4 ms·
So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's be
by theonlybutlet 3y ago
So basically:
Governments are being given authority to create dodgey certificates,
Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and
Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up).
Or am I missing something?
- Astraco 3y agoI think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.
- sigilis 3y agoThe proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation. Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.
- devman0 3y agoSeems like moving to something like DANE would be a good way forward. Seems like having the site owners tell the public what cert should be expected via DNS with appropriate signatures would obviate the need for CAs. (Yes I realize that this just moves the trust anchor to the DNS root authority, but it does reduce the number of authorities you need to trust).
- JoshTriplett 3y agoLots of things would help protect against this, but this regulation purports to prevent the browser vendor from implementing any stronger security mechanisms than those specified by the regulation. If DANE prevented a certificate from one of these governmental CAs from being accepted, this regulation would try to prevent using DANE.
- djantje 3y agoYes, that looks like to be the idea, to keep an option for a man in the middle attack.
- foota 3y agoI wonder if this would require browsers to allow government certs in place of their own pinned certs (e.g., chrome pins certs for google sites and maybe others I believe, if a non matching cert is used then the connection is rejected).
- theonlybutlet 3y agoWell sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certificate authority wise up to it's use, they've then got to prove it's causing harm and get approval from authorities to remove it (authorities can take their sweet time responding to the request).
- foota 3y agoSorry, I mean, browsers today ship with a list of sites that specify a cert that must be in the chain for it to be considered valid, e.g., only trust a facebook.com cert if it's from XYZ CA. Depending on the wording of the law, it seems like it could require browsers to ignore this requirement for government issued certificates, hence bypassing the cert pinning and allowing them to intercept traffic to e.g., Facebook. I'm not sure how many sites do this, I think Google's own do, and maybe some of the other big names use it as well, but I'm not certain.
- theonlybutlet 3y agoSorry I see what you're saying, I think you're right. Perhaps a browser fork for non-EU folk? Far from ideal.
- DyslexicAtheist 3y agospot-on. it helps to recall that ETSI, despite being some opaque standards org is made of people[1] like you and me (many not in Europe) who helped draft this abomination of a standard. This is disguised as digital identity but the interest groups are mostly law-enforcement, and the same crowd that is pushing "chatcontrol", and "regulating cryptography". This "secret list" of experts is here[1]. And here is Tanja Lange's (repeated[2]) warning on this proposal: >> I'm contacting you @LalicVedran & @JerkovicRomana about eIDEAS - as a cryptographer & concerned citizen. As said in eidas-open-letter.org/ & I presented in detail at the ENISA Article 19 working group it doesn't suit an open society to mandate trust. https://hyperelliptic.org/tanja/vortraege/QWACs.pdf https://hyperelliptic.org/tanja/vortraege/QWACs.pdf When Kazachstan[3][4] made people install a certificate in their citizen's browsers we (rightly) called them "Banana Republic". Look who is the Banana Republic now. [1] Patrick Breyer on Twitter Nov 6th (in German) https://nitter.cz/echo_pbreyer/status/1721558594129219912 https://nitter.cz/echo_pbreyer/status/1721558594129219912 [2] Tanja Lange on Twitter Nov 5th https://nitter.cz/hyperelliptic/status/1721215011799142791 https://nitter.cz/hyperelliptic/status/1721215011799142791 [3] Kazakhstan to MitM all HTTPS traffic starting Jan 1 (2015) https://news.ycombinator.com/item?id=10663843 https://news.ycombinator.com/item?id=10663843 [4] MITM on HTTPS traffic in Kazakhstan (2019) https://news.ycombinator.com/item?id=20472179 https://news.ycombinator.com/item?id=20472179
- da39a3ee 3y agoNice that the person from GCHQ is called Crispin.
- izacus 3y ago[flagged]
- theonlybutlet 3y agoThis is an interesting point of view. This also pertains to root certificates in browsers however. Would a better way be not to setup a body to monitor certificates issued to police certificates for their own CA and ensure any offending certificate is immediately removed and to bring in laws to penalise the offending CA. Instead they're prying a new threat vector open wide.
- izacus 3y agoYeah, I'm not sure if I fully agree with the method here either - it feels like it was helped by law enforcement a bit too much. But I did want to make a point about why such paragraph exists and why it's not acceptable for EU to delegate CA policing to non-governmental industry bodies.
- negidius 3y agoIt would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply by the threat of import bans, etc. That would make their less technologically sophisticated customers vulnerable to completely unnecessary risks. The EU might not think the risks are unnecessary because they gain "sovereignty", but that only helps the EU and their member states, not 99.999% of the people who live in their territory. Ultimately, I don't think this will be implemented. They can scream "sovereignty" as much as they want, but everyone else has an incentive to resist, and it would be even more harmful to their perception of sovereignty if both Microsoft and Apple say no and the EU faces the choice of either banning 99% of computers on the consumer market (and still be unable to force the remaining open source alternatives to meaningfully comply) or backing down to foreign organizations after a public confrontation.