Some observations on the final text of the European Digital Identity framework
blog.xot.nl
blog.xot.nl
So same as today but with less steps?
Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is game over.
e.g. https://pki.treas.gov/crl_certs.htm https://www.bit.admin.ch/bit/en/home/themes/swiss-government... plus all the gov CAs already in your browser (looking at firefox source they include, guangdong, taiwan, honkkong, netherlands and Greece. IOS 16 contains spain, belgium, something called "Government Root Certification Authority 00 B6 4B 88 07 E2 23 EE C8 5C 12 AD A6 0E 06 A1 F2" :shrug, greece, hk, Netherlands, Switzerland.
Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.
In your scenario, if the domains CA is the government CA anyway, then it's fair game. Most domains' CA will be cloudflare or whatever not the government CA.
good lucky finding the cert if you didn't download your firefox in brazilian portuguese or didn't register you apple device in brazil. I mean, it is not difficult to find the cert, but it is a pain for travelers.
eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats.
All those existing government CAs are currently audited by CA/B. If Greece gets caught misissuing certificates they can have their CA roots revoked by the browser vendors. The concern is that under eIDAS, the EU could just not revoke the certificate, and the browser vendors' hands would be tied. They'd be forced to accept known bad CAs and every cert they sign, including the spyware ones.
Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.
They still have to receive that permission before they can do it.
Why are your characterizing the CA/Browser forum as US centric companies? Its a collection of certificate issuers from all over and notably includes European Accredited Conformity Assessment Bodies’ Council and the European Telecommunications Standards Institute.
You could if it got to that point, but the CA would almost certainly "voluntarily" stop issuing certificates to news.ycombinator.com rather than face the risk of being blocklisted, and there's no way for you to opt out of that.
The exception is if the consensus is only among a small handful of large corporations that lack competition and then become the unaccountable technocrats. But in that case what you want from governments is not to take over as the malevolent bureaucracy, it's antitrust enforcement.
The current voluntary system is also very open, and anyone can get involved and participate to a much larger extent than people realistically can in an electoral democracy. To me, the voluntary system seems to be better and safer for everyone who doesn't have a very large amount of money to throw at elections.
This is about identity regulation, not random rockets.
> The US constellation isn’t as accurate as the newer networks, said Roberts, the Sydney-based professor. “It used to be GPS was out in front,” he said. Now, though, the EU’s Galileo is in the lead, with China’s BeiDou close behind, he said.
[1] https://www.bloomberg.com/news/articles/2023-09-20/russia-s-...
The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to National Security Letters etc. (and, more insidiously, US social pressure). When the next Snowden-style revelation comes out, what's to stop the US security apparatus from blocking sites associated with it? So yeah, I see more upside than downside in my browser having at least some accountability to the EU.
> All those existing government CAs are currently audited by CA/B. If Greece gets caught misissuing certificates they can have their CA roots revoked by the browser vendors. The concern is that under eIDAS, the EU could just not revoke the certificate, and the browser vendors' hands would be tied. They'd be forced to accept known bad CAs and every cert they sign, including the spyware ones.
I mean sure, you have to accept the government of Greece's certificate because they're the legitimate authority, just like you can't refuse to accept a Greek passport because you think it looks dodgy or you've never heard of Greece. If their government is issuing bad certificates, normal government accountability mechanisms apply, just like with countries that are known to sell citizenships to the wealthy. Again that seems right and proper.
Those browsers are Open Source. (Well, Firefox is, and Chrome's core is even though Chrome isn't). If they tried to ship a MITM-enabling mechanism it'd be obvious.
> I mean sure, you have to accept the government of Greece's certificate because they're the legitimate authority
They're not the authority for arbitrary domains on the Internet, no. Only domains that have requested a certificate through that CA. This is what Certificate Transparency is for. If a Certificate Transparency log shows a CA (governmental or otherwise) issuing a certificate for somecompany.example, and the entity controlling somecompany.example didn't request that certificate, that CA has some explaining to do, and if the answer isn't "here's exactly what happened and how we'll make sure it can never happen again", the likely outcome is that browsers will stop trusting that CA.
The point of CT is that you can't silently issue MITM certificates without permanently burning an entire CA to do it.
A straight up blocklist wouldn't be though. Just treat it like a CRL entry or something.
> They're not the authority for arbitrary domains on the Internet, no.
Agreed. But they're the authority for Greek domains. If anything, it's letting some other entity issue certificates for those that's strange.
The difference is that the current decision makers only have power because other people trust them voluntarily. That makes them accountable, and it means a whistleblower can do much more to limit the damage by leaking the fact they are giving after to US pressure.
A government can impose its will by force, so it is much less accountable and doesn't have to worry about the consequences of its decisions nearly as much. There is nothing I can realistically do if I object to a decision by a government unless I'm a large political donor because governments don't need my consent to operate.
Not really. Plenty of EU citizens don't trust Microsoft, Google or Apple. But there's no practical alternative. The government of an individual EU country has a lot more accountability than that.
Governments ultimately derive their power from their ability to impose their will by violence. That makes them inherently less accountable than organizations that you are free to ignore.
Installing an open-source OS and browser is free and the options are practically unlimited as anyone is free to create a new alternative.
There's what, two and a half real options? Even open-source applications wilfully cut off any non-mainstream OS (see the whole systemd saga). "Anyone is free to create a new browser", sure, but in practice it's now so expensive that even Microsoft had to give up. I've absolutely got more practical choices of country.
No one is going to kick down your door and shoot you if you try to make a new browser or OS from scratch, like they would if you tried to make a new government, but there is really no reason to make a browser from scratch.
Microsoft didn't need to trust Google to fork Chromium, they didn't give up any power to Google and have exactly the same ability to influence web standards as if they had reinvented the browser. If they disagree with a choice the Chromium developers made, they can change it and keep the rest. The same applies to anyone who wants to do the same.
When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to. If you tried to start a new one, the natural thing to ask would be why I should trust you over the established certificate authorities. If your answer is that I don't have a choice because you have the backing of an army and police force that you will use against me if I don't, it doesn't exactly fill me with confidence.
The current certificate authorities don't need to threaten anyone with violence to secure their position, and they operate with significantly more transparency than any government I know of. Compared to governments, they are also much safer to trust because they rely on consent rather than force. A compromised or malicious certificate authority won't shoot you for trying to replace it, it has no enforcement mechanism beyond inertia.
They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFlare (who are pretty low on my list of entities I want to trust) instead. Now that browsers have mostly succeeded in forcing HTTPS everywhere, expect them to start turning the screws.
> The current certificate authorities don't need to threaten anyone with violence to secure their position, and they operate with significantly more transparency than any government I know of.
Really? Can I make a FoI request to find out why a CA refused to issue a certificate to a particular entity? Is there a right of appeal if they refuse to issue a certificate on discriminatory grounds?
DoH doesn't interfere with your ability to choose your own DNS provider. It only means that your DNS queries are between you and your DNS provider, free from the interference of your ISP and other third parties. It provides greater user freedom because your ISP cannot as easily force you to use their DNS provider. Nothing stops ISPs from offering DoH and some (e.g. Comcast) do offer it. Users may however benefit from using a DNS that's not affiliated with their ISP because ISPs are more vulnerable to censorship demands from governments. Usually, when a government demands that an ISP censor a website, the ISP will simply block DNS queries regarding that domain, allowing users of other DNS providers to escape the censorship. This may of course not be a long-term solution, as governments may be more likely to demand different censorship methods if fewer use the IPS DNS.
As far as I'm aware, no one has suggested that DoH should be mandatory. It is a sensible default that improves the privacy and security of most users, but a user who decides that they do not want to use DoH can simply opt out in the settings. Likewise, HTTPS is not mandatory either, and browsers will not prevent users from accessing unsecure sites. They will however warn users to make sure they are aware of the risks. As far as I'm aware, browser vendors do not benefit from users using HTTPS everywhere. They encourage its use because it is generally beneficial to users.
> Really? Can I make a FoI request to find out why a CA refused to issue a certificate to a particular entity? Is there a right of appeal if they refuse to issue a certificate on discriminatory grounds?
A FoI request is just asking the government to give you information. They will never intentionally give you anything they do not want you to have. FoI laws tend to contain enough exceptions to cover any situation, but even if you should legally receive the information, there is nothing you can realistically do to make them provide it to you. Similarly, you can ask any organization for any information, and they can refuse. The same is true with appeals. You can ask an organization to reconsider its decision and for someone else in the organization to look at it, but the decision remains within the organization. The difference is what you can do once the decision has been finally made. Will the decision maker try to force me to adhere to their decision through violent means, or am I free to ignore them and try to convince others to do the same?
The main difference regarding transparency is that more information is made public by default in the current system (what good is the ability to request information if you don't even know that the thing you wanted to request information about happened?) and that decisions are made by several separate entities that need to justify their decisions to each other in order to maintain consensus.
It may not make it impossible but it makes it harder. You need a provider that supports DoH, and your browser will ignore your OS-wide DNS setting. Previously your default DNS provider would be an ISP that you'd picked; now the default is whoever's most profitable for your browser maker (you might say you pick your browser, but there's less real choice there than there is for ISPs, at least where I live).
> As far as I'm aware, no one has suggested that DoH should be mandatory. It is a sensible default that improves the privacy and security of most users, but a user who decides that they do not want to use DoH can simply opt out in the settings. Likewise, HTTPS is not mandatory either, and browsers will not prevent users from accessing unsecure sites. They will however warn users to make sure they are aware of the risks.
They won't do it all at once, but they're making it harder and harder to access non-HTTPS sites. It's gone from a clear warning to a block page where accessing the HTTP version requires multiple clicks on tiny text; the next step will be to make it require a config tweak to even get that tiny text at all, and then they'll say that their telemetry conveniently shows few people are using that config tweak (because who could imagine that the kind of people who would don't trust their browser maker would disable telemetry) so they're removing it. We've seen this whole playbook before. It'll be the same for DoH.
> A FoI request is just asking the government to give you information. They will never intentionally give you anything they do not want you to have. FoI laws tend to contain enough exceptions to cover any situation, but even if you should legally receive the information, there is nothing you can realistically do to make them provide it to you.
Governments are accountable to their citizens, not just in theory but in cultural practice, which is what really matters. If you get a bogus response to an FoI request then you can complain to your representatives, and if your representatives don't respond then you can vote them out. But more importantly, the clerk handling your request knows that their duty is to you, not their shareholders, and will generally act accordingly. And if they don't, there's a whole culture of whistleblowers, investigative journalists, activist judges and so on.
None of that exists for a private company CA where they're working for their shareholders and no-one expects them to do otherwise. Frankly even if it did leak out that a CA had refused to issue a certificate to someone who they just didn't like, it wouldn't even be a scandal unless you were lucky enough to catch the right moment where there was a social movement supporting that particular kind of person.
> As far as I'm aware, browser vendors do not benefit from users using HTTPS everywhere. They encourage its use because it is generally beneficial to users.
Google (which is to say DoubleClick), which funds the majority of browsers, has a huge financial interest in HTTPS. They make their money on ad tracking, and it suits them to put a moat around that; privacy initiatives help them by making it harder for any new competitors to get hold of the same information they built their business on.
I’m surprised any business filing is using a desktop app rather than on the web these days.
It's a complete nightmare. If you want to use some other digital services you are restricted to specific browser versions, some only allow you to use Windows, and in some cases the unsigned installer is only available via HTTP.
Even if they did, it doesn't really address the problem. In order to mount an effective impersonation attack, the attacker needs to either control the network or the DNS. In either case, they will generally be able to remove or change the CAA record; remember that DNSSEC deployment is comparatively rare and browsers do not verify DNSSEC in any case.
"Relying Applications MUST NOT use CAA records as part of certificate validation."
For what you're looking for, DANE (RFC 6698) would be more useful and enable the browser to check the presented certificate against DNS (so effectively CAA on the client).
People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it.
All I see are advantages.
And Sweden isn't alone in using some sort of eID.
So how come the EU can't just build on existing experience? Why are they making it more difficult?
Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services despite warning my bank about the potential problems months ahead of the forced transition. The only way to regain access is to travel back to Denmark and visit my bank or my local council.
However, it is also necessary to make sure data privacy is factored in.
On the other hand I also have the Japanese digital ID card (マイナンバーカード), and what a piece of crap. If you ever hear that Japan is the most technologically advanced country in the world: no, it is not.
The more centralized a system is, the more it ossifies. The more people there are to get used to the status quo and incur large costs if anything changes, the more change gets fought. Third parties get their hooks into it, benefit from the status quo and put substantial resources behind preventing changes that are unambiguously improvements -- "institutions will try to preserve the problem to which they are the solution."
The only way to avoid it is to never build it to begin with. Or tear it down as soon as possible if you're too late to stop it from existing but not too late to have everyone fighting to preserve their rents if you try to get rid of it.
And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it.
South Americans can change it over after only 5 years. But not EU citizens strangely.
Maybe EU citizens don’t get an NIE, though? I’m from further away.
However us EU citizens get the scrap of paper thingy. There's no photo on it either, we're supposed to use it alongside our EU photo ID.
The green paper slip is a certificate of registration of EU citizen in Spain, upon which is also marked with their NIE.
Can anyone here provide an example document / thing with a valid Spanish ID signature?
These kind of services simply don’t care about the small percentage of tourists and expats that they exclude.
But I think the social externalities in terms of freedom of movement are significant and not priced in.
I’m not a fan of adding regulation but I think this is one of the places where it’s necessary.
One of the occiasions where a bit of EU regulation wouldn’t hurt.
Walking through a park in Shanghai, I discovered that the many vending machines throughout the park will let you specify that you want to pay cash.
You can't actually pay cash, though; the slots that would accept it have been physically removed from the machines. The only way to get something out of one of the vending machines is to send the machine an online payment.
In other digital-payments-in-China news, I just ordered some milk today from the store that is across the street from me. It's no great hardship for me to cross the street and buy the milk myself. However, the price of a third of a gallon of milk is 32 rmb. (USD $4.50). If I order it delivered, a courier will show up, buy the milk, and walk it up four flights of stairs to hand it over to me, and besides paying no delivery fee, my price per carton of milk falls to 22 rmb.
What really bothers me about this is that the bag came with a big receipt stapled to it showing that the delivery service paid the store 26 rmb per carton of milk. So the service was nice enough to cover the courier's fee for me at the same time that they paid me for everything I ordered through them.
Something somewhere is orchestrating a huge forced push for online payment. The economics clearly do not work on their own.
The providers holds all the keys, you cannot verify that a signature is legit yourself, you wont get access to the keys they use to sign things, and a cryptographic signature is not really the same as a normal signature on a document.
You might have wanted something else, but it's never been presented as a decentralised or open solution.
In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.
That said, people do not like the wait for the manual check, and the app itself seem to get a lot of hate.
Banks have enough data already, plus, why make a group of business arbiters of ones online identity?
100% agreed :)
> Who even fame up with that?
Guess who.. The banks did.
> Why bring banks into the mix? We've had DigiD for what, also almost 20 years now? Why replace something that works well? iDIN doesn't even fix the main problem, which is being usable in other EU countries.
It fixes the main problem for the banks which is that they were not involved. With iDIN they add another "selling point" for themselves, can sit at the table with government services as a provider and can monitor our behaviour more deeply.
It makes no sense as DigiD has worked OK (as a Dutch person living abroad it's certainly not perfect, especially the SMS 2FA option requirement for a Dutch number is super annoying, and the process of requesting access is a real PITA). At least there's an app now.
> Banks have enough data already, plus, why make a group of business arbiters of ones online identity?
It's a bad idea all around but the VVD government embraced it because they love business participation in everything.
I don't know how the new text changes this.
It doesn't run on my phone because it's supposedly "rooted". I have a new Pixel phone with AOSP and the boot loader unlocked. The app behaves like malware or spyware because they make assumptions about end user devices.
Then they only support SMS based 2FA, none of the standards like TOTP or HOTP.
There is this weird sense of superiority or superior quality with the "Made in Switzerland" label. It may be true for a watch, but it's far from true when it comes to software and technology otherwise. Everything is mostly trash.
This is a great example of when privatization is a bad idea. Fraud is clearly a loss for the society, but the banks couldn't care less. A more secure solution would cost more for them, and it's someone else who has to carry the burden.
Fortunately, BankID doesn't fulfill the EU's security requirements, so Sweden finally has to make a proper eID, despite the bank-friendly politicians (Sweden is very "pro-business") not wanting to.[2]
[1] https://www.svt.se/nyheter/lokalt/uppsala/filippa-lurades-av...
[2] https://www.sweclockers.com/nyhet/37412-statlig-e-legitimati...
It's still much better than anything we had before, and it is after all 20 years old. So I can see that there is room for improvement.
So what is a better eID implementation? Freja?
Elbonian hackers manage to steal the singing key of kneebonia who is part of the EU (and also does IT as well as you would expect a European national government to do) They start publishing a ton of their own certs and start MITM everything out the wazoo.
In the current environment this is noted by the community quickly they respond and revoke the Kneebonian cert, they understand what is happening, they understand why it is happening, they understand why it is bad and they have a vested interest in stopping it.
Compare under the EU rules. The browser vendors cannot now revoke the cert of their own violation without risking significant penalties. They start the process of trying to get it revoked. The individuals involved are largely beauracrats and civil servants the likes of Sir Humphrey. They do not understand the technical jargon they just know the nerds are getting upset. They'll work on discussing the proposed change by evaluating a written request in the Orwellian named "Committee for Public Internet Safety and Electronic Information Security and Cyber protection" this committee meets 3 times a year on March 31st, October 16th and February 29th. In the meantime the entire underlying security model of the internet is broken.
Now some might say "well if it's an emergency they'll respond immediately there will be public outcry and people's lives being ruined." And if it becomes a big deal the EU will act promptly, they will create a taskforce immediately whose job will be to create a recommendation for individuals to serve in a committee to investigate the source of the problem and create a list of possible remediations that could resolve the problem, which it will then present to the parent committee who will draft a response..... Etc etc ad infenitum until everyone involved with the matter has died of old age, and if you think I'm exaggerating when has EU done anything quickly?
Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.
What would steelmaning EU regs have looked like? Not really sure what you mean by this.
A simple "decline [all]" / "accept" choice, not a huge list with dozens of sliders for dozens of options each labelled "legitimate interest" all of which are set to "Accept" by default?
I'm sorry now I'm confused. Is UI design this hard? Is this neurotypical?
EU sites have the same amount of cookie banners as US ones. (ie, all major sites have one)
Quite hilarious are the sites that outright block European IP addresses, as if that way they don't have to bother with the basic human right to privacy (article 8 ECHR). More sites should do this if they have no wish to play by these morals instead of having (legal or illegal) walls!
But I know I'm not a lawyer, and my lack of understanding of the technical jargon in law is likely to be similar to the lack of understanding of technical web jargon in the old screenshot of someone looking at the JS console by accident and thinking it was a secret police thingie: https://images.app.goo.gl/4SPUwbQ1uY2r5oHcA
It's not. You can report this to an appropriate civil authority and in theory it'll be resolved (possibly with a fine). In practice the authorities are still so overwhelmed by GDPR that they will only look at the most severe high profile cases. Fingers crossed one day it'll improve...
This is one of the dumbest narratives I see on HN all the time. A community of people who build things for a living should know better.
Think of regulation as software designed to create an outcome in the real world.
If everyone is wrongly using/interpreting your software…the problem is not “everyone.” The problem is the design of your software.
Browser vendors are not democratically ran institutions. One browser is owned by an ad broker and seller; the other browser is owned by an astroturfed* org that is 80% funded by the said ad broker and seller. Browsers not being allowed to stop their European users from accessing their European websites IS what I want. I do not want it to be possible for U.S. to coerce browsers to take out root stores to my bank, for instance.
And as for security requirements, that's just a load of BS. eIDAS is A+B, not A or B. The security requirements in the legal text are equivalent or higher that of cabforum's, minus the certificate transparency bit. And that's a fair critique. Such mechanism needs to be discussed and plausibly adopted. And we have the democratic institutions for that discourse. It's called ETSI. And browser vendors are welcome to participate in ETSI and give their suggestions of allowing certificate transparency. They aren't doing that; in good faith anyway! They're not participating in a democratic standards body, instead they're running propaganda campaigns trying to rile up their users.
To sum up, I want EU to gain digital sovereignty. Some of critiques are valid (I certainly don't like EV-style UI prescriptions), others are just bullshit. Bullshit we saw before GDPR. "The internet is going to be destroyed!". The internet wasn't destroyed. The internet is better after GDPR. Democratic institutions are good, ad funded browsers engaging in practices with zero accountability aren't.
*plausibly hyperbole; but I'm not sure seeing that Mozilla has shown itself to be useless, as it took pro-Google position in search engine anti-trust case
No, under no circumstances should browser vendors be forced to "discuss" the development and application of higher security standards with an adversary with a vested interest in holding those standards back. You cannot have a reasonable "discussion" with an entity that claims a regulatory veto.
Certificate Transparency is a great example: it's a reliable way to detect MITM certificates. "Here's an established industry standard for detecting improperly issued certificates and rejecting them to prevent interception of communication, allowing revocation of misused CAs." "So what happens when law enforcement uses a CA to issue a certificate for interception pertaining to a warrant?" "Like we said, it detects improperly issued certificates and rejects them to prevent interception of communications, so we'd detect that and revoke the CA." Further conversation after that point goes very differently depending on whether the governmental entity is empowered to veto or not.
> browser vendors are welcome to participate in ETSI and give their suggestions of allowing certificate transparency
"suggestions"? It's their software; any mechanism that attempts to prevent them from defining their own stronger security standards is broken and should be destroyed via every possible route.
If you want digital sovereignty, make a case for your requirements with the software people want to use. If that case is "we want to reduce security", you should lose; if you don't something is very wrong with the process.
Governments are being given authority to create dodgey certificates,
Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and
Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up).
Or am I missing something?
Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.
Depending on the wording of the law, it seems like it could require browsers to ignore this requirement for government issued certificates, hence bypassing the cert pinning and allowing them to intercept traffic to e.g., Facebook.
I'm not sure how many sites do this, I think Google's own do, and maybe some of the other big names use it as well, but I'm not certain.
it helps to recall that ETSI, despite being some opaque standards org is made of people[1] like you and me (many not in Europe) who helped draft this abomination of a standard. This is disguised as digital identity but the interest groups are mostly law-enforcement, and the same crowd that is pushing "chatcontrol", and "regulating cryptography".
This "secret list" of experts is here[1].
And here is Tanja Lange's (repeated[2]) warning on this proposal:
>> I'm contacting you @LalicVedran & @JerkovicRomana about eIDEAS - as a cryptographer & concerned citizen. As said in eidas-open-letter.org/ & I presented in detail at the ENISA Article 19 working group it doesn't suit an open society to mandate trust. https://hyperelliptic.org/tanja/vortraege/QWACs.pdf
When Kazachstan[3][4] made people install a certificate in their citizen's browsers we (rightly) called them "Banana Republic". Look who is the Banana Republic now.
[1] Patrick Breyer on Twitter Nov 6th (in German) https://nitter.cz/echo_pbreyer/status/1721558594129219912
[2] Tanja Lange on Twitter Nov 5th https://nitter.cz/hyperelliptic/status/1721215011799142791
[3] Kazakhstan to MitM all HTTPS traffic starting Jan 1 (2015) https://news.ycombinator.com/item?id=10663843
[4] MITM on HTTPS traffic in Kazakhstan (2019) https://news.ycombinator.com/item?id=20472179