Rely on a third party like the US which has secret courts and gives a shit about EU citizen privacy, their property or their lifes?
Or give it in the hands of the industry? Which only has one motive: making money.
Or leave it unregulated with no safety for no one?
DNS is about trust. We need trust into this thing. And honestly: i would not trust DNS offered in China and most likely also not the US, or 99% of the carriers
One way or another, EU will force its way. Should it do it by e.g. empowering DIGIT to run root DNS servers?
They will for sure tender it off to a murky consortium, but at least there will be a positive political move.
Here's an even better and more logical idea - for those who have concerns about the current DNS root server arrangements, what specifically are they? And what would you propose as solutions to their perceived deficiencies? Bonus points if you can raise actual technical arguments and not just feelings.
DNS roots have worked flawlessly. The EU can just create EU roots and be in control of them and regulate those. Nobody is opposed to that. You can even enforce vendors to only include EU roots when selling devices in the EU (I’m against this personally) or to ISPs (I’m more okay with this). But as a person who loves the EU I’m very much opposed to enforcing EU values and views to 3rd parties.
Everyone should regulate and audit them. How we do with medical devices, and other stuff. The internet is no unicorn with special treatment.
The last paragraph is right until I think about my EU-WhatsApp trying to make connections in Singapore. They try to protect me as a citizen.
Exactly what problem would this law saw? So far all I am seeing are vaugue assurances and warm feelings but zero substance of how it would improve anything.
Indeed, if history is our guide any change is far more likely to hurt rather than help. Therefore it is incumbent on those seeking the change to defend it - how exactly will this law "improve" things. Please be specific and factual and leave feelings to the poets and philosophers.
Not every jurisdiction in the world is based on extreme fines (like the US) but many are build on strict regulations (like most European countries).
Personally, i cannot speak about the concrete law and nis 2 thingy.
If you want to ask my server, send me information in the protocol that says that you want me to meet a certain standard and I'll blackhole the request if I can't meet it.
This is how SSL/TLS works and it works well.
Any software that is used by EU citizens (downloaded from EU App Store or EU vendor website) should use EU DNS servers. (The user should be allowed to change the DNS on per device and per app lvl)
I’d be okay with that. And I think that solves your issue, my issue and EU’s issue.
Another approach is what we do with cars: we don't ban ICE cars, we have different "tiers" (Euro5, Euro6) of emissions and phase them out. We can do the same thing. Any device manufactured after 2020 will need to implement this "feature". It will take a few years to propagate but it is a very feasible approach.
(or maybe I'm not understanding the core problem...)
I'm not quite clear how that's different from ICANN? Ostensibly they're now "multistakeholder", but were under the United States Department of Commerce until 2016. And were infamously in denial about the GDPR impact to WHOIS.
To be clear, I'm not saying the EU proposal is in any way good, I have no idea. But this issue has been brewing for a while, and I don't think it's unreasonable to be critical of ICANN et al and preparing for eventualities. Even if it is the status quo, leaving a major part of the internet in the hands of some unaccountable NGO is a huge risk.
As it stands today, I can no longer reliably block hosts by domain name on my own network thanks to DOH.
You should be able to mitm all your own https traffic right? Not sure if that’s worth it though.
Please don't give them ideas. Not even the Kremlin has done that, although they did something similar with geolocation devices.
Otherwise I fully agree. If the EU wants to audit, they should establish their own root server infrastructure, pay for it and audit that. If I was a root server operator providing what is essentially a free service and this was enforced on me, I'd rather shut down or block EU netblocks than be bothered by EU cyber security auditors.
The implementation part will be tricky but not impossible. Heck ipv6 is still not rolled out and we actually need it. Do you think they will be able to do this faster?
I’m not at all opposed to the EU trying to regulate companies providing services to their citizens.
If you only regulate providers in the EU it’s a pointless exercise from the start, even if you don’t have a lot of ways to actually enforce your regulations.
>https://berthub.eu/articles/posts/how-tech-loses-out/
You wrote
>We barely develop any software here anymore. So even very European companies like like Nokia and Ericsson, that are now trying to tell us that they are building our European telecommunication infrastructure. They’re actually not, they’re getting that built by other people in other countries far away. Anything having to do with server and PC development and manufacturing, there’s nothing left of that in Europe anymore.
As far as I've been told, then there are R&Ds in e.g Cracow, Poland or Wroclaw (probably nor R&D) that actively recruit or even train people
What are they doing then?
Now, India on the other hand...
Why doesn't the EU simply provide a 'core' set of servers, which they operate to a high degree of fidelity and robustness so that 'should something go wrong' ... then the EU still has these resilient services to reply upon?
I don't see how someone doing a public service should arbitrarily come under such scrutiny.
My first question is are they or is this the authors view?
The proposed regulation – like many EU regulations – can also apply to non-EU entities. In this sense, the EU does try to exert extraterritorial jurisdiction.
However, this is constrained to the case where the non-EU entity targets people in the EU, so somehow participates in the EU market. The origins of this “targeting criterion” actually come from consumer protection cases, where it's easy to understand: if you advertise your goods or services to people in a particular country, you'll have to play by that country's rules.
there is not really any other way to play the geopolitical game sadly.
Every goverment on earth is doing this to keep themselves stable, some are just far more succesfull then others.
Let's see... the past year the was a big scandal because apparently multiple non-profits were selling the .ORG top level domain name for $1B. They got these top level domain for free from the US government (or some institution thereof).
I would certainly like the EU to regulate more of the Internet instead of it being an US territory.
They are completely separate entities.
If you dislike this go shout at ICANN. It’s was US organisation - now it’s a “private” one[1]
[1] https://www.icann.org/en/announcements/details/stewardship-o...
It doesn't seem arbitrary to me. The service provided exists in many EU countries, and therefore must eventually be harmonised. This is the prime directive of the project.
That's not a very good prime directive.
Don't regulate things that don't need to be regulated, i.e. unless there is a very material benefit from it.
If the EU is concerned about WW3 level resiliency for these services, they can accomplish that themselves with a few cord, 'hardened' services that meet their criteria. For 'regular operations' it seems we're going quite well right now.
Unless there is a threat posed by these heretofore independent operators ... then I'm don't see any obvious material benefit here.
I'm wondering if somehow these entities could be compromised in a way that makes them a problem, more so than just 'going offline', in which case, maybe there are some benefits.
There is a simpler solution rather than enforcing EU oversight over root DNSes.
[0] https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72172
These are independent operators, NGOs etc, services being 'used by EU citizens' not really 'targeting Europeans'.
From a liability perspective, to the author's point these services I suppose would have to just filter out European sources?
Why would they publish a regulation so obviously vague, full well knowing the reality on the ground?
Why wouldn't they use language that unambiguously places NASA etc. firmly 'in our out' of the regulations or, some criteria which they would be one way or another?
Seems odd.
Regards NGOs: just because you do not make money does not make you a saint.
Regards vagueness: if you want to survive in an agile environment without rewriting every second day, vagueness is the way to go.
So if the US comes out with "GDPR- The Next Generation" with similar mandates towards the EU would that also be "good"?
Asking for a friend.
Or the Hague invasion act which is pretty much that case (US soldier are protected abroad against international treaties).
In reality, the question is not whether EU citizens will use these services, but whether the operator of the service is targeting people in the EU, i.e. whether the operator intends or reasonably expects for EU people to use their service. A US service will most likely be fine if their reasoning goes something like this: (1) We primarily intend to serve connections from the US. (2) This expectation is reasonable based on our network topology. (3) But we don't care if someone else connects.
It would not be appropriate to exempt specific organizations since those organizations may change their targeting in the future. It already exempts most non-EU organizations, due to the criterion that they don't target the EU.
We had the same panicking in 2018 when the GDPR came into force and – quelle surprise – there are no fines for random international websites. The EU doesn't insert itself into your affairs if you don't insert yourself into the EU market.
> In order to determine whether such an entity is offering services within the Union, it should be ascertained whether it is apparent that the entity is planning to offer services to persons in one or more Member States. The mere accessibility in the Union of the entity’s or an intermediary's website or of an emailaddress and of other contact details, or the use of a language generally used in the third country where the entity is established, is as such insufficient to ascertain such an intention. However, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the entity is planning to offer services within the Union.
People also tend to forget that providing a service (in whatever fashion) doesn't exist in a vacuum, there are the services and then there are the consumers of those services and they might have certain freedoms and rights that the locality of the service in question might not honour. Take the right to control your data for example, the US isn't very good at providing that with the services they offer, and they'd rather not have that freedom and rather make those few percent more money.
The EU has a good amount of soft power, this is just testing testing it's waters in directing policy more directly. (other examples are the Iran deal after the US left, and Intervention in Africa)
Geopolitically, this makes a lot of sense, and i think the idea has good intentions, but the implementation of the law is where it falls short.
Is the latter part of this your conclusion and interpretation? I haven't looked at the source material but are you sure they aren't just referring to root servers operating in the EU or by EU companies. I find it hard to believe they would consider DoD servers within their jusrisdiction.