedback/ https://www.jeremiahlee.com/posts/2023-eu-eidas-feedback/
- 2-718-281-828 3y agoyou'd almost think that the /ˌiːˈjuː/ is bent on subverting the internet. i'm experiencing fatigue from news like that already. can't they just stick with what they do best, standardizing vegetables and banning british sausages?
- surfingdino 3y agoThis is concerning, but I still have faith in big orgs' and governments' inability to do a simple thing right while paying consultancies a lot of money for it. I have experience implementing banking infrastructure using eIDAS for participant identification and I know how CAs and financial institutions do not get eIDAS. They make rookie mistakes and deny they've done something wrong for months while blaming the other party and seeking regulatory exemptions. I'd be surprised if the EU governments were able to implement it. What wouldn't surprise me would be them blaming browser devs for it.
- lacoolj 3y agoEU is not the only place with insane laws like this in the pipeline. USA has been trying to introduce this kind of thing (EARN IT Act 2023) as well, under the guise of "preventing child trafficking". Terrifying times we live in where we may not even be able to keep our medical or financial information private anymore because of a handful of people voting on something they don't understand.
- phendrenad2 3y agoIn the EU they will take something that should be a standard, make it an actual law, and pretend it isn't about spying on you, and expect you to believe it. Very 1984.
- j45 3y agoMaybe LLms can help people more effectively engage with their political representatives on topics like this. I’m increasingly convinced that this type of legislation will continue to proliferate until legislation banning it is not pushed for and put in place.
- demarq 3y agoPeople are already self censoring what they really think on social media, this will push people to self censor in private convos. At that point you’ve got to wonder what happens to democracy, when people are afraid to exchange ideas
- lakomen 3y agoI think it's what some people are pushing for, how else can the Lisboa treaty be explained? Surely they weren't that short sighted.
- lakomen 3y agoIt's like, anything coming from the EU lately in regards to IT is a totalitarian nightmare
- phasmantistes 3y agoFundamentally, the whole issue with eIDAS comes down to one thing: you cannot mandate trust. If it's mandated, it isn't trust. It's something else. By mandating that browsers "trust" certain CAs, they're breaking the entire trust model of the internet. My only question is whether they truly don't understand this, do understand it but don't care, or are actively interested in destroying that trust.
- xinayder 3y agoDoes someone else think it's an extreme coincidence that we have Chat Control and now this in place? Pretty sure the negotiations around Chat Control revolve on this eIDAS being approved, that way you don't "undermine" encryption because, well, you have the keys to decrypt everything.
- moogly 3y agoIf they want to push more people to use the dark web, this would do it.
- kmeisthax 3y agoSo, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right? Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this is equivalent to letting the CIA read your text messages.
- Scion9066 3y agoFrom Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.
- darkarmani 3y agoIt's not a "security check" it's just informing the user about their certs...
- ImPostingOnHN 3y agothe certs let the authorities issue new certs for anyone they want, e.g. your email provider, and your browser won't be allowed to verify whether those certifications are valid or not, to notify the user
- mindcrash 3y agoNot just "internet security". There has been discussion that they want to use eIDAS for a lot of things like identification in general and even a health passport. Consider that last thing. We have this thing called bodily integrity [1], which guarantees everybody has self-ownership regarding their body and thus what can be done with it. However, in the COVID period, it was clear as day that those who govern us dont give a rats ass about something like bodily integrity and going as far as taking away freedom of movement in order to make people comply with injecting themselves with a - until this very day - experimental vaccine. Now consider what TPTB could do with a powerful toy like eIDAS. So no, it is not "just" about internet security. Its about slowly and surely stripping away every human right you have as a EU citizen. [1] https://en.wikipedia.org/wiki/Bodily_integrity https://en.wikipedia.org/wiki/Bodily_integrity
- elric 3y agoI'm not sure I understand the point you're trying to make. Few rights are absolute. We, as a society, obviously try to prevent people from harming one another. If you're infected with a dangerous pathogen, and you refuse to do something about it on account of "bodily integrity", you will end up violating other people's bodily integrity by infecting them. That's bad, and it would certainly be within "TPTB"'s rights to stop you. As for vaccines being "experimental", they have saved many lives, and now that the dust has settled, they seem to have done very little harm. This all sounds rather like conspiracy nonsense, which isn't to say that eIDAS isn't stupid, but silly conspiracy nonsense like this undermines potential real concerns with eIDAS.
- elric 3y agoCould someone link to some actually helpful writeups on eIDAS? The linked article doesn't mention what eIDAS is about, only vague but strongly worded language about it having to be stopped, with no justifications or even what it is. The comments too are less helpful than usual. A lot FUD and anti-EU sentiment (which may or may not be warranted, but there's very little objective reasoning going on). Addendum: yes, people could look it up, but given the strong call to action ("last chance to fix eIDAS!"), I would suggest that the onus to provide clear information is on the authors. You can barely get people to care about privacy at all, let alone when so little information is provided.
- Jacobinians 3y ago[flagged]
- workfromspace 3y agohttps://archive.ph/Ilhes https://archive.ph/Ilhes (because it's a NRD-newly registered domain which my dns-hole blocks) Also brief info about website (for the ones who doesn't want to visit an unknown domain without knowing): A Mozilla website for open letter by 300+ cyber security experts, researchers and NGOs.
- Aerbil313 3y agoCall it surveillance or whatever. It really isn’t. Trust and power as manifested by modern technology was and should be a reflection of real life trust and power. Historically, human societies’ governing bodies had all the power to exert as they wish on their citizens. Past couple decades were a deviation from this normal, not in the real but in the online world. You could work against the values of your own government without them being able to find and catch you. This legislation is just a correction to the resulting power imbalance, as the online world has increasingly more power on real world. I think we’ll see the internet and digital ecosystems being segregated into separate parts with boundaries correlating to those of nation-states more and more by the year. As a member of a nation who is not exactly very comfortable with a US-dominant world, I’m all in for it. It’s a national security issue for me. Knowing that some three letter agencies on the other side of the world can surveil me against my rights as per my country’s laws. Or that payment systems (Visa/Mastercard), or Google Maps (you don’t know how vital of a service it is) or satellite internet[1] can stop working if US and her allies determine my time has come. Developing technologies has a power-centralizing effect, and very often it creates a disadvantage for everyone else who didn’t invent the thing first. Not exactly the world I’d have pictured as a desirable one had I lived 5 centuries ago. Maybe read some Ted Kaczynski? 1: Elon Musk stopped Starlink service in Gaza. They have no communications with the outside world.
- inemesitaffia 3y agoWhere'd you get this idea of starlink in Gaza
- PeterStuer 3y agoHonest question, so please bear with me. How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA? Is demanding browsers distributed to EU citizens to carry this certificate different from demanding phone companies to route emergency service numbers correctly? Ofc I can see the 'dark' potential for a mandated cert. Is this realy different from current browsers ubiquitously storing trusted root certificates from CA's issued by private companies residing in states with very serious compelled secret goverment access laws and regulations?
- ExoticPearTree 3y agoCertificate Transparency Lists - and from what I understand, the EU does not want its CAs to publish such a list, and here lies the problem.
- ImPostingOnHN 3y agoThe first priority is ensuring citizens can answer, "how can I make sure my government isn't spying on me", to their satisfaction, and then they might start caring about the government's use-case/pretext.
- chidi0202 3y ago[dead]
- anonymousnotme 3y agoAs far as certificate authorities (CAs) build into the browser: One way around this might be that the browsers ship with the CA as required by law, but that one can disable/delete the CA via the UI. I would guess that a law would be passed that says that the browser can't disable/delete certain CAs (perhaps this one also says that). There can be a list of various government CAs that one might want to disable. This does not help if governments can pressure CAs to issue an alernate CA for use in MITM. Does any of the CA transaprency help? What about a way to have people endorse a certficate (i.e. reputation)?
- donaldjoan36 3y ago[dead]
- AnetteJourdan 3y ago[dead]