[HN Gopher] EU legislation eIDAS article 45.2 may force inclusio...
       ___________________________________________________________________
        
       EU legislation eIDAS article 45.2 may force inclusion of insecure
       QWAC root CAs
        
       Author : mattashii
       Score  : 35 points
       Date   : 2022-07-14 09:41 UTC (13 hours ago)
        
 (HTM) web link (securityriskahead.eu)
 (TXT) w3m dump (securityriskahead.eu)
        
       | DocTomoe wrote:
       | I fail to see the problem here. Their QWAC are root certificates
       | that do not adhere to their idea of a "strict vetting approach".
       | That sounds scary, until you realise all major browsers have
       | happily accepted the LetsEncrypt-CA, when LetsEncrypt does no
       | vetting at all.
       | 
       | To me this sounds like "have a little duck next to the padlock,
       | make users understand that not all encryption is alike" could be
       | a solution.
       | 
       | What am I missing?
        
         | mattashii wrote:
         | The problem is that it becomes mandatory for browsers to
         | include a list of root certificates that may or may not conform
         | to standards, and are not allowed under any circumstance to
         | remove those root certificates. This means that in a case like
         | DigiNotar (root CA of the national QWAC issuer compromised) it
         | would be impossible for browsers to legally choose to secure
         | their users and remove the compromised root from the trust
         | list.
         | 
         | Additionally, eIDAS CA requirements and vetting have not been
         | as strict as those in the CA/B Forum Baseline Requirements and
         | the other documents related to DV/OV/EV certificate issuance.
         | 
         | Apart from that, there are known problems with QWAC (mostly
         | related to name collisions, and the mostly manual process of
         | vetting information being prone to errors), but that is
         | generally a lesser issue than the above two.
        
           | amluto wrote:
           | I hope the QWAC proposal at least has subdomain constraints.
        
         | amluto wrote:
         | I assume they're referring to the CA/B Baseline Requirements,
         | which the browser vendors take _extremely_ seriously.
         | 
         | https://cabforum.org/baseline-requirements-documents/
         | 
         | But the OP webpage is so terrible that I'm really not sure what
         | they're talking about.
        
       | [deleted]
        
       | Shadonototra wrote:
       | Mozilla, an american company spreading their propaganda in EU
       | with a .eu domain
       | 
       | This should be illegal
       | 
       | I trust EU more than i trust Mozilla root certificates
       | 
       | That's where your "Firefox" donations go, people!
        
         | randomhodler84 wrote:
         | Cool. I trust the engineers at Mozilla far more than the
         | politicians in EU.
         | 
         | You can't mandate or legislate security from the parliament. It
         | takes hard work, skill, education, experience, luck and
         | visibility.
         | 
         | In my world, the law is just someone's opinion. Security deals
         | with systems, math, information, physics. I want the EU far far
         | away from my root CA store pls.
        
           | Shadonototra wrote:
           | nobody prevents you to use mozilla certificates, you do what
           | you want with your love and dependency on mozilla
           | 
           | i want americans to mind their own business instead of trying
           | to lobby in both EU/Asia by impersonating identities like
           | with this .eu domain, what a trustworthy behavior btw ;)
           | 
           | > Cool. I trust the engineers at Mozilla far more than the
           | politicians in EU.
           | 
           | > You can't mandate or legislate security from the
           | parliament. It takes hard work, skill, education, experience,
           | luck and visibility.
           | 
           | nobody said nor want that, you should read the original
           | articles instead of this propagandized website
        
         | _ink_ wrote:
         | Oh, common? What interest could Mozilla have to break up the
         | encryption of the few users still using their browser (and ruin
         | everything they fought for?). Vs what could the government do
         | when breaking the encryption of 500M users?
        
           | Shadonototra wrote:
           | An american company can not be trusted, that's as simple as
           | that
           | 
           | I don't have the right to hold that statement?
           | 
           | Should i create a .us/.com website, spread my message and
           | target every american voters so you can understand me?
           | 
           | You didn't like when the Russian did something similar, why
           | should it be ok when it is the americans doing it?
        
       | mimsee wrote:
       | Article 45.2[0] states:
       | 
       |  _The Commission may, by means of implementing acts, establish
       | reference numbers of standards for qualified certificates for
       | website authentication. Compliance with the requirements laid
       | down in Annex IV shall be presumed where a qualified certificate
       | for website authentication meets those standards. Those
       | implementing acts shall be adopted in accordance with the
       | examination procedure referred to in Article 48(2)._
       | 
       | [0]: page 35 from https://eur-lex.europa.eu/legal-
       | content/EN/TXT/PDF/?uri=CELE...
       | 
       | Annex IV page 42
        
       | amluto wrote:
       | I read that and it feels like I'm reading a modern Internet
       | graphic novel. Except the novel never got to the point. What is a
       | QWAC?
        
         | soraminazuki wrote:
         | It's succinctly explained in the article:
         | 
         | > Supporting QWACs will mean that browsers will have to support
         | providers that issue them without independently vetting their
         | security practices.
        
       ___________________________________________________________________
       (page generated 2022-07-14 23:02 UTC)