FB pixel

Mozilla steps up its attack on revising EU’s eIDAS regulations

Categories Biometrics News  |  Surveillance
Mozilla steps up its attack on revising EU’s eIDAS regulations
 

Changes being contemplated for the EU’s eIDAS regulation could make people on the web less secure and make state surveillance easier, says Mozilla, the nonprofit developer of the Firefox browser.

In a report published today, Mozilla is warning that Article 45.2 of the European Union’s eIDAS is in danger of revisions that would weaken security, posing risks to web authentication and encryption standards.

Browsers might be required to recognize qualified web authentication certificates that the EU creates. The stamps of legitimacy are known by the profoundly unself-conscious acronym QWACs.

The certificates would not be free, as current documentation is and, according to Mozilla, will be inferior in securing the web compared to the certificates issued today.

It is not a new objection, at least not for Mozilla, which has been lobbying European politicians on the matter for some time.

A small handful of web notables are highlighted in the report agreeing with the warning. They include a senior vice president at the Internet Society, a GlobalSign chief information security officer and Mozilla’s own chief security officer.

The Internet Society’s Joseph Lorenzo Hall is quoted saying that politicians are playing with the idea of “bolting an exception mechanism on for EU government trusted entities.”

Doing that, Hall says means “browsers will be forbidden, for example, from revoking trust for certain things.” The community would be prevented from acting quickly and unilaterally to sites known to be spoofed or those that are being bugged.

Arvid Vermote, CISO at certificate authority GlobalSign, says the changes would multiply the number of bodies that can define “globally trusted” from four now to upwards of 30. That would make consensus-making and much harder resulting in some poor decisions inevitable.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

ID4Africa vendors see Africa leapfrogging legacy digital identity systems

The annual ID4Africa AGM is a major world event in identity – a must-attend for many biometrics providers working on…

 

Gataca boosts age assurance pitch with certification to ISO standard by ACCS

Madrid-based Gataca is now certified as a provider of privacy-preserving age assurance following an independent assessment. The company successfully completed…

 

BixeLab testing activity highlights expansion of biometric assurance

As digital identity systems evolve, biometric testing labs are increasingly becoming central to trust, compliance and interoperability. BixeLab’s recent activity…

 

Apple removes Russian digital ID app Max from its stores citing sanctions

Apple has removed Russian state-backed messaging and digital ID platform Max from its official App Store, affecting more than 20…

 

G7 backs privacy-preserving age assurance as Japan proposes social media access limits

Japan is considering new restrictions on minors’ access to social media while stopping short of blanket age bans. While countries…

 

Digital company ID could save UK financial sector £1.7B: CFIT

A UK initiative to create a reusable digital identity credential for businesses could save financial institutions £1.7 billion (US$2.2 billion)…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events