Sam
5.1K posts


This obsession to continuously shorten the validity period of TLS certificates is just baffling. Claims to improve security without any actual evidence, and not a word about service disruption due to renewal failure...
Cryptoki@Cryptoki
Let's Encrypt announces 6 day validity and IP address #TLS certs letsencrypt.org/2025/01/16/6-d…
English

Why quantum computers are probably not a threat worth your time and money (source: ches.iacr.org/2024/Jaques_CH…)

English
Sam retweeted
Sam retweeted

The first five Implementing Acts for the European Identity Wallet (Art. 5a & 5c #eIDAS 2 - Regulation) have been published in the EU Official Journal! They will enter into force (triggering the 2-year implementation period) as X-mas present on 24th Dec.: eur-lex.europa.eu/search.html?SU…
English
Sam retweeted
Draft ETSI TS 119 471 V0.0.11 (2024-11)
Policy and Security requirements for Providers of Electronic
Attestation of Attributes Services
docbox.etsi.org/esi/Open/Lates…
欧州のeIDAS2.0 は、DIWに限らず、「属性証明」に向かっていて、これは重要だよ。

日本語

@Tweetddale @Joerg_Lenz LOL absolutely not, where did you get such hilarious nonsense ? Can't wait to tell the actual IA team, they will laugh pretty hard at that🤣
English

@sam280 @Joerg_Lenz @sam280, respectfully, Steffen is leading the writing of the actual Implementing Acts on these topics. Probably not the best to refer to him as a fake self-proclaimed expert 🙃
English

Apparently some work is needed to make the ARF more comprehensible 🙁
QEAAs are not "Substantial LoA" credentials, and PID is not a special kind of "High LoA" QEAA that relies on a QTSP.
Alex Tweeddale 🆔⚛️@Tweetddale
Yet, these "High" LoA credentials will only make up a tiny proportion of the total number of credentials in circulation within the EUDI ecosystem. The majority of credentials for European markets will be either "Low" or "Substantial" LoA.
English

@sam280 You’re right: even if QEAAs are accepted by MS for identification purposes, they are not electronic identification means from a legal perspective and, thus, they don’t have any LoA
English

@Joerg_Lenz Nice, someone already noticed that PuB-EAA are missing from the diagram😀👍
English

@Joerg_Lenz The opinion of a fake self-proclaimed expert is irrelevant to me 🙂 This diagram is wrong on many aspects, which hopefully will get clarified when the first implementing acts are published (soon). An hopefully QTSPs have a better understanding of where their opportunities lie.
English

@R_Garavaglia That's what I'm trying to do :) these topics were discussed during the negotiations on art. 5a and 5c of the regulation, but not at the level of implementing acts where this committee took place.
English

📢 THE FIRST FIVE IMPLEMENTING ACTS REGARDING EUDI WALLET HAS BEEN VOTED
On November 21, 2024, the 3rd #eIDAS Committee meeting resulted in the adoption of five key implementing acts for the #eIDAS2 regulation.
#EUDIWallet
linkedin.com/posts/robertog…

English

The "public discussion" that D-Trust had to go through for their CCADB root store inclusion request was a disgrace. Under #eIDAS, CAB accreditation prevents random internet bullies from harassing respectable QTSPs.
groups.google.com/a/ccadb.org/g/…
English
Sam retweeted

@BainaA17 @AvramVali199699 France is not testing the EU Wallet, because neither the legal basis, nor the technical specifications, are complete yet. France Identité is something else.
English

@AvramVali199699 Yes, for now it is not mandatory. In France it is in the test phase, there are more than a million people who have downloaded the application.
English

In May 2024, the Japan Institute of Research released a report concerning the eIDAS, the European digital identity wallet. Here are two selected parts that are particularly interesting. The eIDAS strongly resembles what #Jasmy offers, aligning closely with Japan's recent initiatives in digital identity. #JAPAN funded 50% of pilot projects to support use cases within the European Union. These initiatives aim to simplify access to public and private services (such as opening bank accounts, registering SIM cards, and enabling cross-border payments) ahead of a large-scale deployment.
The wallet would allow EU citizens to store digital identifiers and personal documents (such as ID cards, driver's licenses, and medical records) directly on their devices, like smartphones. The goal is to create a unified digital identification system, harmonizing standards and guidelines to ensure secure identification recognized in all member states. This would facilitate identity verification in various contexts, both public and private.
The report also highlights adaptability to new technologies, particularly electronic services like blockchain, through mechanisms for electronic archiving and record management, integrated into mobile devices. Compliance with European regulations, especially the GDPR for data protection, is also crucial. Measures are proposed to resolve potential conflicts between regulations, particularly in cybersecurity. (#Jasmy complies with this law.)
Lastly, the system aims to provide users with better control over their personal data, allowing them to choose which information to share while minimizing risks of undesirable surveillance by third parties.


English

Advanced Electronic Signatures (AdES) have been adopted by the EU with eIDAS2, and which gives a legal standing for digital signing. With eIDAS-2, there are five signature methods. Here is XAdES (XML Advanced Electronic Signatures): asecuritysite.com/signatures/xad…

English

Not all TLS certificates are created equal, and a thorough applicant verification is imperative 🤷 #eIDAS #QWAC
watchTowr@watchtowrcyber
In August, watchTowr Labs hijacked parts of the global .mobi TLD - and went on to discover the mayhem that we could cause. Enjoy.... labs.watchtowr.com/we-spent-20-to…
English

