Mozilla publishes position paper on the EU Digital Identity Framework
blog.mozilla.org
blog.mozilla.org
A negative security example that comes readily to mind are how bad government policies/standards helped cement for a long time the awful practice of complex password requirements including rapid change requirements, "security questions" and so on. These are actively negative for security, people in the field realized pretty fast (and of course many argued from the start) that the only reqs for passwords should be some minimum length, not using previously exposed ones, and having a sufficiently high maximum length that everyone is free to use more comfortable ones like diceware if they wished. While that has been getting revised at last bureaucracy still moves much too slowly there.
Of course this hasn't made it through the gauntlet and hopefully won't, but I'm glad to see it getting some attention.
They did, you don't have to imagine it.
In 2009 they've signed a memorandum of understanding with 14 phone companies, which is why micro-B was the standard before type C. Apple was within those that signed it, and used a loophole in the text to ship a lightning-to-micro-B adapter instead.
Around 2016 they've realised micro-B was outdated and notified the signatories that they should switch to type C.
https://www.macrumors.com/guide/eu-charging-standard-proposa...
> The recent 582-40 parliamentary vote in favor of a common charging standard came about because the European Commission's previous approach of merely "encouraging" tech companies to develop a standardized solution "fell short of the co-legislators' objectives," according to a briefing on the European Parliament website.
The first phones with USB-C came out in 2015. If this MoU was instead binding legislation, those USB-C phones never would not have been allowed.
> To address the challenges for consumers as well as the environment, the Commission has supported a common charging solution for mobile phones and similar electronic devices since 2009. The Commission first facilitated a voluntary agreement by the industry in 2009 that resulted in the adoption of the first Memorandum of Understanding (MoU) and led to reducing the number of existing charging solutions for mobile phones on the market from 30 to 3. Following the Memorandum's expiration in 2014, a new proposal by industry presented in March 2018 was not considered satisfactory in delivering a common charging solution or meeting the need for improved consumer convenience and e-waste reduction.
https://ec.europa.eu/commission/presscorner/detail/en/ip_21_...
A shortcoming for _their_ goals. Their goals are at odds with what is best for us. It is a good thing the micro-b MoU did not have any teeth.
If I can charge my laptop with it, it's surely good enough for charging devices with a much smaller battery at least for the next decade or so.
E-waste is a direct consequence of technology progress. We're not still all using 486s. Technology advances, people want that new stuff.
I would wager charging ports are insignificant.
But I wouldn't call it significant, I would call it completely unnecessary. I'd really rather buy one when I need it than get one with every single gadget I buy, which is precisely what the EU is trying to achieve.
It would be another thing if I was on Apple ecosystem.
The only reason to get a new charger is if you need more power, but that’s exactly the same situation as with Android. Where did you get the idea that you had to get new chargers?
But they didn't. These people aren't that dumb, they told companies to settle on a standard, and now that we have a good standard that basically everyone follows they want to make a law to ensure everybody follows it. Bringing up a scenario where they did the right thing and argue "just imagine if they didn't do the right thing here, that would be a problem!" isn't a strong argument.
The new tech would prove itself, somehow, and then the standard changed over after there's evidence that the new tech improves more than the cost of the change!
The only way to ‘prove’ that a tech is better than another is by letting the market decide.
Apple doesn't follow it. Also the reason companies settled was that EU threated them with regulations, if they didn't follow through when some companies (Apple) misbehaves it would mean that such threats would lose teeth and wont solve future problems. So if anything the problem here isn't EU, the reason that law is coming is Apple. Best possible scenario is that companies dynamically create new standards and fall inline, but Apple refuses to play along so regulations are necessary.
They did follow it. The initial agreement was about chargers, not cables, and you can charge any iPhone off any usb charger. Now, we can discuss the spirit versus the letter, but they signed the agreement and followed it.
The analogous scenario is a phone with 2 charging ports. The legacy usb-c alongside the newer port you would actually want/use.
Q: Do network operators/SIM card (re)sellers still have to support 2G, or just the phone manufacturers?
After a while, almost all phone also have usb-C, most people like usb-C, so the industry can petition to replace micro-B with usb-C.
Are there any examples where the EU mandates legacy stuff that is no longer useful, but still has to be kept anyway?
Not that I have ‘the answer’ just that it’s a hard problem.
I quickly glanced at a couple of the feedback documents they've got so far, and they seem to echo your concerns. We'll see if the parliament makes any changes.
There is a rather significant and major issue that this change highlights; essentially all our politicians and bureaucrats see themselves as smart and wise enough to be central planners and masters of the universe … when the truth could not be farther from it.
It's a less complicated issue, while nuanced, I think most of the details are manageable by a willing political actor.
It's also a known quantity.
This MOZ paper deals with much more complicated things.
I'm wary of involvement, I wonder if there are industry-led solutions that could be supported.
If MSFT, G, FB, AMZN could agree on something with the blessing of the EU and indirectly the US, I wonder if would happen very quickly.
> But forcing everyone to use it until the end of time is ridiculous.
Correct, it is ridiculous you think anyone did that.
> Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.
They did. We do have usb-c.
HTTPS basic auth is secure and should always be an option. There, perfect interop.
There is not enough trust and political currency to accept such measures in my opinion. Formalized ID systems seem to net more attack vectors than what we currently have.
So this proposed regulation mandates that my browser must support QWAC, and include TSP roots? Does that mean that browsers MUST deprive me of the ability to control my root store? Would I be in violation if I modified my (open-source) browser so that it was no longer in compliance?
Supposing I published my patch on a website outside the EU (e.g. in the UK)?
To be clear, I don't want a root cert from any entity that is effectively controlled by a government, to be trusted by my browser. Some governments bother me more than others, (for example) a Turkish government-controlled CA was caught forging certificates. There's still a Turkish CA in there, I see; Debian have seen fit to remove it.
It's all fine, the sky won't fall. As long as I can still decide who I trust.
> To that end, web-browsers should ensure support and interoperability with Qualified certificates for website authentication pursuant to Regulation (EU) No 910/2014. They should recognise and display Qualified certificates for website authentication to provide a high level of assurance, allowing website owners to assert their identity as owners of a website and users to identify the website owners with a high degree of certainty.
Edit: It also limits this to larger web browser providers in another part and only after 5 years. So people are free to run their own forks of browsers, so I doubt that it will be forbidden for browsers to just have a setting for specific sets of certs.
And then mandate sites use it for any age restricted content? Comes a year later. And everything against a backdrop that some EU members want encryption backdoors. Meanwhile we have safe e-commerce for years. No, thank you.
A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just this month you have to check-in with the government before you can enter a restaurant. (only temporary, surely) It's designed to manage people like livestock, and we all know that some pigs are more equal than others. Even vax passports and so-called "mandates," have exploited loopholes in our high trust societies and assumed formlessness as to avoid being challenged legally. Digital identity regimes will use the same indirect methods. This is their strategy.
Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it.
Civilization doesn't survive malicious institutions that turn inward against the people they serve, and I hope other technologists think seriously about identity and consider the consequences of it falling into the hands of an enemy or evil institution, because having worked in identity, I guarantee it will.
I don't understand this argument at all. In what way does the economy require that people take on risks of identity theft when they trade with each other? I don't see a single instance of trade being limited even if all transactions were between established identities.
There are other issues of tight tracking of course, but I don't see this one.
I personally don't want my identity checked unless I'm asking someone to trust me. And I'd rather use a trust-minimizing system before going there. You don't need your id checked when going to the restaurant or the theater. You need to check someone's id when they take your money and promise you something in return (and even then, there may be a better way).
> I don't see a single instance of trade being limited even if all transactions were between established identities.
Do you buy something if you need to send a copy of your id? Do you use a website if it requires Facebook connect?
The issues of tight tracking you mention would be amplified by widespread use of id checks so I think it's essential not to do them often.
I can see an objection to erasure of cash, but not these identities.
There's generally two buckets of biometric auth:
1. Local biometric auth, with no metrics shared outside the local context, for convenience in authentication. This would be FaceID/TouchID/Windows Hello sorts of functions
2. Remote biometric auth to prevent certain types of 'friendly' impersonation, such as using a family member's identity for an age or background or credit check. This is say comparing a live camera capture against a previous photo.
You see #2 a lot in identity proofing, e.g. I presented an official document and it is legitimate, but how do they know it's actually the right person vs someone who did some lucky dumpster diving?
For digital identity credential systems which represent those documents, you have both cryptographic document verification and typically have a form of authentication by proof-of-possession of some key, but often people still feel the need for a remote biometric check. The reality is that they should be basing that on an actual need.
The real problems in identity proofing are things like task delegation, substitute decision makers in elder care, parents doing things on behalf of their kids and kids asserting their parents permission, federation of user attributes with privacy, etc. These aren't difficult technical problems, except you need some way to transfer risk and accountability, which is an absolute quagmire. Universal digital identity (because let's face it, that's what it necessarily is) approaches these problems with a necessary component of a solution, but that's not what it's mainly going to be used for.
Maybe this yields a thought experiment where let's say I write an app for parents and kids where kids can use it to show they have their parents permission to be in a park after dark, walk to school by themselves, participation in a class trip, travel by themselves on a train or plane, get consent for emergency medical procedures, etc. Then that kid grows up and it switches from their parents to being a drivers license, age of majority card, school graduation certificates, their last STD test, list of employers and past salaries, speeding tickets, criminal records, lowest rated tweets, sexual partners etc. Sounds like it could be a real product right? Except that kid never wanted the stupid app that monitors them, the hovering parents who imposed it on them just use them as a source of narcisistic supply, and then their entire life is one of being subject to some proxy for these helicopter parents. The app is capitivity, or more accurately, entry into a panopticon that deprives them of their basic humanity. This is why digital identity is a terrible idea in pretty much every version I've seen so far. It's not chosen, it's imposed, and that's not a product, that's a mandate laundered through tech.
Interesting to see the EU choose the path of Kazakhstan.[0]
[0] - https://www.internetsociety.org/news/statements/2019/interne...
I'm very doubtful though that trying to just directly legislate how software universally works though bypassing process is a good idea. Massive room for abuse as well.
Having a standard for Identity Management seems reasonable. Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen.
That may not be the step in between "collect underpants" and "profit" but it feels like it's coming. In the U.S., I'm sure something like this will be sold in the clothing of think-of-the-children.
They didn't mandate that though, the proposal was that it should be possible to use it, not that everyone should be forced to use it. You would still be able to log in using other means.
Basically, facebook would be required to provide you with the option to use e-id to log in. But you could still log in with other means. It just gives you more freedom.
South Korea already has these retirements for (some of) their video games.
That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign in with Google” and require such sites also offer a “Login with EU” option.
Source: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=COM%3A20...
That means there is nothing preventing $TSP from forging my certificate, and giving it to criminals/government-agents, and nothing to keep the TSP in line, because the single audit constraint is "Keep the Minister satisfied".
I personally don't have a problem with the idea of replacing passwords with user-certs, provided I get to generate my own cert with my own private key. But the evidence is that general users can't learn how to use certificates.
I hate passwords, but I'd rather use passwords than a user-cert issued by an unreliable CA.
So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus?
You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?
The eID certificates do come with probative (legal) effect, but this is where it gets complicated.
If the CA is hacked or screws up, yes, the CA is liable. But only if you did everything you were supposed to, such as checking every element of the certificate. These certificates have a variety of fields, such as “liability only up to XX euros”, and you (the site or user) are liable if you use it for more than that.
PSD2 has shown that the standards are a nightmare to fully implement. https://wso2.com/blogs/thesource/all-you-need-to-know-about-... gives a useful overview of how it’s worked for PSD2, and the new Digital Identity Framework/eIDAS Revisions proposes to make that the approach the standard everywhere.
In practice, this means that the server accepting your certificate needs to implement all of this correctly (spoiler: they don’t), or they bear the liability if the CA gets hacked - and they can’t distrust that CA. It also means the CA potentially learns every site you visit, because the sites have to check with the CA (if using OCSP).
Of course, if the government themselves directed the CA to misissue - e.g. at the direction of law enforcement - no such liability would be presumed, because it was a presumably lawful issuance.
Source: https://www.enisa.europa.eu/publications/qualified-website-a...
Do you expect that everything runs like an extremely powerful well oiled machine, where 100% interoperability likely means complete surveillance? A seemingly technocratic dystopian reality where every impulse is quantified and catalogued? I think its naive to believe that governments don't want more money, power and control over its citizens and government likely will be extracting more with every optimization the system makes.
Or would you rather an extremely powerful machine that is disjointed, highly flawed and laden with inconvenience in-so-that society doesn't really know who you are? Where the individual has more freedom and liberty, but as a result there is more crime and less "safety". A world where powerful anti-social forces are at play, such as disinformation campaigns, polarization of discourse, fringe movements and revolution.
The commonality is they are both driven by technology. We have built an extremely powerful machine and that has introduced enormous complexity into our society. This complexity equates to entropy and either we pull it together with draconian government policy, or the system unravels.
In the past we've been able to out-innovate and maintain moral leadership thru a fictional aspiration to democratic norms. Now state actors can run finely targeted propaganda campaigns and measure our engagement with them in real time while using extensive censorship measures to prevent us from doing the same to their populations.
None of this invalidates your point, but the tables have been tilted and abstract discussions of freedom tend to avoid wrestling with the geopolitical ramifications.
Due by whom, and for what?
The implementation is not that different from the "log in with Google/Facebook/Twitter/MySpace/Apple" buttons on many websites, though the login procedure is a bit more involved because of the sensitivity of the data.
There are some citizens who want this. Not all.
> a poor implementation doesn’t guard against overreach.
A good implementation enables overreach as in, "Please confiscate everything belonging to John Q. Public." An effective identity enables government overreach.
This cure is worse than the disease.
My identity is just fine, but thanks for your concern :)
I can walk into my local bank branch and ask to either pay in or withdraw money and they don't ask for any kind of ID(!), or my account number, becuase they actually know me :) They even tend to say "Hello $firstname" when I walk in, even if I only called in to use the ATM.
Amazing how good ol'fashioned _offline_ identity can actually be secure.
Try walking into my local branch with faked ID of me and attempting to withdraw funds from my account.
Personal trust as a foundation for identity became an untenable option as soon as the modern age arrived and our world expanded beyond our immediate geographic area.
Eventually every system boils down to personal trust, from the doctor that certifies you were born, to the person looking at the computer screen in a licensing office who is deciding if she is going to issue the license. There is no escaping this.
Suppose I have my personal QWAC installed in my browser. Does this mean that I won't be able to visit $BIGSITE without authenticating and logging-in?
That wouldn't make things more efficient - it would create friction, because I'd have to switch browsers if I wanted to visit a site that I didn't want to authenticate to; or do some settings fandango to disable QWAC before clicking a link.
You're entitled to your opinion but for me, it's a firm "No, thanks".
I feel considerably more comfortable* carrying a paper document which proves my vaccination/negative test than I do using any kind of government-approved app on my phone.
* that's putting it mildly
If you care about limiting infections, get tested.
If you care about freedom, reject government certificates.
Yes, a common electronic ID is an absolute godsend. Can't wait for it to be implemented on every fricking public administration website.
That is, if a QWAC is issued by a CA that is not part of the browser root store, it must not be rejected (as any other untrusted certificate would be).
Deeply worrying, yes, but not unexpected.
> This is because through Article 45.2, the legislative proposal, in effect, mandates that browsers automatically include Trust Service Providers (TSPs) in their browser root programs.
I haven't read the law in question but I would take "mandates" to imply that doing the opposite is somehow prohibited by the proposed law.
Why should a foreign country have control over my interests?
Why should Mozilla DECIDE what I should and shouldn't trust?
I am very glad that the public opinion decided to not trust Firefox at all (3% market share today)
For example, imagine if all big browsers everyone uses where made in China, and mostly just trusted Chinese CA. Do you think that would be a problem? Do you think the rest of the world would just let that happen instead of starting to regulate it? That is the situation EU faces right now with American browsers.
EU is safe in that way since the people making the legally binding laws to enforce them aren't the same people making the EU laws, so everything has to go through at least two levels of elected representatives to actually take effect. This means that if EU wants to spy on you then your country can block it, and if your country wants to spy via this system on you then they have to get approval from EU at least. Either way EU is an improvement over just having your local representatives.
The EU itself says so:
- https://ec.europa.eu/info/law/law-making-process/applying-eu...
- https://ec.europa.eu/info/law/law-making-process/applying-eu...
I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech. Regrettably I would not be surprised if EU took a more authoritarian stance.
I understand the issues mentioned in passing scammy actors as legitimate but, in which way your rights to speech would be vulnerated?
https://en.wikipedia.org/wiki/Compelled_speech
Whether or not it would violate the 1st amendment would be up to the courts to decide.
That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA". Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the CA; to boycott a CA; to implement this in code and ship it.
[0] https://crsreports.congress.gov/product/pdf/IF/IF11072 ("The First Amendment: Categories of Speech")
Nothing so far says that Mozilla can't tell its users that EU trusts this but Mozilla doesn't. However it is clear that it is intended to force Mozilla to at least gives the user the choice to trust EU on this.
The decision of trusting or not trusting a CA has an expressive character; it's not pure machine math. Some of the decisions are political speech, even: "we don't like the policies of country X, therefore we'll boycott their root certificate". (Roughly characterized)
You might object to this for other reasons, but free speech isn't a good reason.
To compound problems legal entity names are not required to be unique across states or countries so an EV certificate for a popular company name can be obtained in another geography and presented to the user on an attacker controlled domain.
https://www.bleepingcomputer.com/news/security/extended-vali...
Care to expand on this? I have a hard time making any sort of connection.
Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must behave. Would e.g. making a fork of Firefox that does not comply with this digital identity framework be illegal? Or is this just hyperbole from Mozilla, and the browser would be merely non-compliant?
Why not? They publish directives that result in criminal law in member states all the time.
A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.
Key word "such". Prescribing which certificates I am obligated to trust is many many steps beyond e.g. banning DRM circumvention (which is itself a step too far IMO).
No, this only applies to medium to large companies shipping browsers and they only have to follow it after operating for 5 years. If you fork a browser and edit it then that is working as intended, and if you fork it and distribute binaries that is also ok since you aren't a medium big company. Possibly the company label refers to CA or site, but the 5 year window gives you plenty of time to refork every 5 years in the worst case, and this only apply if you operate as a browser provider so you can use it yourself forever.
"Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services"
Those of us not within their bounds could just decide not to comply with their nonsense, and there isn't a great deal that they could actually do about it.
Instead we're letting Europe pull a California, to the detriment of the entire internet.
There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true.
However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me.
Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser decides to reject certificates used by that country's government.
Of course, it would be nice if country certificates could be restricted to country specific resources. Maybe mozilla should push for that.
Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc).
There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a fancy logo makes the site any safer.
That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.
Amusingly, Mozilla rejected the US government's request to add the federal PKI to the root store.
https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...
Furthermore, I have seen nothing wrong in mozilla's stewardship of the root certificate program in the decades it's been running, whereas mozilla points to deficiencies in the EU's certificate programs. This is to be expected since running a root store is not one of the EU's specialties. I would trust that government most that defers to private companies in areas where they lack expertise.
Is that really a question to be taken seriously? One is a private organization, completely unaccounted for and in a foreign jurisdiction, who sets their own rules and follows up on themselves.
The other is accountable and audited by independent auditors in a system which upholds separation of power and keeps independent media?
(Just to clarify: Neither Mozilla or anyone else should accept QWAC or any other standard in the face of legitimate concerns, of course. That's not what trust means.)
There is nothing intrinsic to any system of government that would make any of them good at solving technical issues on their own.
It could weaken protection for people in the EU, but then the way forward is to make requirements for root certs mandatory in the EU.
Maybe I missed it, but did the document require special UI elements for EU certs?
https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...
I can't speak with authority, but my reading of PKI issues suggests Google is just as strict, while Microsoft and Apple are less strict. However, that just might be because MS and Apple are less public with their root programs.
For example, QWACs cannot legally be automated (e.g. via ACME), because of certain restrictions applied to needing to validate the natural or legal person making the certificate request. This actually was an issue for one CA (BuyPass) that tried to support ACME but ran afoul of the framework.
While originally QWACs were proposed as optional, regulation such as PSD2 attempts to make them mandatory for (financial services) servers to obtain. If one of those keys is compromised, then the server wishing you obtain a replacement certificate may have to wait weeks to obtain such a certificate, or make an in-person visit to the CA (e.g. the post office).
A considerable number of compromised or misissued certificates have failed to been revoked on the industry-agreed upon timelines (24 hours or 5 days, depending), because of challenges CAs have faced because their customers haven’t (or legally can’t) automate replacement, and because the additional information in the certificate requires manual validation, despite having no technical impact on the TLS connection.
I get QWAC goes against the trend of phasing out EV certs. But isn’t the real issue that the browsers don’t trust TSP audits carried out for EU member states?
Similarly, automation affects how easy or hard it is to replace a CA, for example, if moving to distrust a CA. If you rely on QWAC attributes, you can only use QWAC CAs, and changing CAs becomes significantly more complex.
The audit issue is definitely an issue: the audits used are fundamentally different than what browsers try to achieve, and so having to adopt the lower standard definitely impacts user security. However, my point was that in addition to those concerns, the technical design itself results in less robust and less agile systems, and that makes things less secure.
In some sense, Firefox could be an exception, because Mozilla doesn't seem to do a lot of advertising in the EU.
It is not like Apple, Google, or Microsoft can say: we don't really care about the EU, we just remove the browser from products we distribute (directly or through third parties) in the EU.
But the way I understand it, a QWAC is an identity certificate, issued to users, not to websites. AIUI, websites are to be compelled to accept such user-certs in lieu of a password. Well, I don't see what that has to do with the contents of the root store - that controls the website identities that my browser will accept, not the user-identity that the website accepts.
I read the position paper, but not the regulation. I'd like to see a better explanation of the regulation.
[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
Can't they focus on their broken system first?
I agree Firefox could be better, but time spent on effective lobbying which will help all browsers is well spent.