5 ms·
I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries i
by Astraco 3y ago
I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.
- sigilis 3y agoThe proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation. Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.
- devman0 3y agoSeems like moving to something like DANE would be a good way forward. Seems like having the site owners tell the public what cert should be expected via DNS with appropriate signatures would obviate the need for CAs. (Yes I realize that this just moves the trust anchor to the DNS root authority, but it does reduce the number of authorities you need to trust).
- JoshTriplett 3y agoLots of things would help protect against this, but this regulation purports to prevent the browser vendor from implementing any stronger security mechanisms than those specified by the regulation. If DANE prevented a certificate from one of these governmental CAs from being accepted, this regulation would try to prevent using DANE.
- djantje 3y agoYes, that looks like to be the idea, to keep an option for a man in the middle attack.