Skip to content

Comment on EU Digital Identity Reform: The Good, Bad and Ugly in the EIDAS Regulation

Comments

Its remarkable that citizens from mostly the US and UK think this is horrible, while most citizens from western Europe actually already deal with these systems on a national level - so it isn't anything new.

Similar to how bank transactions have been instant in Europe for more than two decades, but are still a novelty in the US. Or pre-filled tax forms.

This regulation should be seen in the context of the pre-existing systems which it builds on, towards a common European standard. An obvious criticism is that this centralizes power, but that is fundamentally rooted in the assumption that the EU is similar to the US: It's not.

In the EU the component States are very influential, they have formal or 'soft' veto's on practical all matters. There are no EU presential elections. The EU 'government' is run by appointees nominated by the States. Its much more like the US Confederacy. (pre- federation, long before civil war, not that confederacy)

Similar to how bank transactions have been instant in Europe for more than two decades, but are still a novelty in the US.

As the other commenter says, "Europe" is not a uniform entity. You may be thinking of some component of "Europe" where this may have been true for two decades. Wonder where that is.

In my experience, in the French component, this has absolutely not been the case. Only recently have "immediate" transfers become free at my bank, and they've only been available at all for a few years. Certainly less than 10 years.

And they're also not actually instant. I'm a freelance, and my professional account is at the same bank, same branch, as my personal account. The "instant" transfer is only credited the next day, even though it shows up quickly in pending transactions.

And this isn't some dingy "mom & pop" operation, it's the biggest bank in Europe (which may or may not help with these issues).

> This regulation should be seen in the context of the pre-existing systems which it builds on, towards a common European standard. An obvious criticism is that this centralizes power, but that is fundamentally rooted in the assumption that the EU is similar to the US: It's not.

In the EU the component States are very influential, they have formal or 'soft' veto's on practical all matters. There are no EU presential elections. The EU 'government' is run by appointees nominated by the States. Its much more like the US Confederacy.

I'm not familiar with US' workings or its history so can't comment on how close the EU is to it. But, at least in France, people do take issue with the centralization of power. "It's not the US" is actually an argument against centralization (again, not sure how correct this is).

Similar to how bank transactions have been instant in Europe for more than two decades

Please elaborate. Are you talking about some country-specific schemes? Cause I’m not aware of any EU-wide instant payment scheme that has existed for 20 years. AFAIK Instant SEPA Credit Transfers are still a relative novelty. My bank charges extra for them and there’s a cap of several thousand euros on the transfer amount.

In the Netherlands, instant transfers have been possible for at least 5 years. I think also in Belgium. This is indeed being rolled out to the whole EU.

[1] https://www.betaalvereniging.nl/en/focus/giro-based-and-onli...

How this technically works under the hood is less about any technical implementation and more about banks having agreements with each other. That said, it's amazing how fast you get used to instant bank transfers.

Instant transfers are the default method and there is no charge in Slovakia. But if it’s over few hundred Euro then it will usually downgrade to regular SEPA (usually next day).

In Italy we have already digital IDs through SPID[1] which is most likely going to be phased into eIDAS and it works a similar way (though way less standardized), government websites can integrate it willy-nilly while private companies have to undergo quite a rough approval process to make sure they absolutely need that information.

Given the amount of already digital tech in our gov (we also have "legal mail" via PEC[2] and a bunch others minor standards) I think it would be insane if EU just went "nice work you have there, now scrap it all and use ours instead", so I see why component states still have so much authority (even if it means some will not have a good time).

1. https://www.spid.gov.it/en/ 2. https://www.rfc-editor.org/rfc/rfc6109.html

With so much talk about eIDAS see actually a different trend.

For many years, we had Belgium Root CA in browsers but they have been replaced by Digicert certificates, effectively giving the US power over the encryption for all Belgian government services and more.

That really isn't how this works. DigiCert don't have any 'power' as you suggest - the .be government are free to choose any CA they wish from those who are globally trusted. These are for serverAuth certificates, too, so no-one is talking about internal/top-secret/sensitive intra-government communications.

Even if you were paranoid enough to think a US company like DigiCert would 'do anything' - their issuance is subject to public scrutiny (something the EU proposal doesn't like) and malfeasance has very real consequences to the whole of Digicert's business.

Before the change, the Belgian government did not have to choose any CA from "globally trusted". They were one of the globally trusted CAs.

I think the eIDAS is trying to revert the trend and put Europeans back in charge of their CAs. See for instance the eSignature Trusted Lists like this one [1]

I understand and support the intention. European Commission is just too bad at implementing it.

[1] https://ec.europa.eu/digital-building-blocks/DSS/webapp-demo...

DigiCert's HQ is a 10 minute drive away from the NSA's Utah Data Center. I don't think you you need to be particularly paranoid to think there might be foul play there.

That is how what specifically doesn't work? Could you specify? Digicert's root certificates serve all purposes, not just serverauth.

NSA can and will use CA certs to mitm when they want, there's no need for overt malfeasance on Digicert's side.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.