Gandalf_The_Grey
Level 83
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
- Apr 24, 2016
- 7,256
The proposed EU Digital Identity framework (eIDAS) aims to meddle with the process around internet certificates and will undermine the independence and security assurances of the basis for website security:
In summary, eIDAS Article 45 and 45a represent a dangerous intervention in a system that is essential to securing the Internet.
- A certificate contains the website's identity (name, etc.) and its public key for encryption and signing. It is endorsed by trusted organizations that undergo regular audits. This process enables browsers to verify that the website we visit is authentic (thus avoiding "man-in-the-middle" attacks) and establishes an encrypted connection.
- Articles 45 and 45a stipulate that web browsers must recognise a new form of certificate issued by any EU state , potentially compromising the encryption and most of all trust and overall security of the web.
- This situation bears similarity to the controversy surrounding "chat control", as it implies that authorities could intermediate all traffic, decrypting communications sent over services using these certificates.
Mullvad is against these proposed articles.
Time perspective:
Industry letter
- 8th November – political (trilogue) agreement sign-off
- End of November to mid-December: Council & Parliament votes (both in Committee & Plenary)
https://blog.mozilla.org/netpolicy/files/2023/11/eIDAS-Industry-Letter.pdf
Read more
https://blog.mozilla.org/netpolicy/files/2021/11/eIDAS-Position-paper-Mozilla-.pdf
Can we agree on the facts about QWACs?
Mozilla | QWACs - #SecurityRiskAhead EU -
eIDAS
EU Digital Identity framework (eIDAS) another kind of chat control? - Blog | Mullvad VPN
The proposed EU Digital Identity framework (eIDAS) aims to meddle with the process around internet certificates and will undermine the independence and security assurances of the basis for website security:
mullvad.net