User Controls
Poll: ???
-
lol
- vindicktive vinny ,
- Donald Trump ,
- Lanny ,
- Frothy ,
- Kingoffrogs ,
- Haxxor ,
- Mik ,
- Instigator
-
lmao
- vindicktive vinny ,
- Donald Trump ,
- Lanny ,
- Kawkasian ,
- Kingoffrogs ,
- Speedy Parker ,
- RIPtotse ,
- Xlite ,
- trippymindfuk ,
- Sudo ,
- squidwarth
UK Online Safety Bill Passes
-
2023-11-15 at 11:18 AM UTC
Originally posted by aldra second sentence, the companies that issue and verify SSL certificates, the EU wants to control them so that they can decrypt SSL-encrypted traffic.
this only relates to SSL, has nothing to do with tor, though it wouldn't be too hard to shut down tor access if they can get enough ISPs onboard for packet inspection/interception
Proxy interception is already a thing on corporate networks. The browsers there have custom certs inserted that enable interception. The computational cost is pretty high, and they don't do anything with the information, but it's a thing.
Getting the root certificate authorities to give their private keys to government is the next, logical step. It'll happen. -
2023-11-15 at 11:20 AM UTCyeah, usually it's pretty obvious that you're given the wrong SSL cert in that circumstance though
this would bar the browser from warning you, if it even needs to considering they'd be able to just log encrypted data and decrypt it later -
2023-11-15 at 11:23 AM UTC
-
2023-11-15 at 1:31 PM UTC
Originally posted by aldra https://last-chance-for-eidas.org
now they basically want the government/s to control all CAs in the EU and force all browsers to hard trust them (cannot be queried, interrogated, blacklisted etc.).
this means that all of the Certificate Authorities that manage SSL certs for every major site will have to give up their private signing keys so that EU governments can decrypt SSL traffic and ostensibly forge certs for other purposes like impersonating sites and MITM attacks.
in theory it undermines the entire SSL scheme, in practice you could install a non-EU compliant browser but it'd still undermine trust in the tiered certificate system because the CAs operating in the EU (a major market) would be forced to give up their keys, which affects everyone.
self-sign everything
i dont understand whats the implication here.
EU is just a very small geographical area and likewise demographically miniscule.
so i dont live in the EU and cant remember whens that last time my life is dependent on EU generated content.
and neither do most of us. -
2023-11-15 at 1:35 PM UTCif SSL cert authorities have to hand over their private keys to the EU it makes everyone insecure. consider that it's illegal for most of the intelligence agencies to spy on the communications of US citizens, so instead they have other members of the Five Eyes group do it and pass the information back as a workaround.
potentially they could sign EU and international certs with different keys so that they're not compelled to give up the international keys, but regardless it sets yet another dangerous precedent for cryptographic security. -
2023-11-15 at 1:39 PM UTC
Originally posted by aldra if SSL cert authorities have to hand over their private keys to the EU it makes everyone insecure. consider that it's illegal for most of the intelligence agencies to spy on the communications of US citizens, so instead they have other members of the Five Eyes group do it and pass the information back as a workaround.
potentially they could sign EU and international certs with different keys so that they're not compelled to give up the international keys, but regardless it sets yet another dangerous precedent for cryptographic security.
so people and sites that truly value privacy and security would just either self sign or use certs from non-EU controlled parties. -
2023-11-15 at 1:41 PM UTC
Originally posted by vindicktive vinny so people and sites that truly value privacy and security would just either self sign or use certs from non-EU controlled parties.
self-signing and managing trust is beyond most peoples' understanding.
the other component is they're mandating browsers to accept the state-controlled CAs and the (possibly malicious) certificates they issue -
2023-11-15 at 1:42 PM UTC'padlock good'
-
2023-11-15 at 1:44 PM UTC
Originally posted by aldra self-signing and managing trust is beyond most peoples' understanding.
the other component is they're mandating browsers to accept the state-controlled CAs and the (possibly malicious) certificates they issue
impossible unless they force-upgrade everyone and every site like how they have done with GDR or whatever that cookie-consent thing is called. -
2023-11-15 at 1:54 PM UTC
-
2023-11-15 at 1:54 PM UTC
-
2023-11-15 at 2:01 PM UTCThe globalist traitors to humanity are losing bad, so they need to get rid of the truth, at all costs. If they don't stop the truth, they're finished.
-
2023-11-15 at 2:03 PM UTC
-
2023-11-15 at 2:04 PM UTC
-
2023-11-15 at 2:05 PM UTCwhys that ?
-
2023-11-15 at 2:08 PM UTC
-
2023-11-15 at 2:09 PM UTC
-
2023-11-15 at 2:11 PM UTC
-
2023-11-15 at 2:26 PM UTC
-
2023-11-15 at 2:28 PM UTC