- cross-posted to:
- privacy@lemmy.ml
- cross-posted to:
- privacy@lemmy.ml
It’s an opinion article, but I heavily agree with it. It’s really sad that technical decisions are made by chimps who can’t tell the difference between a computer and internet.
🤖 I’m a bot that provides automatic summaries for articles:
Click here to see the summary
The Electronic Frontier Foundation (EFF) and hundreds of experts don’t, pointing out that elements of proposed revisions to EU regulations called eIDAS would exempt state-approved certificates from security action by browsers.
This would give states, state-approved organisations, or anyone corruptly part of that particular chain of trust, the ability to make fake sites that monitor and decrypt Web traffic silently and at scale.
The EFF is a fully open group of people with a long record of identifying and warning about harmful attempts to damage user freedoms on the internet.
The eIDAS regulation makes an enormous change by mandating man-in-the-middle attack technology that it would be illegal for browser makers to defend against.
It weakens the security on which the web is built in a unique way for unsophisticated users, while giving a wide range of entities the tools to decrypt data of all kinds.
It is as likely to go wrong as any state-run secret security system, through incompetence, accident or malevolence, with consequences that could affect not just the half-billion EU citizens but all those who use EU-based services.
Saved 82% of original text.