this post was submitted on 11 Jan 2024
44 points (100.0% liked)

Technology

60052 readers
3783 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
 

cross-posted from: https://infosec.pub/post/6945259

Let's talk about root certificate management and the EU proposed QWACs.

Steve Gibson of the security now podcast weighed in with opposition to the EUs proposed QWACs certs and cited a few other prominent figures also expressing opposition.

Paragraphing their concerns, they proposed that mandating a bunch of new CAs introduced more risk and greater opportunity for abuse or compromise. Steve favors less CAs also being in favor pruning out most, but 6 or 7.

At the moment, I don't care for browsers having their own certificate stores, as I would rather use the OS which I would use group policy for windows or use an automation tool for Linux.

I am also in favor of pruning out certs, though I've never tested that in an enterprise.

Does your organization allow non OS certificate stores?

Does your organization prune out default root certs?

How do you feel about the proposed QWACs?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 7 points 11 months ago

The real issue with QWACS is the idea that the EU government requires them to be added to web browsers running in the EU. It's bad enough that France and Germany can issue those certificates but imagine Erdogan's government pushing them out.

It's not like any politician knows how the Internet works and that someone who knows better couldn't rip those certificates out, but the tyranny of the default means that governments will have more control over EU citizens browsing. That's not something likely to benefit anyone.