I'm very doubtful though that trying to just directly legislate how software universally works though bypassing process is a good idea. Massive room for abuse as well.
Having a standard for Identity Management seems reasonable. Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen.
That may not be the step in between "collect underpants" and "profit" but it feels like it's coming. In the U.S., I'm sure something like this will be sold in the clothing of think-of-the-children.
They didn't mandate that though, the proposal was that it should be possible to use it, not that everyone should be forced to use it. You would still be able to log in using other means.
Basically, facebook would be required to provide you with the option to use e-id to log in. But you could still log in with other means. It just gives you more freedom.
South Korea already has these retirements for (some of) their video games.
That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign in with Google” and require such sites also offer a “Login with EU” option.
Source: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=COM%3A20...
That means there is nothing preventing $TSP from forging my certificate, and giving it to criminals/government-agents, and nothing to keep the TSP in line, because the single audit constraint is "Keep the Minister satisfied".
I personally don't have a problem with the idea of replacing passwords with user-certs, provided I get to generate my own cert with my own private key. But the evidence is that general users can't learn how to use certificates.
I hate passwords, but I'd rather use passwords than a user-cert issued by an unreliable CA.
So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus?
You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?
The eID certificates do come with probative (legal) effect, but this is where it gets complicated.
If the CA is hacked or screws up, yes, the CA is liable. But only if you did everything you were supposed to, such as checking every element of the certificate. These certificates have a variety of fields, such as “liability only up to XX euros”, and you (the site or user) are liable if you use it for more than that.
PSD2 has shown that the standards are a nightmare to fully implement. https://wso2.com/blogs/thesource/all-you-need-to-know-about-... gives a useful overview of how it’s worked for PSD2, and the new Digital Identity Framework/eIDAS Revisions proposes to make that the approach the standard everywhere.
In practice, this means that the server accepting your certificate needs to implement all of this correctly (spoiler: they don’t), or they bear the liability if the CA gets hacked - and they can’t distrust that CA. It also means the CA potentially learns every site you visit, because the sites have to check with the CA (if using OCSP).
Of course, if the government themselves directed the CA to misissue - e.g. at the direction of law enforcement - no such liability would be presumed, because it was a presumably lawful issuance.
Source: https://www.enisa.europa.eu/publications/qualified-website-a...
Do you expect that everything runs like an extremely powerful well oiled machine, where 100% interoperability likely means complete surveillance? A seemingly technocratic dystopian reality where every impulse is quantified and catalogued? I think its naive to believe that governments don't want more money, power and control over its citizens and government likely will be extracting more with every optimization the system makes.
Or would you rather an extremely powerful machine that is disjointed, highly flawed and laden with inconvenience in-so-that society doesn't really know who you are? Where the individual has more freedom and liberty, but as a result there is more crime and less "safety". A world where powerful anti-social forces are at play, such as disinformation campaigns, polarization of discourse, fringe movements and revolution.
The commonality is they are both driven by technology. We have built an extremely powerful machine and that has introduced enormous complexity into our society. This complexity equates to entropy and either we pull it together with draconian government policy, or the system unravels.
In the past we've been able to out-innovate and maintain moral leadership thru a fictional aspiration to democratic norms. Now state actors can run finely targeted propaganda campaigns and measure our engagement with them in real time while using extensive censorship measures to prevent us from doing the same to their populations.
None of this invalidates your point, but the tables have been tilted and abstract discussions of freedom tend to avoid wrestling with the geopolitical ramifications.
Due by whom, and for what?
My identity is just fine, but thanks for your concern :)
I can walk into my local bank branch and ask to either pay in or withdraw money and they don't ask for any kind of ID(!), or my account number, becuase they actually know me :) They even tend to say "Hello $firstname" when I walk in, even if I only called in to use the ATM.
Amazing how good ol'fashioned _offline_ identity can actually be secure.
Try walking into my local branch with faked ID of me and attempting to withdraw funds from my account.
Personal trust as a foundation for identity became an untenable option as soon as the modern age arrived and our world expanded beyond our immediate geographic area.
Eventually every system boils down to personal trust, from the doctor that certifies you were born, to the person looking at the computer screen in a licensing office who is deciding if she is going to issue the license. There is no escaping this.
Suppose I have my personal QWAC installed in my browser. Does this mean that I won't be able to visit $BIGSITE without authenticating and logging-in?
That wouldn't make things more efficient - it would create friction, because I'd have to switch browsers if I wanted to visit a site that I didn't want to authenticate to; or do some settings fandango to disable QWAC before clicking a link.
The implementation is not that different from the "log in with Google/Facebook/Twitter/MySpace/Apple" buttons on many websites, though the login procedure is a bit more involved because of the sensitivity of the data.
There are some citizens who want this. Not all.
> a poor implementation doesn’t guard against overreach.
A good implementation enables overreach as in, "Please confiscate everything belonging to John Q. Public." An effective identity enables government overreach.
This cure is worse than the disease.
You're entitled to your opinion but for me, it's a firm "No, thanks".
I feel considerably more comfortable* carrying a paper document which proves my vaccination/negative test than I do using any kind of government-approved app on my phone.
* that's putting it mildly
Yes, a common electronic ID is an absolute godsend. Can't wait for it to be implemented on every fricking public administration website.
If you care about limiting infections, get tested.
If you care about freedom, reject government certificates.