EFF about EU: EIDAS 2.0 Sets a Dangerous Precedent for Web Security
eff.org
eff.org
Is that correct?
Long story short, this isn't about asking browsers to ignore flawed procedures or lacking security. Incompetence is always a factor and this law won't allow for more incompetence than we're already used to from private CA's.
This is about preventing browsers from distrusting government-controlled CA's issuing certificates used to MITM traffic. EU's trying to do what Khazakhstan (IIRC, could be one of the other -stans) did a few years ago).
I'd like to say that in a democracy the use of such powers are limited, but every so often I find myself disappointed by news that such powers are directed at protesters in the UK, and my news about the US leans towards "gosh don't these police cars look suspiciously more capable than actual military vehicles".
For stuff like this, my main concern is that it creates an easy way for hostile agents (someone else's security agencies rather than our own) to break things that ought not to be breakable.
But, given that most people (including most criminals) are clueless about digital security, this kind of thing may genuinely be useful for breaking into otherwise-secret chat forums.
I can't balance these competing concerns. I really hope the people on our side ("security is good") are getting taken seriously by the agencies; but I don't have any reason to think that hope is anything more than wishful thinking.
The governments of the world are essentially our enemies. Encryption technology needs to start threat modeling with governments in mind. Cryptography must be so ubiquitous and undefeatable that it's impossible for any government to do anything about it short of nuking its own citizens.
Heck, I’d do away with governments existing and advocate anarchism, except for the messy reality of human nature.
Sure, but that doesn't imply that we should create new tyrannical powers out of whole cloth, just so the state can have them. The more that power remains distributed, allowing the population freedom and self-determination, the better.
The problem with governments is they dominate the entire earth. They force their social contract on us and we're forced to accept it just because we happened to be born somewhere. We can't just reject their power and rules: leaving is expensive, difficult or impossible and the only thing we can do is escape to another imperfect government.
Sure, in a sense the dual authoritarian powers of government/capital are always going to be looking for ways to push into our lives, turn voluntary two party relationships into chaperoned/extractive three party ones, etc. But as individuals that wish to remain individuals living in a distributed society, our job is to push back.
Don't forget that DANE requires DNSSEC, which your DNS service provider must support (and switching DNS provider is not 'relatively easy').
Another problem with DNSSEC is that there are some people (and with 'some people' I mean tptacek) who are ferociously against it.
Also, TLSA records require maintenance. If you forget to update them you will break things. Had to rotate your keys unexpectedly? Well now you have to wait for DNS propagation and explain your boss that some of your customers may get scary warning messages for a few hours when they try to reach you, and there will be nothing you can do about it.
eIDAS 2.0 should have forbidden that to start with.
Some authorities are granted an issuer-of-qualified-issuers status which allows them to issue both qualified and non-qualified sub-authorities. The data about all these issuing authorities is published in national lists which are signed by a national body, and these lists are then referenced in a Europe-wide list signed by a central authority, IIRC…
So validation becomes a bit of an issue - to tell if a certificate is qualified you need not only to perform normal x509 path validation but also validation against a parallel trust chain which branches off from the x509 chain at some point and resolves via a national list and then a master list to the eidas root.
Nevertheless this CA store distribution put us in this censorship situation. I think it should be moved further towards the service provider in a similar way webauthn works. The 3rd party CA makes the whole process vulnerable to rough CA providers or mandatory CA stores. Let's stop trusting 3rd parties with our security.
Probably at some point they will start mandating those CAs for broader categories of sites until they make the (EU) internet unusable for anyone that does not have the govt certificates.
That gives control over the root stores for Chrome, Firefox, Safari, and Edge. (And the approximation of the Mozilla store used by most Linux distros, the root stores on macOS/iOS/etc, and the root store on Windows.)
I'm not aware of any other browsers worth considering.
EV was never the wrong path, it just needs stricter checking mechanisms. Google wants people to dislike them because those checking mechanisms require humans and intentionally doesn't scale. (Good security does not scale, people who tell you it does are wrong.)
On the other hand, Let's Encrypt has _securely_ issued billions of DV certs, automatically and for free, meaning millions of websites have gone from plaintext to TLS-secured. That has given the world a tangible increase in privacy and security, which is not "mostly pointless". An ideal future is that _every website in the world_ is TLS-secured, and the US Government loses its panopticon
However, most users do not care if the US government can see their traffic. (Whether or not they should... not the point.) And MITM attacks aren't a practical concern for the vast majority of society in a real world sense.
EV certs do something largely useful. DV certs are mostly useless in practice but make tech nerds happy.
EV certs are an expensive boondoggle that add little-to-no value over DV certs. It's why all browser makers (not just Google) dropped any special rendering for them. The real value is pervasive TLS.
Phishing and website impersonation should be tackled with a variety of practises, and EV certs don't really come into it. Your preferred search engine should give you the "real" Wells Fargo site if you search for that. Your browser history should have it. You can bookmark it. If you've clicked a phishing link and you're on wellsfargo.com.badguy.com instead of wellsfargo.com, don't you find it odd you can't auto-fill your user/password any more? Maybe you're on the wrong site? Oh yes, there on the URL bar is "wellsfargo.com.badguy.com", I see it now.
Can you imagine if we still had that awful special rendering for EV certs, and the wellsfargo.com.badguy.com owners incorporated "Wells Fargo" in Timbuktu and bought an EV cert for their legitimate business, and the entire URL bar was covered up with " Wells Fargo"... lol
This is merely an example of what I already stated: Validation practices and participation requirements need to be improved. I am well aware of this popular example.
> Do you even read links?
Please check the HN guidelines for conduct. I've actually already read all of the popular media on the topic.
> Your preferred search engine should give you the "real" Wells Fargo site if you search for that.
Google regularly serves malware as the "top search result", because Google Ads appear to be search results to average users, and advertisers can lie about the destination URLs in text ads. Bing is not better in this respect either. If you trust your search engine, you might as well just plaintext all your traffic anyways.
Everybody is doing that, so we don't care doesn't work for security.
They should really start with participating in the CA/B forum workgroups, instead of trying to reinvent (and mangle) the wheel.
They are merely adding themselves to the defaults set by current manufacturers. End users are free to remove them.
Microsoft, Mozilla and others already provide you with a list of who you’re going to trust by default.
It would be more outrageous if the current CAs were some sort of gold standard, but the whole system is flawed.
And browsers could create a "more secure" list of CAs, with governments CAs outside the list and a scary Accept the Risk page for everything outside the more secure list. Anyway, what happens when every government website use the new CAs and people will have to accept that because it's the only way to deal with government services? Every other site using those CAs will soon enjoy a free pass because of the Accept/Next/Next fatigue demonstrated by the last 30+ years of human computer interaction.
Let's not pretend we don't know the power of defaults, or that we expect users to learn about and modify the obscure and technical innards of their browsers. Even expert users can be fooled, such as when the NSA bribed a company to default to a weak cipher [1].
> Microsoft, Mozilla and others already provide you with a list of who you’re going to trust by default.
If I use Firefox, I choose to trust Mozilla. But now, whichever browser I choose, I am forced to trust its maker and the government and intelligence agencies of every EU member state.
I can spend my limited time learning how to fix this, but is it legal to share my solution in a convenient form (such as a browser that by-default trusts CAs based on merit, not government order), or would that make me a browser vendor, and compel me to backdoor my software?
This is, in effect, prohibiting cooperation to fight surveillance.
> It would be more outrageous if the current CAs were some sort of gold standard, but the whole system is flawed.
I don't see how the current system being flawed makes a government mandate to default-trust hypothetical known-untrustworthy CAs less bad. It is a red herring - is a system being "flawed" justification for government intrusion? And does this intrusion even attempt to fix those flaws??
[1] https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...
The point is that the only way browsers have to influence a CA or the industry is the threat to eventually distrust. If they can't threaten that to government-stamped CAs, then those CAs no longer even have an incentive to operate responsibly, and, as we know from the many, many incidents, they almost certainly won't.
If I had to guess, half of the least trustworthy CAs in the one-store-fits-all keystore are also government affiliated ones and we don't even get anything to differentiate them from any regular commercial cert.