It's like they gave up on trying to actually innovate or grow a tech industry (composed of more than the odd successful euro tech corporation) after years of trying and now they are just banking on their market size to push more and more ridiculous legislation.
I can't wait for that to backfire, or for corporations to not bother anymore (imo the GPDR is the only good thing that came out of this non stop spree of legislation, and that's almost half a decade old now).
At least with China, whatever they do or restrict usually only affects their own home grown tech industry. The funny thing is that if the US gov seriously pushed for something similar to the recent laws (chatcontrol, client side scanning, the weird copyright laws, the "fake news" thing, etc), Europeans would call it fascism or typical American thirdworldism (which is extremely ironic regardless of context).
https://www.europarl.europa.eu/RegData/etudes/STUD/2020/6487...
Agree partly the GDPR though, since it requires disclosure about how collected data is gonna be used.
What do you think of the Digital Markets and Digital Services Acts?
A company based in Ireland for example, has a really hard time employing someone in Germany, without spinning up a “local branch” in Germany, and thus having to comply with German tax rules as well.
Rules around contractors vary wildly and don’t simplify matters much.
The “solution” is to accept the overheads of a company like Remote or similar who act as an employer of record, but that’s a bodge.
No member state has any real incentive to simplify cross border employment/business rules, so it drags everyone down.
It gets even worse for startups when rules around equity, etc, vary wildly country to country - some countries have extremely hostile tax rules around equity that may never be realized.
But you'll probably have to keep an EU version on hand in order to access EU gov sites, EU banks, and likely EU businesses if/when the EU government decides to force businesses to use eIDAS certs for their sites.
The most practical way to achieve that is to legislate for a new API in the browser and implement this in the application layer. That will take some time to implement, however eIDAS itself will also take some time to implement.
This would involve the browsers implementing a new eIDAS-only CA store within their browsers. Which is very easy to do as it's new and the API is regulated thus fixed.
The verification flow would work by exchanging attributes (i.e. browser sends crypto-random message to server, server signs it, browser verifies). It adds work to the audit of eIDAS solutions (implementers will f** it up en masse as most of the involved parties are hopelessly bad) but it's better than the alternatives.