Photo of Browser Padlock on Screen
© ktsdesign/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Top security experts have warned that a proposed revision to the European Union’s electronic Identification, Authentication, and Trust Services (eIDAS) would undermine long-established web security standards and expose users to various online threats, Mozilla said in a press release on Monday.

A recent report by the Economist Impact Studios for Mozilla and the “#SecurityRiskAhead” campaign said the revision may lead to “an increase in ID Theft, phishing, and financial fraud” and “even aid in the surveillance of dissidents by repressive regimes.”

The revision — labeled Article 45.2 of the eIDAS — proposes the establishment of a new type of web certificate known as a Qualified Website Authentication Certificate (QWAC), which would be issued by government-approved Trust Service Providers (TSP) operating in each European Union (EU) member state.

“Browsers would be required to trust certificates issued by those TSPs regardless of whether they would meet Root Program security requirements, and without any way to remove misbehaving CAs [Certificate Authorities],” Mozilla said in a March 2022 blog post questioning the initiative.

The proposed changes are “needlessly placing a limit on web security for citizens, users, the wider economy and even democracy,” the report said, adding that “a separate cybersecurity regime for the EU” risks the future security of the internet.

QWACs ‘Undermine Nearly Three Decades of Progress’

The eIDAS modifications require web browsers to accept QWACs as valid and safe without “extensive vetting and auditing.” CAs are “heavily vetted by each browser maker” before they are deemed safe enough and stored in a browse’s configuration files. Thanks to CAs, users are warned if a site’s certificate is invalid and presents a security risk.

Although the proposed revisions align with the EU’s GDPR, the report says it gives users a false sense of security and undermines decades of progress.

Arvid Vermote, GlobalSign’s chief information security officer, said the revision may create “an astronomical problem.”

“The big concern for me, in eIDAS Article 45.2, is the part that says browsers should accept any Certificate Authority in its root store when any of the EU member states says they should be accepted,” he said.

Vermote explained that having 34 instead of four supervisory bodies defining which companies can be globally trusted means “any traffic on the internet could be targeted for interception if those CAs are compromised.”

Meanwhile, Joseph Lorenzo Hall, senior vice president for strong Internet at Internet Society, said the European Commission is “letting geopolitics cloud clear, sound, security thinking.”

“What they [the Commmission] don’t seem to understand is that by bolting an exception mechanism on for EU government trusted entities, browsers will be forbidden, for example, from revoking trust for certain things. This means that you could have a group of websites online that are being spoofed, or being eavesdropped upon, by some compromised EU-anointed authority. And we are handcuffed and cannot do things that we would normally do very quickly to protect the people of the internet,” Hall said.

Repressive Regimes Could Abuse QWACs

Marshall Erwin, Mozilla’s vice president & chief security officer, said users would not benefit from QWACs, and it will do nothing to prevent phishing attacks and other threats.

Erwin explained that using QWACs would “turn back the clock on web security” to a level prior to the Let’s Encrypt project — a non-profit CA project founded in 2014 that helped propagate HTTPS encryption globally.

He said it would take just one “compromised employee in one of the new unaudited CAs to breach security,” meaning that certain regimes could conduct man-in-the-middle attacks to surveil dissidents and journalists operating locally and put them at immediate risk.

“This is something we’ve seen over and over again: repressive regimes want to compromise encrypted web traffic and gain clear text access to traffic on the Internet,” Erwin added.

Meanwhile, Scott Helme, an independent authentication and security researcher, noted that QWACs would also be very expensive compared to regular HTTPS encryption.

QWACs could cost as much as $1,000, he said, adding that paying for the technology doesn’t prevent abuse as fraudsters and scammers can “easily register businesses that sound similar to legitimate ones.”

Helme questioned why the EU is taking this path, adding that profit may be the end goal.

“I feel like this is driven more by organisations that will be selling these products in the future. So I wonder if the evidence that’s been presented to them is perhaps a little skewed,” he added.

How to Protect Yourself on the Web

With cyber threats becoming more sophisticated, web encryption standards serve as the bedrock of internet security, shielding users. Long-established standards like AES, TLS, RSA, and HTTPS exist to protect billions of internet users and countless organizations on the internet from cyber threats.

At VPNOverview, we recommend that you ensure the websites you visit are secured with a digital certificate. You can tell if a website is secure by looking for a padlock icon in the address bar.

Our cybersecurity experts also recommend adding an extra layer of encryption to your internet traffic with a virtual private network (VPN) and practicing proper cyber hygiene to stay safe online.

Leave a comment