4 ms·
For those wondering why some cybersecurity experts are concerned, from Wikipedia (https://en.wikipedia.org/wiki/EIDAS#Man-in-the-middle_attacks_and_mass_surveil
by GranularRecipe 3y ago
For those wondering why some cybersecurity experts are concerned, from Wikipedia (https://en.wikipedia.org/wiki/EIDAS#Man-in-the-middle_attacks_and_mass_surveillance https://en.wikipedia.org/wiki/EIDAS#Man-in-the-middle_attack...):
> In 2023, a change was proposed to eIDAS that would allow any EU government to surveil all internet communication, even when encrypted.[..]
> The proposal would force internet companies to place a backdoor in web browsers to let them perform a man-in-the-middle attack, deceiving users into thinking that they were communicating with a server they requested, when, in fact, they would be communicating directly with the EU government. The EU government would then read and change their messages before passing the possibly modified message on to the intended recipient.
- lock-the-spock 3y agoThis is quite an absurd summary, both legally and technically simply nonsense. And eidas is about digital identity management, this critiqued part is just s tiny part of it, not a main feature, so this is not "what eidas is about".
- GranularRecipe 3y agoValid criticism. I removed the snipped "what eIDAS is about" from my comment. I think the criticism raised is not (solely) against digital identity, but about possible security risks associated with it.
- lock-the-spock 3y agoThank you. I think the criticism is really just about the certificate requirement. I just don't see what other part of eidas could be considered to MitM anyone. But of course only the author would know for sure what they meant.
- Vinnl 3y agoThat is indeed why they keep referring to Article 45 - the specific article of concern. If that was removed, presumably this new version of eIDAS would be fine. (And an existing version has already been in effect for a while, if I understand correctly.)