Hacker News new | ask | show | jobs
by kmeisthax 963 days ago
So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right?

Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this is equivalent to letting the CIA read your text messages.

1 comments

From Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.
It's not a "security check" it's just informing the user about their certs...
the certs let the authorities issue new certs for anyone they want, e.g. your email provider, and your browser won't be allowed to verify whether those certifications are valid or not, to notify the user