Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

eIDAS is federated login between countries in EU. What is wrong with that?
 help



It's a mechanism to legally force web browser vendors to install government issues root certificates (which they already did btw). And EU pinky-promises that not a single independent EU member won't use them to do MITM attacks on their political opposition and journalists. Like Orban 2.0 or Fico won't use Hungarian or Slovak root cert for nefarious purposes, no-no-no. It's only to protect the children, see, and definitely not to help murder journalists investigating drug smuggling cover-up. :)

I think we have pretty decent examples where browsers remove malicious root certificates if they have been so proven. Do you think the matters will be different if those belong to a country level root?

And I think we have pretty decent examples of all kinds of initiatives where governments (or corporations) promise not abuse something which clearly can be abused, and then proceed to do just that. In the age of "cheques and bank balances" and continuous degradation of parliamentarism and judicial systems in multiple developed countries, I don't have much hope for "if the abuse will happen, we will fix it afterwards" promises. Rather, I expect it to be immediately normalized and then made worse. Yesterday we (IT) were talking how government can abuse information requests. Today we have government just sifting through almost everything unencrypted in real-time with zero shame. Tomorrow we will lose E2EE in most big countries and no one would "fix that" or roll back (it's already slowly happening in UK for example).

As usual, it's federated*1 login*2 between countries*4*5 in EU*6*7*8



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: