<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Article 45 Will Roll Back Web Security by 12 Years in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64366#M6506</link>
    <description>Just encrypt the disks… then if they get stolen… &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;</description>
    <pubDate>Wed, 08 Nov 2023 13:17:01 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2023-11-08T13:17:01Z</dc:date>
    <item>
      <title>Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64464#M6500</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lawmakers in Europe are expected to adopt digital identity rules that civil society groups say will make the internet less secure and open up citizens to online surveillance.&lt;/P&gt;&lt;P&gt;The legislation, referred to as eIDAS (electronic IDentification, Authentication and trust Services) 2.0, has been described as an attempt to modernize an initial version of the digital identity and trust service rules. The rules cover things like electronic signatures, time stamps, registered delivery services, and certificates for website authentication.&lt;/P&gt;&lt;P&gt;But one of the requirements of &lt;A href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2014.257.01.0073.01.ENG" target="_blank" rel="nofollow noopener"&gt;eIDAS 2.0&lt;/A&gt; is that browser makers trust government-approved Certificate Authorities (CA) and do not implement security controls beyond those specified by the European Telecommunications Standards Institute (ETSI).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theregister.com/2023/11/08/europe_eidas_browser/" target="_blank"&gt;https://www.theregister.com/2023/11/08/europe_eidas_browser/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is true, you have a complete surveillance state - 1984 reigns.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is it scaremongering?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 21:19:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64464#M6500</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-11-12T21:19:13Z</dc:date>
    </item>
    <item>
      <title>Article 45 Will Roll Back Web Security by 12 Years</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64341#M6503</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The EFF has issued a warning that the EU is about to introduce a new law that will enable EU/national governments to secretly eavesdrop on all web communications among their own citizens.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-years" target="_blank"&gt;https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-years&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering how/what this inter-operates with GDPR and how it will affect folks in other countries that do business in the EU.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would love other folks thoughts/comments/concerns regarding this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 00:53:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64341#M6503</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2023-11-08T00:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Article 45 Will Roll Back Web Security by 12 Years</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64346#M6504</link>
      <description>You pick up that sword, you just don’t want to put it down again…&lt;BR /&gt;&lt;BR /&gt;I’d say it’s incompatible with the GDPR as that took into account government eavesdropping- anyone not familiar with the Stasi should please down tools and go and watch the lives of others immediately.&lt;BR /&gt;&lt;BR /&gt;Like the Patriot Act this causes issues when trying to take the high moral ground with authoritarian regimes.&lt;BR /&gt;&lt;BR /&gt;I guess there is a balance to be struck, but I don’t see any extraordinary threat to offset the harm this would cause - and to any government, especially the EU which is a sort of weird overlay I’d say you created and built none of these tools - really, stop snooping and mind your own business.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Nov 2023 02:04:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64346#M6504</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-08T02:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Article 45 Will Roll Back Web Security by 12 Years</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64365#M6505</link>
      <description>&lt;P&gt;I guess as long as the EU does a good job of encrypting the data at rest...?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":clown_face:"&gt;🤡&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:14:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64365#M6505</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-11-08T13:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Article 45 Will Roll Back Web Security by 12 Years</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64366#M6506</link>
      <description>Just encrypt the disks… then if they get stolen… &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:17:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64366#M6506</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-08T13:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64471#M6501</link>
      <description>Maybe they can fold it in with the LLM stego encoding request..? &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Anyway this is a bad idea, unless the EU wants to weaken the security of it’s citizens and allies…</description>
      <pubDate>Mon, 13 Nov 2023 08:05:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64471#M6501</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-13T08:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64503#M6502</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&amp;nbsp; At least Germany is chirping up, and complaining about, there appears a lot of group-think and sheep thinking going on at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It certainly is bad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 19:20:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64503#M6502</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-11-13T19:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64514#M6507</link>
      <description>Yes the Germans are at least sensible due to East Germany and before.&lt;BR /&gt;&lt;BR /&gt;If find it hard to reconcile this EU with the one that was furious about patriot act, Prism and Merkle’s phone tap… do we now have a chance of the US complaining about data transfers to h the EU under the safe data privacy shield harbour Atlantean Transit Data framework? Seems a shame to make all that noise publicly and then drop all your principles…&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Nov 2023 23:04:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64514#M6507</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-13T23:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Article 45 Will Roll Back Web Security by 12 Years</title>
      <link>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64705#M6518</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&amp;nbsp; This is okay, as a strategy, as long as they are Quantum-Resistant.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Harvest Now, Decrypt Later (HNDL)....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you remember how long it took the payments industry to change over from SSL v3 after the POODLE attack to TLS v1.2?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It took four years....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 03:07:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Bad-eIDAS-Europe-ready-to-intercept-spy-on-your-encrypted-HTTPS/m-p/64705#M6518</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-11-20T03:07:34Z</dc:date>
    </item>
  </channel>
</rss>

