News: 1699432027

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

(2023/11/08)


Lawmakers in Europe are expected to adopt digital identity rules that civil society groups say will make the internet less secure and open up citizens to online surveillance.

The legislation, referred to as eIDAS (electronic IDentification, Authentication and trust Services) 2.0, has been described as an attempt to modernize an initial version of the digital identity and trust service rules. The rules cover things like electronic signatures, time stamps, registered delivery services, and certificates for website authentication.

But one of the requirements of [1]eIDAS 2.0 is that browser makers trust government-approved Certificate Authorities (CA) and do not implement security controls beyond those specified by the European Telecommunications Standards Institute (ETSI).

[2]

Under eIDAS 2.0, government-endorsed CAs – Qualified Trust Service Providers, or QTSPs – would issue TLS certificates – Qualified Website Authentication Certificates, or QWACs – to websites.

[3]

[4]

But browser makers, if they suspect or detect misuse – for example, traffic interception – would not be allowed to take countermeasures by distrusting those certificates/QWACs or removing the root certificate of the associated CA/QTSP from their [5]list of trusted root certificates.

Put simply: In order to communicate securely using TLS encryption – the technology that underpins your secure HTTPS connections – a website needs to obtain a digital certificate, issued and digitally signed by a CA, that shows the website address matches the certified address. When a browser visits that site, the website presents a public portion of its CA-issued certificate to the browser, and the browser checks the cert was indeed issued by one of the CAs it trusts, using the root certificate, and is correct for that site.

[6]

If the certificate was issued by a known good CA, and all the details are correct, then the site is trusted, and the browser will try to establish a secure, encrypted connection with the website so that your activity with the site isn't visible to an eavesdropper on the network. If the cert was issued by a non-trusted CA, or the certificate doesn't match the website's address, or some details are wrong, the browser will reject the website out of a concern that it's not connected to the actual website the user wants, and may be talking to an impersonator.

Here's one problem: if a website is issued a certificate from one of those aforementioned Euro-mandated government-backed CAs, that government can ask its friendly CA for a copy of that certificate so that the government can impersonate the website. Thus, using a proxy in a man-in-the-middle attack, that government can intercept and decrypt the encrypted HTTPS traffic between the website and its users, allowing the regime to monitor exactly what people are doing with that site at any time. The browser won't even be able to block the certificate.

As Firefox maker Mozilla put it:

This enables the government of any EU member state to issue website certificates for interception and surveillance which can be used against every EU citizen, even those not resident in or connected to the issuing member state. There is no independent check or balance on the decisions made by member states with respect to the keys they authorize and the use they put them to.

How that compares to today's surveillance laws and powers isn't clear right now, but that's the basically what browser makers and others are worried about: government-controlled CAs being abused to issue certificates to websites that allow for interception.

Certificates and the CAs that issue them are not always trustworthy and browser makers over the years have removed CA root certificates from CAs based in Turkey, France, China, Kazakhstan, and elsewhere when the issuing entity or an associated party was found to be intercepting web traffic. Many such problems have been [7]documented in the past.

[8]

An authority purge of this sort occurred last December when [9]Mozilla, Microsoft , [10]Apple , and later [11]Google removed Panama-based TrustCor from their respective lists of trusted certificate providers.

Yet eIDAS 2.0 would prevent browser makers from taking such action when the CA has a government seal of approval.

"Article 45 forbids browsers from enforcing modern security requirements on certain CAs without the approval of an EU member government," the Electronic Frontier Foundation (EFF) [12]warned on Tuesday.

"Which CAs? Specifically the CAs that were appointed by the government, which in some cases will be owned or operated by that selfsame government. That means cryptographic keys under one government's control could be used to intercept HTTPS communication throughout the EU and beyond."

The foundation added the rules "returns us to the dark ages of 2011, when certificate authorities could collaborate with governments to spy on encrypted traffic — and get away with it."

[13]Europe's digital identity system needs patching after can_we_trust_this function call ignored

[14]Mozilla tells extension developers to get ready to finally go mobile

[15]Microsoft seeks EU Digital Market Acts exemption for underdog apps like Edge

[16]In quest to defeat Euro red-tape, Apple said it had three Safari browsers – not one

Mozilla and a collection of some 400 cyber security experts and non-governmental organizations published [17]an open letter last week urging EU lawmakers to clarify that Article 45 cannot be used to disallow browser trust decisions.

"If this comes to pass it would enable any EU government or recognized third party country to begin intercepting web traffic and make it impossible to stop without their permission," the letter warns. "There is no independent check or balance on this process described in the proposed text."

In an email to The Register , a Mozilla representative added, "Mozilla is deeply concerned by the proposed legislation and is continuing to engage with key stakeholders in the final stages of the trilogue process. We are committed to security and privacy on the Internet and have been heartened by the outpouring of support from civil society groups, cyber security experts, academics, and the public at large on this issue. We are hopeful that this heightened scrutiny will motivate EU negotiators to change course and deliver regulation with suitable safeguards."

Google has also raised concerns about how Article 45 might be interpreted. "We and many past and present leaders in the international web community have significant concerns about Article 45's impact on security," the Chrome security team [18]argued , and urged EU lawmakers to revise the legal language.

According security researcher Scott Helme, the latest regulatory language – which has not been made public – [19]is still problematic .

The EFF says the legislative text "is subject to approval behind closed doors in Brussels on November 8." ®

Get our [20]Tech Resources



[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2014.257.01.0073.01.ENG

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUtqUb29HKryY7sPQnMb-gAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUtqUb29HKryY7sPQnMb-gAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUtqUb29HKryY7sPQnMb-gAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://wiki.mozilla.org/CA/Included_Certificates

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUtqUb29HKryY7sPQnMb-gAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://sslmate.com/resources/certificate_authority_failures

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUtqUb29HKryY7sPQnMb-gAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/12/02/mozilla_microsoft_trustcor/

[10] https://support.apple.com/en-us/102798

[11] https://security.googleblog.com/2023/01/sustaining-digital-certificate-security_13.html

[12] https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-years

[13] https://www.theregister.com/2019/10/30/eidas_security_flaw/

[14] https://www.theregister.com/2023/11/03/mozilla_android_extensions/

[15] https://www.theregister.com/2023/10/26/microsoft_dma_exemption/

[16] https://www.theregister.com/2023/11/02/apple_safari_browser/

[17] https://last-chance-for-eidas.org/

[18] https://security.googleblog.com/2023/11/qualified-certificates-with-qualified.html

[19] https://scotthelme.co.uk/what-the-qwac/

[20] https://whitepapers.theregister.com/



b0llchit

Article 45 forbids browsers from enforcing modern security requirements on certain CAs without the approval of an EU member government...

That amounts to telling EU citizens that surveillance cameras must be installed in their house, are mandatory, may not be disabled and you may not get any information on their use. Such rule is a clear violation of the human rights declaration of the European Union. The courts will be having a say here.

And then, I'll compile my own FF without their crap if I damn well please. Let them prosecute me for enabling my own privacy.

Not just limited to the EU

The Mole

Government agencies have a history of skirting round the rules of not spying on their own population by asking a friendly foreign agency to do it for them. I'm certain that if this came to pass the NSA/CIA would have a fast track route to getting these certificates, whilst China would quickly compromise all these government run CAs.

The browsers on the other hand I'm sure will strictly follow the rules and not ban the CAs, they will just provide straight forward integrations to third party open source databases which may cause the CA to be banned completely independently of the browser manufacturer.

AMBxx

I'm pretty sure the German privacy laws will prevent this ever being approved. Given their history, the germans are very touchy about government spying.

Anonymous Coward

Given that the German govt is busy trying to ban political parties I would not put it past them to sneakily allow this.

At last! A Brexit bonus!

alain williams

The UK having left the EU will not be subject to these rules.

However: I am confident that Suella Braverman will decide that this is a great idea and ask GCHQ to come up with something that is better (or worse depending on your point of view).

"GCHQ to come up with something that is better"

Mike 137

Not necessarily better, just 'harmonised'.

"The dark ages of 2011"

Aleph0

From the users' point of view maybe, but I'd wager that government snoops consider 2011 "the good old days"...

Re: "The dark ages of 2011"

Anonymous Coward

Anyone remember the clipper chip? All your encryption backdoors are belong to us!

Tubz

Upvote if you don't trust the faceless EU muppets to lick a window, never mind Article 45 and downvote if you do.

Zippy´s Sausage Factory

Have they considered that anything the "good guys" get on Monday, the "bad guys" get hold of by Friday?

Surely this is opening the doors to hackers - not just for citizens' information, social media and bank accounts, but also for secure government information.

hoodedgeometry

“if a website is issued a certificate from one of those aforementioned Euro-mandated government-backed CAs, that government can ask its friendly CA for a copy of that certificate so that the government can impersonate the website.”

Not quite - the government can ask its friendly CA to issue a new certificate, but a copy of the old certificate will be of little use without the private key stored on the requesting organisation’s web server etc.

It can do this even if the original certificate wasn’t issued by one of the Euro-mandated government-backed CAs, as presumably organisations wanting to reduce the risk of government tampering would use a CA outside this government programme.

Existing countermeasures like Certification Authority Authorization (CAA) would presumably remain effective against this EU-mandated vulnerability, or at least require DNS to also be compromised to perform the MITM attack.

Enterprising browser extension developers can hopefully code for removing these CAs from the trust chain to restore security on the endpoint - perhaps rolled up into existing popular extensions like ad blockers.

Never understood certs

Zack Mollusc

I am connecting to an HTTP web site run by some unknown jerk. OMG, my privacy and security are at risk!

Solution: connect to an HTTPS web site run by some unknown jerk and trust that the cert issued by a different unknown jerk is kosher.

"If Jesus came back today, and saw what was going on in his name, he'd never
stop throwing up."
-- Max Von Sydow's character in "Hannah and Her Sisters"