cross-posted from: https://lemmy.cafe/post/1482289

It’s an opinion article, but I heavily agree with it. It’s really sad that technical decisions are made by chimps who can’t tell the difference between a computer and internet.

  • library_napper@monyet.cc
    link
    fedilink
    arrow-up
    3
    ·
    7 months ago

    The eIDAS regulation makes an enormous change by mandating man-in-the-middle attack technology that it would be illegal for browser makers to defend against

    How would this law affect websites with Onion Services (eg Facebook) that don’t use http at all, but Tor’s internal pinned end-to-end encryption with a pinned certificate tied to the .onion name?

    • Illecors@lemmy.cafeOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 months ago

      This doesn’t affect websites as such - it’s the end clients, i.e. browsers that would be forced to accept gov issued CAs. I don’t see anyone going after TOR as it’s already a very niche thing, so it should be fine.