Article 45 of eIDAS 2.0 will roll back web security by 12 years

A contentious provision in the EU’s proposed eIDAS 2.0 regulation (Article 45) would require browsers to trust government-designated certificate authorities, potentially limiting their ability to enforce modern security checks like Certificate Transparency. Commenters warn this could enable undetectable man-in-the-middle attacks by states, weaken web security globally, and repeat past attempts to erode end-to-end encryption and online privacy. Others argue that governments already control some CAs and see the current text as imprecise or unfinished rather than an explicit backdoor, but acknowledge the secrecy of the drafting process and the risk of long-lasting damage if it passes.

Scope and Intent of Article 45 / eIDAS 2.0

  • Many see Article 45 as forcing browsers to trust government-appointed CAs while forbidding them from applying their own stricter security policies (e.g., CT, extra audit rules).
  • Concern that this creates an “upper bound” on security: browsers could not reject state-picked CAs for failing non‑ETSI criteria.
  • Leaked draft text is referenced; some argue public criticism is warranted because the trilogue phase implies near-final wording, not an early draft.

Security Risks and MITM Concerns

  • Core worry: governments (or compromised CAs) could issue certificates for arbitrary domains and perform undetectable TLS man-in-the-middle, especially if CT enforcement is disallowed.
  • Commenters note this effectively recreates or legitimizes attacks similar to prior state-level CA abuses (e.g., Kazakhstan, Turkey).
  • Some argue browsers’ current root programs and CAB Forum rules significantly reduce such risks, and shifting power to an EU bureaucracy weakens that.

Disagreement and Claims of FUD

  • A minority argues the EFF and others are overstating the threat:
    • Governments already operate or control CAs; adding another CA type (QWACs) doesn’t create fundamentally new interception capability.
    • eIDAS is framed by some as mainly a digital identity framework, not an anti-encryption measure.
  • Others respond that the combination of mandatory trust and limits on browser enforcement does materially change the risk.

Enforcement, Compliance, and Workarounds

  • Debate over how far the EU can practically go:
    • Some think the EU could compel big vendors via fines, asset seizures, or targeting EU-based staff.
    • Others argue open source forks, extra-EU distribution, VPNs, and non‑compliant browsers will remain available and hard to fully control.
  • Suggestions include delisting EU CAs, moving browser projects outside EU reach, or visually marking “government-mode” certs.

User Controls and TLS/PKI Discussion

  • Several comments explain how TLS and CAs enable MITM when a trusted CA issues fraudulent certs or when a corporate/government root is installed.
  • Proposed mitigations:
    • Let users manage their own trust stores and clearly label powerful “blanket” CAs.
    • Strong UI warnings when corporate/government interception is detected.
    • SSH-like “trust on first use” or decentralized alternatives.
  • Others counter that pushing PKI decisions onto ordinary users is unrealistic and leads to warning fatigue.

Legal and Political Context

  • Some expect potential challenges at EU courts (e.g., privacy rights, Schrems-like outcomes) but worry this could take years.
  • Several see eIDAS 2.0 as one more step in a broader “crypto wars” pattern of incremental encroachment on encryption and privacy.