[HN Gopher] EU legislation eIDAS article 45.2 may force inclusio...
___________________________________________________________________
EU legislation eIDAS article 45.2 may force inclusion of insecure
QWAC root CAs
Author : mattashii
Score : 35 points
Date : 2022-07-14 09:41 UTC (13 hours ago)
(HTM) web link (securityriskahead.eu)
(TXT) w3m dump (securityriskahead.eu)
| DocTomoe wrote:
| I fail to see the problem here. Their QWAC are root certificates
| that do not adhere to their idea of a "strict vetting approach".
| That sounds scary, until you realise all major browsers have
| happily accepted the LetsEncrypt-CA, when LetsEncrypt does no
| vetting at all.
|
| To me this sounds like "have a little duck next to the padlock,
| make users understand that not all encryption is alike" could be
| a solution.
|
| What am I missing?
| mattashii wrote:
| The problem is that it becomes mandatory for browsers to
| include a list of root certificates that may or may not conform
| to standards, and are not allowed under any circumstance to
| remove those root certificates. This means that in a case like
| DigiNotar (root CA of the national QWAC issuer compromised) it
| would be impossible for browsers to legally choose to secure
| their users and remove the compromised root from the trust
| list.
|
| Additionally, eIDAS CA requirements and vetting have not been
| as strict as those in the CA/B Forum Baseline Requirements and
| the other documents related to DV/OV/EV certificate issuance.
|
| Apart from that, there are known problems with QWAC (mostly
| related to name collisions, and the mostly manual process of
| vetting information being prone to errors), but that is
| generally a lesser issue than the above two.
| amluto wrote:
| I hope the QWAC proposal at least has subdomain constraints.
| amluto wrote:
| I assume they're referring to the CA/B Baseline Requirements,
| which the browser vendors take _extremely_ seriously.
|
| https://cabforum.org/baseline-requirements-documents/
|
| But the OP webpage is so terrible that I'm really not sure what
| they're talking about.
| [deleted]
| Shadonototra wrote:
| Mozilla, an american company spreading their propaganda in EU
| with a .eu domain
|
| This should be illegal
|
| I trust EU more than i trust Mozilla root certificates
|
| That's where your "Firefox" donations go, people!
| randomhodler84 wrote:
| Cool. I trust the engineers at Mozilla far more than the
| politicians in EU.
|
| You can't mandate or legislate security from the parliament. It
| takes hard work, skill, education, experience, luck and
| visibility.
|
| In my world, the law is just someone's opinion. Security deals
| with systems, math, information, physics. I want the EU far far
| away from my root CA store pls.
| Shadonototra wrote:
| nobody prevents you to use mozilla certificates, you do what
| you want with your love and dependency on mozilla
|
| i want americans to mind their own business instead of trying
| to lobby in both EU/Asia by impersonating identities like
| with this .eu domain, what a trustworthy behavior btw ;)
|
| > Cool. I trust the engineers at Mozilla far more than the
| politicians in EU.
|
| > You can't mandate or legislate security from the
| parliament. It takes hard work, skill, education, experience,
| luck and visibility.
|
| nobody said nor want that, you should read the original
| articles instead of this propagandized website
| _ink_ wrote:
| Oh, common? What interest could Mozilla have to break up the
| encryption of the few users still using their browser (and ruin
| everything they fought for?). Vs what could the government do
| when breaking the encryption of 500M users?
| Shadonototra wrote:
| An american company can not be trusted, that's as simple as
| that
|
| I don't have the right to hold that statement?
|
| Should i create a .us/.com website, spread my message and
| target every american voters so you can understand me?
|
| You didn't like when the Russian did something similar, why
| should it be ok when it is the americans doing it?
| mimsee wrote:
| Article 45.2[0] states:
|
| _The Commission may, by means of implementing acts, establish
| reference numbers of standards for qualified certificates for
| website authentication. Compliance with the requirements laid
| down in Annex IV shall be presumed where a qualified certificate
| for website authentication meets those standards. Those
| implementing acts shall be adopted in accordance with the
| examination procedure referred to in Article 48(2)._
|
| [0]: page 35 from https://eur-lex.europa.eu/legal-
| content/EN/TXT/PDF/?uri=CELE...
|
| Annex IV page 42
| amluto wrote:
| I read that and it feels like I'm reading a modern Internet
| graphic novel. Except the novel never got to the point. What is a
| QWAC?
| soraminazuki wrote:
| It's succinctly explained in the article:
|
| > Supporting QWACs will mean that browsers will have to support
| providers that issue them without independently vetting their
| security practices.
___________________________________________________________________
(page generated 2022-07-14 23:02 UTC)