Some observations on the final text of the European Digital Identity framework

A new EU Digital Identity framework (eIDAS 2.0) that would require browsers to trust government-approved certificate authorities is raising concerns about weakened web security and state-enabled HTTPS interception. Critics argue it shifts control from browser vendors and the CA/Browser Forum to EU technocrats, potentially blocking mechanisms like Certificate Transparency and slow-walking revocation of compromised government CAs. Supporters counter that it strengthens European “digital sovereignty” against US-based tech giants, likening it to treating government-issued digital certificates like passports, while others point to mixed real-world experience with national eID systems across Europe.

Government CAs & eIDAS Changes

  • Current model: browser vendors (via CA/Browser Forum) decide which certificate authorities (CAs) to trust and can fully distrust misbehaving CAs.
  • Under eIDAS, EU‑designated “qualified” CAs must be trusted by browsers in the EU; vendors would need regulatory permission to remove them, even if compromised or abusive.
  • Critics see this as enabling governments to issue “dodgy” certificates and perform MITM interception, with browsers constrained in response.
  • Supporters frame it as shifting power from US‑centric browser makers to EU public institutions and “sovereign” authorities.

Security Mechanisms & Certificate Transparency

  • Several comments stress that trust in PKI relies on being able to revoke bad CAs quickly.
  • Concern: regulation may forbid browsers from requiring stronger mechanisms (e.g., Certificate Transparency, DANE, pinning) if these could block government‑issued certs.
  • Some note that CT currently makes silent MITM issuance costly because it exposes misissued certs; fear is eIDAS weakens this dynamic.

Digital Sovereignty vs Corporate Control

  • Pro‑eIDAS voices emphasize that browsers are owned/controlled by ad‑funded US companies subject to national security letters and opaque pressure.
  • They argue EU institutions are at least indirectly accountable to voters and better for “digital sovereignty” than unaccountable private consortia.
  • Opponents respond that governments wield coercive power and are harder for individuals to avoid than software vendors; voluntary, open CA/B processes are seen as more accountable in practice.

Cookie Banners as Cautionary Tale

  • Cookie consent pop‑ups are cited as an example of poorly designed or poorly enforced EU regulation.
  • Some argue devs intentionally implemented them in the most user‑hostile way; others say if everyone misinterprets a law, that’s a design/enforcement failure of the law itself.

National eID Systems: Pros, Cons, Exclusion

  • Users report mixed experiences with national eIDs (Sweden’s BankID, Spain’s DNIe, Dutch DigiD, SwissID, Singapore’s SingPass, Danish and French systems).
  • Positives: convenience, long stable operation, use for banking, taxes, and cross‑border EU services (under existing eIDAS).
  • Negatives: fraud incidents (e.g., BankID social engineering), dependence on banks; technical lock‑ins (rooted phones blocked, SMS‑only 2FA); difficulty for foreigners, temporary residents, and people abroad to obtain or recover access.
  • Some see this fragmentation as an argument for an EU‑wide standard; others warn about centralization, ossification, and bureaucratic failure.

Bureaucracy, Incident Response, and Risk

  • A recurring worry: in a large EU regulatory structure, revoking a compromised state CA could be slow and politicized, unlike today’s relatively nimble browser‑driven response.
  • Supporters counter that states already manage critical identity infrastructure (passports, IDs) and are experienced in dealing with fraud and forgery.