EU legislation eIDAS article 45.2 may force inclusion of insecure QWAC root CAs
securityriskahead.eu
securityriskahead.eu
The EU has recently acted untrustworthy. They're interested in breaching your privacy. The last attempt was made and thwarted just recently. I have to repeat, research the new copyright and other digital regulations and the voting shenanigans from 2018. The EU especially the unregulated EC is not trustworthy.
If the target domain has your country's TLD, you can compel your national registrar to manipulate DNS records, then get yourself a perfectly legitimate Let's Encrypt certificate for that domain.
Alternatively, you can go the direct route and approach one of the various private CAs in your country and force them to generate you the certificate you want.
But nowhere does it say what the actual vetting process for QWACs is and how it differs from the one of current certificates. Is that explained somewhere?
Also a bit disingenuous that nowhere on the page, they link to the actual specifications or discussions of the regulation, not even Wikipedia. All we get are some barebone definitions with a heavy dose of spin.
But of course they already have a cute ducky logo.
Right now, this just reads like a power struggle between browsers and EU, with browsers (or at least Mozilla) trying to style this as some kind of grassroots movement.
I'm tired of billion dollar companies pretending to be student protesters.
Wikipedia page on QWACs btw: https://en.m.wikipedia.org/wiki/Qualified_website_authentica...
The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for website authentication. Compliance with the requirements laid down in Annex IV shall be presumed where a qualified certificate for website authentication meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
[0]: page 35 from https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
Annex IV page 42
> Supporting QWACs will mean that browsers will have to support providers that issue them without independently vetting their security practices.
Think like EV-Certs, but now with more legally binding power cause you don't get them from some random private company but the government. Though admittedly that legal power is more of a thing when signing documents.
If Mozilla has EU-based physical locations, would they be fined? With seizing of servers, real estate, bank accounts, etc. on EU territory if the fines aren't paid?
What if Mozilla has no permanent physical presence on EU territory? Could they still be fined? What happens if they ignore the fine? Could Mozilla executives on vacation in Europe, or technical staff presenting at European conferences, be arrested?
Would EU-based websites be legally required to block Firefox user agents? Would they be required to implement network-level firewalling of websites for downloading Firefox? Would it become illegal for EU residents to donate to Mozilla, or would the EU banking system be obligated to divert those donations to pay Mozilla's backlog of EU fines?
Would individual users on EU territory be subject to fines or arrest for running a browser without the QWAC root CA? What if they changed the browser settings, or recompiled the source code, to remove the QWAC root CA from the trust list?
Would it be illegal for Firefox to put QWAC on the trust list, but implement some sort of local "security enhancement proxy" whose sole purpose is to deny access to sites that use the QWAC CA?
They will be included by other browsers. They can also make certain services dependent on this CA.
Some people still believe that s stands for security in https.
To me this sounds like "have a little duck next to the padlock, make users understand that not all encryption is alike" could be a solution.
What am I missing?
https://cabforum.org/baseline-requirements-documents/
But the OP webpage is so terrible that I’m really not sure what they’re talking about.
Additionally, eIDAS CA requirements and vetting have not been as strict as those in the CA/B Forum Baseline Requirements and the other documents related to DV/OV/EV certificate issuance.
Apart from that, there are known problems with QWAC (mostly related to name collisions, and the mostly manual process of vetting information being prone to errors), but that is generally a lesser issue than the above two.
Browsers would be forbidden from just deciding on their own to remove a root, but I imagine trust agents can lose their status and get removed from all browsers if they misbehave.
Decision on removal would lie with some EU agency though, not with individual browsers.
Do you have some more information about the actual differences between the requirements? I'd be interested to know and the article is certainly not telling them.
> mostly related to name collisions, and the mostly manual process of vetting information being prone to errors
What name collisions are those? If it's the old issue with confusing company names, the new certificates are supposed to contain a street address and a unique identifier to resolve that.