FB pixel

Mozilla to Europeans updating eIDAS: Let’s give this more thought

Mozilla to Europeans updating eIDAS: Let’s give this more thought
 

Mozilla is waving off European Commission members, who are considering an update to their 2014 digital ID framework for online transactions.

The foundation, developer of the Firefox browser, pushes its pro-privacy stance hard. That is why it is noteworthy that its executives oppose digital ID security efforts by the only major economy that also seems to prioritize online privacy.

Indeed, executives at Mozilla say that they will not be able to honor their security commitments to Firefox users.

Commission members this year proposed an update to its electronic ID and trust services regulation, or eIDAS, improving interoperability and security of digital identification.

Important problems need to be addressed in the draft rules, however, according to a Mozilla white paper.

Changes being discussed would make browsers suspend root store policies necessary to maintain trust and security, Mozilla executives say. The policies “underpin a system of online trust” critical to protecting the security of every person using a browser.

Browsers also would have to accept website certificates that are “based on a flawed certificate architecture that is ill-suited” for online risks today. The so-called qualified web authentication certificates, or QWACs, are too risky, according to Mozilla.

Extended validation (EV) certificate architectures, which are based on QWACs, wrongly convince people that they are safe at a given site only to leave them open to phishing and domain impersonation.

In fact, according to a Mozilla blog post, “no major browser showcases EV certificates directly in the URL address bar.”

For these reasons, Mozilla says, the revisions being considered by the commission cannot make support for QWACs mandatory for browsers.

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Boarding tomorrow: SITA envisions the future of air travel in Singapore Experience Center

Jewel Changi waterfall at Singapore Changi Airport, November 2025 (Photo/Lu-Hai Liang) Singapore Changi has a singular distinction among airports. Besides the…

 

AgeAware goes live, setting up faceoff between reusable age check systems

AgeAware, the cryptographic token-based age assurance system developed by the nonprofit euCONSENT ASBL, has gone live. The launch comes in…

 

Scottish Biometrics Commissioner launches strategic plan, 4 police reviews

A better public understanding of how police in Scotland use biometrics and a series of reviews to provide assurance that…

 

EU AI Act proposals could rewire GDPR, water down tech regulations

The European Commission is considering amending its landmark AI Act as Brussels faces overwhelming pressure from U.S. tech companies and…

 

Yubico adds Hypr, Nametag identity verification options to passkey service

Yubico has added support for digital identity verification from Hypr and Nametag to its YubiKey as a Service platform to…

 

Wallets for the win: digital payment model enters pantheon of everyday tech

After Commodores, IBMs and Macs; Segas and Nintendos; mp3s and streaming services; smartphones and tablets and apps; biometrics and everything…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events