8 ms·
What the QWAC? An EV Certificate all over again
- thedaly 3y agoHe leaked excerpts from the text but not the full document. I would really like to read the actual full text document. The fact that the European commission keeps the draft legislation secret is concerning. Is this the typical process for all EU regulation?
- deleted 3y ago[deleted]
- jacquesm 3y ago> I would really like to read the actual full text document. I think they are not releasing the full text to protect their source in case the text was steganographically marked.
- layer8 3y agoThe processes are relatively transparent and regularly being reported upon [0][1], though working drafts are not generally public. Most of what is being criticized now is already contained in the 2021 proposal [2]. In reaction to earlier criticisms, provisions were added to the current draft to allow browser vendors to take measures in case of security concerns regarding QWACs, see paragraphs 2–4 in https://news.ycombinator.com/item?id=38183994 https://news.ycombinator.com/item?id=38183994. The whole thing is not a secret conspiracy, and legislators are generally well-intentioned (for whatever that’s worth). [0] https://www.europarl.europa.eu/legislative-train/spotlight-JD22/file-eid https://www.europarl.europa.eu/legislative-train/spotlight-J... [1] https://www.europarl.europa.eu/RegData/etudes/ATAG/2023/739285/EPRS_ATA(2023)739285_EN.pdf https://www.europarl.europa.eu/RegData/etudes/ATAG/2023/7392... [2] https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=COM%3A2021%3A281%3AFIN https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=COM%3A20...
- dwheeler 3y agoI believe the legislators are generally well-intentioned, but that is worth nothing. Laws and regulations should be judged by what they will do. In this case, they will make security worse, witg no adquate compensatory advantage, so it should be rejected.
- dang 3y agoRelated ongoing thread: Article 45 of eIDAS 2.0 will roll back web security by 12 years - https://news.ycombinator.com/item?id=38181114 https://news.ycombinator.com/item?id=38181114 - Nov 2023 (77 comments) Also: (others?) Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform - https://news.ycombinator.com/item?id=38126997 https://news.ycombinator.com/item?id=38126997 - Nov 2023 (63 comments) Last Chance to fix eIDAS: Secret EU law threatens Internet security - https://news.ycombinator.com/item?id=38109494 https://news.ycombinator.com/item?id=38109494 - Nov 2023 (299 comments) EFF about EU: EIDAS 2.0 Sets a Dangerous Precedent for Web Security - https://news.ycombinator.com/item?id=33966364 https://news.ycombinator.com/item?id=33966364 - Dec 2022 (44 comments) EU legislation eIDAS article 45.2 may force inclusion of insecure QWAC root CAs - https://news.ycombinator.com/item?id=32093891 https://news.ycombinator.com/item?id=32093891 - July 2022 (36 comments) Mozilla and the EFF publish letter about the danger of Article 45.2 - https://news.ycombinator.com/item?id=30549119 https://news.ycombinator.com/item?id=30549119 - March 2022 (13 comments)
- dang 3y agoUrl changed from https://twitter.com/Scott_Helme/status/1721905520788086836 https://twitter.com/Scott_Helme/status/1721905520788086836, which points to this.
- charleyablaze 3y agoThe secret text of Article 45: > I have access to the near-final text of the regulation, which is not yet public, but was leaked to me by a confidential source. ‘qualified certificate for website authentication’ means a certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IV; Evaluation of compliance with those requirements shall be carried out in accordance with the standards and the specifications referred to in paragraph 3. Qualified certificates for website authentication issued in accordance with paragraph 1 shall be recognised by web-browsers. Web-browsers shall ensure that the identity data attested in the certificate and additional attested attributes are displayed in a user-friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1 Qualified certificates for website authentication shall not be subject to any mandatory requirements other than the requirements laid down in paragraph 1. 1. Web-browsers shall not take any measures contrary to their obligations set out in Art 45, notably the requirement to recognise Qualified Certificates for Web Authentication, and to display the identity data provided in a user friendly manner. 2. By way of derogation to paragraph 1 and only in case of substantiated concerns related to breaches of security or loss of integrity of an identified certificate or set of certificates, web-browsers may take precautionary measures in relation to that certificate or set of certificates 3. Where measures are taken, web-browsers shall notify their concerns in writing without undue delay, jointly with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory authority, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory authority shall issue an acknowledgement of receipt to the web-browser in question. 4. The competent supervisory authority shall consider the issues raised in the notification in accordance with Article 17(3)(c). When the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate(s), the supervisory authority shall inform the web-browser accordingly and request it to put an end to the precautionary measures referred to in paragraph 2. There is also recital text which I did not copy.
- crotchfire 3y ago[dead]
- resolutebat 3y agoFor other confused people, "EV" here is an Extended Validation certificate, and this has nothing to do with Electric Vehicles. The author's previous blog post is basically mandatory reading if you want to make any sense of this one: https://scotthelme.co.uk/looks-like-a-duck-swims-like-a-duck-qwacs-like-a-duck-probably-an-ev-certifiacate/ https://scotthelme.co.uk/looks-like-a-duck-swims-like-a-duck...
- deleted 3y ago[deleted]
- amluto 3y agoA sad thing is that, on its face, this isn’t actually crazy: > At the top of my list of concerns is that browser and client vendors (Root Store Operators) will have a legal obligation to add Government mandated Root Certificate Authorities to their Root Stores, bypassing existing approval mechanisms. > Yep, you read that right. Government mandated Root Certificate Authorities... > I could end this blog post right here because anyone reading this will understand the significance of such a statement, and just how much of a catastrophically bad idea that is, but it gets worse. At the end of the day, (other than the EV-like “additional attested attributes”, which have been tried and were not a success), this makes quite a bit of sense: the EU is the authority as to the mapping from foobar.eu to whatever logically lives there. Norway is the authority mapping foobar.no. The US likewise controls .us, etc. So, if the EU says that foobar.eu maps to some public key, who is Google or Mozilla or Apple to question it? Of course, all of this is ignoring massive technical issues. DNSSEC really does map domain names to attributes (but not individual names!) in a verifiable manner, and DANE can extend it to HTTPS, but DNSSEC is massively problematic. And the CA / WebPKI system is a baroque mess that is, finally, sort of under control. And the actual leaked text of the proposal does not respect any of what got the CA system under control. I can imagine a situation in which the EU (through its qualified agents) could attest, cryptographically, which CT or its equivalent, that a domain name in .eu maps to a given certificate, and browsers should accept that. Except this is pointless — browsers already accept the equivalent of this. IMO it would be more valuable for the EU to do the converse: require that browsers not accept a .eu certificate without attenuation from the EU. Raise the bar, don’t lower it! The EU absolutely has an interest in preventing a US (or Chinese or whatever) entity from falsely certifying an EU site.
- candiddevmike 3y ago> DNSSEC is massively problematic. Everyone has all of these problems with DNSSEC but no solutions. What's the better alternative? We need a way to verify hostname lookups. DNSSEC does what it says on the tin. DIYing DNSSEC is a pain in the ass, but in 2023 I think the overlap of folks who self host DNS and aren't capable of setting up DNSSEC is quite small. I personally think we missed a great opportunity with DANE to decentralize a lot of things, but DNSSEC FUD got in the way.
- jrockway 3y agoWhat's the enforcement mechanism for including the root certs? As far as I know, there is no web browser that is sold for money. That means that if you're Apple or Google, you can spin off a company that has no presence in the EU and ship whatever root certificates you want, and it's not like you lose out on revenue. You probably dispel a lot of antitrust concerns as well. At the end of the day, what certs you trust is a personal decision. It's not a democracy; there is no need for an entire country to agree on which certificates are trusted and mandate that by law. Pick the ones who you trust, and your choice need not affect my choice. (Most of us delegate to browser vendors, OS vendors, or our employer, of course, but that is a choice. Don't like Apple's set of root certs? Delete the ones you don't trust, or use Firefox, or use Chrome.)
- Hamcha 3y agoI would assume coercing the OS providers (MS/Apple/Google) who do sell a system with a browser for money into shipping the backdoored browser would be enough of a win for them. Not a lot of people change their browser, even when it was stupid old Internet explorer...
- LamaOfRuin 3y agoIf this was actually true, Chrome would not have anywhere near the market share it has.
- jrockway 3y agoI feel like "Edge only exists so I can download Chrome" is a meme that many, many people outside the software engineering field relate to. Go post it to Reddit, instant 100k upvotes every time ;)
- Hamcha 3y agoI never said it was the majority, but if you look at the numbers there's a chunkable size of population that don't change (and it's been higher than the Mozilla market share for many years now), that number is getting bigger now that Edge is not immediately terrible anymore (I know several people who used Chrome and now stick to Edge). Plus we have a history of people keeping the default browser around just in case since gov websites were always optimized for weird setups like "Internet Explorer running Java applets".
- olliej 3y agoIt's strictly worse because at least a rogue/incompetent CA can be distrusted, as the legislation intentionally makes distrusting one of these CAs difficult/impossible
- emilfihlman 3y agoIt's pretty funny to me when people defend PKI as something good and nice, especially while criticising EV. As it stands, PKI is EXACTLY good for spying, MITM etc attacks. I so wish that a) governments would become their own CAs, this would finally allow us to have actually reliable and secure government level communications and b) tofu would be the standard when communicating with anything on the internet. PKI is CIAs wet dream, and it's infuriating how people just skip right over that. I actually think it's highly likely that certificate pinning was actually killed because it allowed tofu and basically removed all need for outside control.
- tsimionescu 3y agoCan you explain how exactly you believe a government can exploit the PKI to MITM traffic to, say, google.com? Especially how they could do so in a way that wouldn't have been much easier if they (a) could force a browser to trust an insecure CA or (b) intercept my initial communication if they know I'm doing TOFU?
- emilfihlman 3y agoI recommend that you, for example, look into the very recent attack on the Russian Jabber service that was talked about here a lot a couple of weeks back. Companies, doesn't even have to be the CA themselves, are very easy to coerce into doing the governments bidding, and it doesn't even have to be the entire company, just one person is enough, it's just a change in law that most outside of IT circles support, and it's already law in many, many places. Like it or not, country level domains are already under the control of their respective country. And PKI is enabling this coercion, it simply wouldn't be possible if we didn't place trust on these third parties, and place our trust in them all the time, that's a 3 months maximum wait. As for "bootstrapping" trust, your first connection is always going to be about trust unless you have a side channel to provide you trust (basics of encrypted communications), so trusted CAs are in no way special here, I would much prefer if this trust was provided by say Debian, as it provides the software I'm running. I even much more trust a first connection validity vouched for by an actual government, especially say from Finland than I would trust one vouched for by just some random company. As for tofu, you do realise attacking it requires capturing and changing ALL traffic, forever, to be effective, as as even though SSH doesn't do it, it's super easy to add forward secrecy to it with a signature update mechanism. And once you have tofu, you are set. If you can compromise that channel you can also compromise PKI. PKI is strictly worse than TOFU. Random company CAs are strictly worse than governments themselves vouching for connections. PKI is CIAs wet dream.
- rediguanayum 3y agoWhy don't the browsers make the trusted CA root set a choice? Have a radio button selector between the "EU sanctioned", "Browser safe-default", and user selectable? Make radio button panel really easy to find and update.
- gruez 3y agoWhat happens when you selected "Browser safe-default" but your bank's website presents an EU certificate? Sure, you can probably add a "trust only for this site" option, but soon enough users are going to get used to this and will blindly click that button every time the warning shows up, which kills the whole point.
- supriyo-biswas 3y agoParent's suggestion is to accept the eIDAS certs only within the EU.
- gruez 3y agoAre we reading the same comment? The one I'm reading only mentions having a "radio button selector" with no reference to making it geo specific. Regardless, even if it were geo specific, then what? I guess it's fine for american users, but what about all the EU users that might be getting MITMed?
- supriyo-biswas 3y agoIf the law mandates a MITM capability, and users in the EU don’t consider it important enough to oppose said law, there isn’t really a choice and the region scoped certs may be the only choice moving forward.
- ThePowerOfFuet 3y agoThere will be a fork of Firefox in that case.
- awei 3y agoWhat would this mean for let’s encrypt free certificates ? Would their root CA still be recognized in the EU?
- Scion9066 3y agoIt would be, but so would any of the EU state controlled ones, even if that's not what you use for your domain. The main problem isn't that it puts any limits on what you can use as a CA but rather that it mandates some of what everyone must trust as one, even if that trust isn't earned (or maintained).
- awei 3y agoI understand better now, thanks!
- tgsovlerkhgsel 3y agoThe simple solution to this is to promise that any browser instances outside the EU will label these certificates as invalid with very big red scary warnings (maybe mumbling something about risk of state-sponsored attacks). The CAs trying to push those certificates will then quickly lose interest in pushing this regulation... Within the EU, this can also be solved: Pop up a dialog with the certificate, showing "This web site uses a special kind of certificate that <browsername> is by law required to accept. <issuing authority> from <country> claims that this web site has the following identity <claim>. Such certificates are typically used by (explain whatever the intended use case of these certificates is supposed to be). If you do not expect this web site to use such a special certificate, this may be a government-sponsored attack. The below text will help any technical people investigate. <base64 of the certificate> [ ] do not show again for this certificate and site". That fulfills both the letter and the spirit of the law while making it very unlikely that these certificates can be used maliciously (and if they were, would make it extremely likely that signed evidence of that would quickly show up). Optionally, allow site operators of major sites to indicate that they will never use such certificates.
- deleted 3y ago[deleted]
- figassis 3y agoBrowsers could simply make QWACs distinguishable from all other certs. Make sure to show qwac next to the lock. Will the EU say hide the qwac?
- deleted 3y ago[deleted]
- denton-scratch 3y agoReplace the padlock with a duck icon!
- billpg 3y agoAm I the only one who checks the EV cert when logging into the bank?
- teekert 3y agoI almost exclusively use apps for banking nowadays. Honestly, for my own bank I am looking at the cert details and I have no idea if it's an EV, I think it's not.
- pashadee 3y agoCan't individuals (on their local systems) just blacklist those root CAs independently of the browsers? I can do that today to trust and distrust any certificate out there. Problem solved right?
- lyu07282 3y agoMost people never change defaults, this is for mass surveillance and repression. Its not about some specific activists, for those they hire foreign private security firms and they are using 0-days anyway.
- denton-scratch 3y ago> Can't individuals (on their local systems) just blacklist those root CAs independently of the browsers? The problem (for me at least) is deciding which of the 200-odd roots I want to distrust. If a root has a name that I can't decipher because it's in foreign, that's easy. But most roots have cryptic names, and there's no standard way of finding out who operates a given root, who audits it, or who that root is allowed to issue certs for. Perhaps there's a market for an open-source root-store editor, that annotates each root with a plain-language description, including stuff like how many certs it has issued, and how many frauds and cock-ups it's been responsible for.
- spacebanana7 3y agoI wonder whether site operators could mitigate this by using SPF-like DNS records to say which cert authorities their site uses. It's of course possible for a sophisticated attacker to try to interfere with such a workaround but: 1) The DNS ecosystem is messy with OS, browser and cached records. This makes it very annoying and slow for attackers to target anything but individual users. 2) Browser vendors, if needed, could verify such DNS records in an EU free connection for most sites. 3) Scanners could compare DNS records to results in EU based browser requests and alert the public. 4) Sites with greater concern could additionally post information about which certs their site uses in other public locations like HTML meta tags, public databases, or even centralised locations like search consoles & app stores. This isn't as elegant as the current system of certificate transparency, but meaningfully raises the costs of MITM'ing connections in an environment where eIDAS is enforced.
- minimaul 3y agoThis sounds a lot like CAA records! https://datatracker.ietf.org/doc/html/rfc6844 https://datatracker.ietf.org/doc/html/rfc6844
- spacebanana7 3y agoNice! thanks for the reference
- denton-scratch 3y agoSo how's about the browsers/root-programme operators simply stop bundling a root store? Instead, they could hive-off their root programme into an independent operation. Make it possible for the user to choose which root store they want. Does EIDAS mandate that browsers must provide a root store? I occasionally pick over my root store(s) looking for government-run root-certs for governments I don't need to trust. But the names of those root certs aren't transparent; you have to research each one before you can safely distrust it. Most government-run roots are only needed by citizens of that country; e.g. countries that issue government electronic ID that you need for things like voting (which isn't that common). So I'd choose a minimal root store, and then perhaps add back groups of certs, based on what my specific needs were. This could be managed through a slick UI. It would be extra cool if browser manufacturers could restrict government-issued CAs to attesting subdomains of their CC-TLD. It's nuts that (e.g.) the Turkish and Hungarian governments can attest any domain they want.
- nerdbert 3y agoIf it doesn't exist already, surely this would be demand for this as a browser extension in the event that article 45 passes.
- denton-scratch 3y agoYeah, I've never tried to write a browser extension. I'd foul it up; but I'd be glad to help if anyone else wants to have a go. And it is needed now; there's no need to wait until this proposal goes through. The other side of the coin is that you'd then get a community of root-block lists (and root-add lists), like AdBlock lists.