Some observations on the final text of the European Digital Identity framework
A new EU Digital Identity framework (eIDAS 2.0) that would require browsers to trust government-approved certificate authorities is raising concerns about weakened web security and state-enabled HTTPS interception. Critics argue it shifts control from browser vendors and the CA/Browser Forum to EU technocrats, potentially blocking mechanisms like Certificate Transparency and slow-walking revocation of compromised government CAs. Supporters counter that it strengthens European “digital sovereignty” against US-based tech giants, likening it to treating government-issued digital certificates like passports, while others point to mixed real-world experience with national eID systems across Europe.
Government CAs & eIDAS Changes
- Current model: browser vendors (via CA/Browser Forum) decide which certificate authorities (CAs) to trust and can fully distrust misbehaving CAs.
- Under eIDAS, EU‑designated “qualified” CAs must be trusted by browsers in the EU; vendors would need regulatory permission to remove them, even if compromised or abusive.
- Critics see this as enabling governments to issue “dodgy” certificates and perform MITM interception, with browsers constrained in response.
- Supporters frame it as shifting power from US‑centric browser makers to EU public institutions and “sovereign” authorities.
Security Mechanisms & Certificate Transparency
- Several comments stress that trust in PKI relies on being able to revoke bad CAs quickly.
- Concern: regulation may forbid browsers from requiring stronger mechanisms (e.g., Certificate Transparency, DANE, pinning) if these could block government‑issued certs.
- Some note that CT currently makes silent MITM issuance costly because it exposes misissued certs; fear is eIDAS weakens this dynamic.
Digital Sovereignty vs Corporate Control
- Pro‑eIDAS voices emphasize that browsers are owned/controlled by ad‑funded US companies subject to national security letters and opaque pressure.
- They argue EU institutions are at least indirectly accountable to voters and better for “digital sovereignty” than unaccountable private consortia.
- Opponents respond that governments wield coercive power and are harder for individuals to avoid than software vendors; voluntary, open CA/B processes are seen as more accountable in practice.
Cookie Banners as Cautionary Tale
- Cookie consent pop‑ups are cited as an example of poorly designed or poorly enforced EU regulation.
- Some argue devs intentionally implemented them in the most user‑hostile way; others say if everyone misinterprets a law, that’s a design/enforcement failure of the law itself.
National eID Systems: Pros, Cons, Exclusion
- Users report mixed experiences with national eIDs (Sweden’s BankID, Spain’s DNIe, Dutch DigiD, SwissID, Singapore’s SingPass, Danish and French systems).
- Positives: convenience, long stable operation, use for banking, taxes, and cross‑border EU services (under existing eIDAS).
- Negatives: fraud incidents (e.g., BankID social engineering), dependence on banks; technical lock‑ins (rooted phones blocked, SMS‑only 2FA); difficulty for foreigners, temporary residents, and people abroad to obtain or recover access.
- Some see this fragmentation as an argument for an EU‑wide standard; others warn about centralization, ossification, and bureaucratic failure.
Bureaucracy, Incident Response, and Risk
- A recurring worry: in a large EU regulatory structure, revoking a compromised state CA could be slow and politicized, unlike today’s relatively nimble browser‑driven response.
- Supporters counter that states already manage critical identity infrastructure (passports, IDs) and are experienced in dealing with fraud and forgery.