4 ms·
I live in Norway, that is one of the many European countries that have a national eID system, and it's one of these things that might not make much sense if you
by einarfd 3y ago
I live in Norway, that is one of the many European countries that have a national eID system, and it's one of these things that might not make much sense if you haven't lived somewhere where its there. But if you've used to it. It's such a clear good thing, that being against it makes no sense.
I'll try to explain why it's such a positive, but it feels a bit like trying to explain why paying with cards is nice, to someone who had only used cash.
So at the moment, I'm in the process of moving to a new bank, and will be moving my mortgage, getting new credit cards, and closing my old bank accounts. I'll be able to do all of that, without signing and faxing documents around, but instead doing all that signing with my eID, or BankID which the Norwegian variant is called. I can also use this id system to login to the health care system, look at my prescription, or any other government service that's on the internet.
One simplified way of looking at these eID system is that they are a way prove that you are you, on the internet, that courts and the government believes in. That opens the door to services that just isn't possible without it.
- NoImmatureAdHom 3y agoThis isn't surprising to hear from someone who lives in a highly developed country like Norway, where you have very high (and obviously implicit!) trust in your government. I'd still argue the details of the implementation are very important and even in places where people trust their governments things like this should be approached with caution. But I'm not surprised. The same attitude doesn't make much sense if your government is a bunch of untrustworthy criminals with unchecked (or unevenly-checked power). Imagine being from Nigeria or China and wanting those governments to have more power and visibility! Nah.
- einarfd 3y agoI agree that the legislation need to be done properly, and be of high enough quality. But there is a lot of EU states, that have had these kind of systems for a long time, and would have experience with the pitfalls of this. If the EU manages to ruin eID in memberstates, with this legislation, that will probably enrage every citizens in countries that have them, let's hope the bureaucrats aren't that dumb. Since the article was in the context of EU, I was commenting in the context of countries in it, or comparable to it. I'm sure you are right. A bad government will be able to turn anything, including something like this, into a bad thing.
- schroeding 3y agoAs far as I understand it, the main problem / risk is not that it's an eID system (which many EU countries already have), but that government CAs are being introduced into browsers and devices without the possibility of removing them - even if those CAs don't conform to current CA standards like certificate transparency. We already have CAs from e.g. the German Bundesdruckerei in trust stores, that's not new, but those can be distrusted, if one wants to. The law may disallow this, and those CAs can be used to e.g. MitM TLS connections. See: https://blog.mozilla.org/netpolicy/files/2023/11/eIDAS-Industry-Letter.pdf https://blog.mozilla.org/netpolicy/files/2023/11/eIDAS-Indus... and https://nce.mpi-sp.org/index.php/s/cG88cptFdaDNyRr https://nce.mpi-sp.org/index.php/s/cG88cptFdaDNyRr
- einarfd 3y agoI was not aware of this part. Not being able to disable CA seems like a weird thing to add. In practice how much difference will this make, the list of trusted CA in browser seems to already be a bit of a problem? In any case what I want out of this legislation is that you can use an eID from country a in country b. That, that isn't possible is the main downside of the current setup.
- Thorrez 3y agoMajor browsers today only accept CAs that use certificate transparency. This law will force them to accept CAs that don't use certificate transparency. If a CA misbehaves, browsers will distrust it. That happened to Symantec, which was the largest CA. This law will prevent browsers from distrusting CAs that misbehave. https://news.ycombinator.com/item?id=38112520 https://news.ycombinator.com/item?id=38112520
- dvfjsdhgfv 3y agoTechnically, I can't imagine how this could be implemented. In the worst case, it would mean that everybody caring for privacy would use alternative builds. But realistically, a week after publishing the first browser with this kind of hostile certificate, we would have several hacks on how to disable it. It simply makes no sense at all.
- tomatocracy 3y agoI live in the UK. We don't have any form of national ID, let alone an online eID. Yet I can open a bank account entirely online without needing to sign or fax documents and I can also access my health records, file taxes, tax vehicles, apply for a new passport, etc online.
- belorn 3y agoFor the health/tax aspects, do you use a login with username and password, is it an smartphone app attached to your phone number, or something else?
- einarfd 3y agoSo how do your prove that you are you, and how robust is that against fraud? I was under the impression that the UK had a really old fashioned and clunky consumer bank sector. But that is just hearsay, so I might be wrong. The closest I've every been to a British bank, was getting a Curve credit card, where they wanted a picture of me and my passport. Which imo. Was hilarious and must be way to easy to forge.
- intunderflow 3y ago> The closest I've every been to a British bank, was getting a Curve credit card, where they wanted a picture of me and my passport. Which imo. Was hilarious and must be way to easy to forge. Yep, and this is standard operating procedure at pretty much every bank in the UK, and they wonder why they have to spend so much money on mitigating financial crime (not to mention employing people to review pictures of customers full time)...
- theshrike79 3y agoI've had friends be deadlocked getting an apartment in UK/Ireland 1. To get an apartment you need a bank account 2. To have a bank account you need to identify yourself 3. How do you do that? Provide them with a GAS BILL for your apartment - which you don't have. IIRC the deadlock in this case was solved by another friend loaning their bank account to bootstrap the system.
- raxxorraxor 3y agoProblem begins when every commercial site needs to have your eID. Banks are already forced to "know their customer". It could be a step to deanonymize the net broadly. Or restrict access where you haven't proven your age. We already see some of that today. I personally would always restrict usage to government services, but I doubt people will care about their privacy.