CINXE.COM
The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web - Open Policy & Advocacy
<!DOCTYPE html> <html lang="en-US" dir="ltr" class="no-js"> <head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="license" href="#license"> <link rel="profile" href="https://gmpg.org/xfn/11"> <link rel="shortcut icon" type="image/png" href="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/favicon.png"> <!--[if IE]> <meta name="MSSmartTagsPreventParsing" content="true"> <meta http-equiv="imagetoolbar" content="no"> <meta http-equiv="X-UA-Compatible" content="IE=Edge"> <![endif]--> <!--[if lte IE 8]> <script src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/js/html5.js"></script> <link rel="shortcut icon" type="image/x-icon" href="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/favicon.ico"> <link rel="stylesheet" type="text/css" media="all" href="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/oldIE.css"> <![endif]--> <style type="text/css"> @media screen and (min-width: 480px) { #masthead { background-image: url('https://blog.mozilla.org/netpolicy/files/2017/02/cropped-blog-header-policy.jpg'); } } </style> <meta name="title" content="The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web – Open Policy & Advocacy"> <meta name="description" content="Since its founding in 1998, Mozilla has championed human-rights-compliant innovation as well as choice, control, and privacy for people on the Internet. We have worked hard to actualise this belief ..."> <meta property="og:site_name" content="Open Policy & Advocacy"> <meta property="og:url" content="https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web"> <meta property="og:title" content="The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web – Open Policy & Advocacy"> <meta property="og:description" content="Since its founding in 1998, Mozilla has championed human-rights-compliant innovation as well as choice, control, and privacy for people on the Internet. We have worked hard to actualise this belief ..."> <meta property="twitter:title" content="The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web – Open Policy & Advocacy"> <meta property="twitter:description" content="Since its founding in 1998, Mozilla has championed human-rights-compliant innovation as well as choice, control, and privacy for people on the Internet. We have worked hard to actualise this belief ..."> <meta name="twitter:card" content="summary"> <meta property="twitter:image" content="https://blog.mozilla.org/netpolicy/files/2017/02/cropped-blog-header-policy.jpg"> <meta name="twitter:site" content="@mozilla"> <meta name='robots' content='index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1' /> <meta name="blog-name" content="Open Policy & Advocacy" /> <!-- This site is optimized with the Yoast SEO plugin v22.5 - https://yoast.com/wordpress/plugins/seo/ --> <title>The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web - Open Policy & Advocacy</title> <link rel="canonical" href="https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/" /> <meta name="twitter:label1" content="Written by" /> <meta name="twitter:data1" content="Udbhav Tiwari, Ben Wilson" /> <meta name="twitter:label2" content="Est. reading time" /> <meta name="twitter:data2" content="3 minutes" /> <script type="application/ld+json" class="yoast-schema-graph">{"@context":"https://schema.org","@graph":[{"@type":"WebPage","@id":"https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/","url":"https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/","name":"The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web - Open Policy & Advocacy","isPartOf":{"@id":"https://blog.mozilla.org/netpolicy/#website"},"datePublished":"2020-10-08T13:42:24+00:00","dateModified":"2020-10-08T13:42:24+00:00","author":{"@id":"https://blog.mozilla.org/netpolicy/#/schema/person/ff14f0f0ab51ea9d14fa40b60ab45046"},"breadcrumb":{"@id":"https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/"]}]},{"@type":"BreadcrumbList","@id":"https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://blog.mozilla.org/netpolicy/"},{"@type":"ListItem","position":2,"name":"The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web"}]},{"@type":"WebSite","@id":"https://blog.mozilla.org/netpolicy/#website","url":"https://blog.mozilla.org/netpolicy/","name":"Open Policy & Advocacy","description":"Mozilla's official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://blog.mozilla.org/netpolicy/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https://blog.mozilla.org/netpolicy/#/schema/person/ff14f0f0ab51ea9d14fa40b60ab45046","name":"Udbhav Tiwari","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https://blog.mozilla.org/netpolicy/#/schema/person/image/f699f32e51f4160a4535df8e4fee7f12","url":"https://secure.gravatar.com/avatar/4f8624c8f8ea1e841eaa162ab2a2c0ce?s=96&d=mm&r=g","contentUrl":"https://secure.gravatar.com/avatar/4f8624c8f8ea1e841eaa162ab2a2c0ce?s=96&d=mm&r=g","caption":"Udbhav Tiwari"}}]}</script> <!-- / Yoast SEO plugin. --> <link rel="alternate" type="application/rss+xml" title="Open Policy & Advocacy » Feed" href="https://blog.mozilla.org/netpolicy/feed/" /> <link rel="alternate" type="application/rss+xml" title="Open Policy & Advocacy » Comments Feed" href="https://blog.mozilla.org/netpolicy/comments/feed/" /> <link rel='stylesheet' id='wp-block-library-css' href='https://blog.mozilla.org/netpolicy/wp-includes/css/dist/block-library/style.min.css?ver=6.3.5' type='text/css' media='all' /> <style id='co-authors-plus-coauthors-style-inline-css' type='text/css'> .wp-block-co-authors-plus-coauthors.is-layout-flow [class*=wp-block-co-authors-plus]{display:inline} </style> <style id='co-authors-plus-avatar-style-inline-css' type='text/css'> .wp-block-co-authors-plus-avatar :where(img){height:auto;max-width:100%;vertical-align:bottom}.wp-block-co-authors-plus-coauthors.is-layout-flow .wp-block-co-authors-plus-avatar :where(img){vertical-align:middle}.wp-block-co-authors-plus-avatar:is(.alignleft,.alignright){display:table}.wp-block-co-authors-plus-avatar.aligncenter{display:table;margin-inline:auto} </style> <style id='co-authors-plus-image-style-inline-css' type='text/css'> .wp-block-co-authors-plus-image{margin-bottom:0}.wp-block-co-authors-plus-image :where(img){height:auto;max-width:100%;vertical-align:bottom}.wp-block-co-authors-plus-coauthors.is-layout-flow .wp-block-co-authors-plus-image :where(img){vertical-align:middle}.wp-block-co-authors-plus-image:is(.alignfull,.alignwide) :where(img){width:100%}.wp-block-co-authors-plus-image:is(.alignleft,.alignright){display:table}.wp-block-co-authors-plus-image.aligncenter{display:table;margin-inline:auto} </style> <style id='classic-theme-styles-inline-css' type='text/css'> /*! This file is auto-generated */ .wp-block-button__link{color:#fff;background-color:#32373c;border-radius:9999px;box-shadow:none;text-decoration:none;padding:calc(.667em + 2px) calc(1.333em + 2px);font-size:1.125em}.wp-block-file__button{background:#32373c;color:#fff;text-decoration:none} </style> <style id='global-styles-inline-css' type='text/css'> body{--wp--preset--color--black: #000000;--wp--preset--color--cyan-bluish-gray: #abb8c3;--wp--preset--color--white: #ffffff;--wp--preset--color--pale-pink: #f78da7;--wp--preset--color--vivid-red: #cf2e2e;--wp--preset--color--luminous-vivid-orange: #ff6900;--wp--preset--color--luminous-vivid-amber: #fcb900;--wp--preset--color--light-green-cyan: #7bdcb5;--wp--preset--color--vivid-green-cyan: #00d084;--wp--preset--color--pale-cyan-blue: #8ed1fc;--wp--preset--color--vivid-cyan-blue: #0693e3;--wp--preset--color--vivid-purple: #9b51e0;--wp--preset--gradient--vivid-cyan-blue-to-vivid-purple: linear-gradient(135deg,rgba(6,147,227,1) 0%,rgb(155,81,224) 100%);--wp--preset--gradient--light-green-cyan-to-vivid-green-cyan: linear-gradient(135deg,rgb(122,220,180) 0%,rgb(0,208,130) 100%);--wp--preset--gradient--luminous-vivid-amber-to-luminous-vivid-orange: linear-gradient(135deg,rgba(252,185,0,1) 0%,rgba(255,105,0,1) 100%);--wp--preset--gradient--luminous-vivid-orange-to-vivid-red: linear-gradient(135deg,rgba(255,105,0,1) 0%,rgb(207,46,46) 100%);--wp--preset--gradient--very-light-gray-to-cyan-bluish-gray: linear-gradient(135deg,rgb(238,238,238) 0%,rgb(169,184,195) 100%);--wp--preset--gradient--cool-to-warm-spectrum: linear-gradient(135deg,rgb(74,234,220) 0%,rgb(151,120,209) 20%,rgb(207,42,186) 40%,rgb(238,44,130) 60%,rgb(251,105,98) 80%,rgb(254,248,76) 100%);--wp--preset--gradient--blush-light-purple: linear-gradient(135deg,rgb(255,206,236) 0%,rgb(152,150,240) 100%);--wp--preset--gradient--blush-bordeaux: linear-gradient(135deg,rgb(254,205,165) 0%,rgb(254,45,45) 50%,rgb(107,0,62) 100%);--wp--preset--gradient--luminous-dusk: linear-gradient(135deg,rgb(255,203,112) 0%,rgb(199,81,192) 50%,rgb(65,88,208) 100%);--wp--preset--gradient--pale-ocean: linear-gradient(135deg,rgb(255,245,203) 0%,rgb(182,227,212) 50%,rgb(51,167,181) 100%);--wp--preset--gradient--electric-grass: linear-gradient(135deg,rgb(202,248,128) 0%,rgb(113,206,126) 100%);--wp--preset--gradient--midnight: linear-gradient(135deg,rgb(2,3,129) 0%,rgb(40,116,252) 100%);--wp--preset--font-size--small: 13px;--wp--preset--font-size--medium: 20px;--wp--preset--font-size--large: 36px;--wp--preset--font-size--x-large: 42px;--wp--preset--spacing--20: 0.44rem;--wp--preset--spacing--30: 0.67rem;--wp--preset--spacing--40: 1rem;--wp--preset--spacing--50: 1.5rem;--wp--preset--spacing--60: 2.25rem;--wp--preset--spacing--70: 3.38rem;--wp--preset--spacing--80: 5.06rem;--wp--preset--shadow--natural: 6px 6px 9px rgba(0, 0, 0, 0.2);--wp--preset--shadow--deep: 12px 12px 50px rgba(0, 0, 0, 0.4);--wp--preset--shadow--sharp: 6px 6px 0px rgba(0, 0, 0, 0.2);--wp--preset--shadow--outlined: 6px 6px 0px -3px rgba(255, 255, 255, 1), 6px 6px rgba(0, 0, 0, 1);--wp--preset--shadow--crisp: 6px 6px 0px rgba(0, 0, 0, 1);}:where(.is-layout-flex){gap: 0.5em;}:where(.is-layout-grid){gap: 0.5em;}body .is-layout-flow > .alignleft{float: left;margin-inline-start: 0;margin-inline-end: 2em;}body .is-layout-flow > .alignright{float: right;margin-inline-start: 2em;margin-inline-end: 0;}body .is-layout-flow > .aligncenter{margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > .alignleft{float: left;margin-inline-start: 0;margin-inline-end: 2em;}body .is-layout-constrained > .alignright{float: right;margin-inline-start: 2em;margin-inline-end: 0;}body .is-layout-constrained > .aligncenter{margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > :where(:not(.alignleft):not(.alignright):not(.alignfull)){max-width: var(--wp--style--global--content-size);margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > .alignwide{max-width: var(--wp--style--global--wide-size);}body .is-layout-flex{display: flex;}body .is-layout-flex{flex-wrap: wrap;align-items: center;}body .is-layout-flex > *{margin: 0;}body .is-layout-grid{display: grid;}body .is-layout-grid > *{margin: 0;}:where(.wp-block-columns.is-layout-flex){gap: 2em;}:where(.wp-block-columns.is-layout-grid){gap: 2em;}:where(.wp-block-post-template.is-layout-flex){gap: 1.25em;}:where(.wp-block-post-template.is-layout-grid){gap: 1.25em;}.has-black-color{color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-color{color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-color{color: var(--wp--preset--color--white) !important;}.has-pale-pink-color{color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-color{color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-color{color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-color{color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-color{color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-color{color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-color{color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-color{color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-color{color: var(--wp--preset--color--vivid-purple) !important;}.has-black-background-color{background-color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-background-color{background-color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-background-color{background-color: var(--wp--preset--color--white) !important;}.has-pale-pink-background-color{background-color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-background-color{background-color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-background-color{background-color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-background-color{background-color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-background-color{background-color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-background-color{background-color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-background-color{background-color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-background-color{background-color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-background-color{background-color: var(--wp--preset--color--vivid-purple) !important;}.has-black-border-color{border-color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-border-color{border-color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-border-color{border-color: var(--wp--preset--color--white) !important;}.has-pale-pink-border-color{border-color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-border-color{border-color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-border-color{border-color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-border-color{border-color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-border-color{border-color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-border-color{border-color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-border-color{border-color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-border-color{border-color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-border-color{border-color: var(--wp--preset--color--vivid-purple) !important;}.has-vivid-cyan-blue-to-vivid-purple-gradient-background{background: var(--wp--preset--gradient--vivid-cyan-blue-to-vivid-purple) !important;}.has-light-green-cyan-to-vivid-green-cyan-gradient-background{background: var(--wp--preset--gradient--light-green-cyan-to-vivid-green-cyan) !important;}.has-luminous-vivid-amber-to-luminous-vivid-orange-gradient-background{background: var(--wp--preset--gradient--luminous-vivid-amber-to-luminous-vivid-orange) !important;}.has-luminous-vivid-orange-to-vivid-red-gradient-background{background: var(--wp--preset--gradient--luminous-vivid-orange-to-vivid-red) !important;}.has-very-light-gray-to-cyan-bluish-gray-gradient-background{background: var(--wp--preset--gradient--very-light-gray-to-cyan-bluish-gray) !important;}.has-cool-to-warm-spectrum-gradient-background{background: var(--wp--preset--gradient--cool-to-warm-spectrum) !important;}.has-blush-light-purple-gradient-background{background: var(--wp--preset--gradient--blush-light-purple) !important;}.has-blush-bordeaux-gradient-background{background: var(--wp--preset--gradient--blush-bordeaux) !important;}.has-luminous-dusk-gradient-background{background: var(--wp--preset--gradient--luminous-dusk) !important;}.has-pale-ocean-gradient-background{background: var(--wp--preset--gradient--pale-ocean) !important;}.has-electric-grass-gradient-background{background: var(--wp--preset--gradient--electric-grass) !important;}.has-midnight-gradient-background{background: var(--wp--preset--gradient--midnight) !important;}.has-small-font-size{font-size: var(--wp--preset--font-size--small) !important;}.has-medium-font-size{font-size: var(--wp--preset--font-size--medium) !important;}.has-large-font-size{font-size: var(--wp--preset--font-size--large) !important;}.has-x-large-font-size{font-size: var(--wp--preset--font-size--x-large) !important;} .wp-block-navigation a:where(:not(.wp-element-button)){color: inherit;} :where(.wp-block-post-template.is-layout-flex){gap: 1.25em;}:where(.wp-block-post-template.is-layout-grid){gap: 1.25em;} :where(.wp-block-columns.is-layout-flex){gap: 2em;}:where(.wp-block-columns.is-layout-grid){gap: 2em;} .wp-block-pullquote{font-size: 1.5em;line-height: 1.6;} </style> <link rel='stylesheet' id='frontierline-css' href='https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/style.css?ver=1715715365' type='text/css' media='all' /> <script type='text/javascript' src='https://blog.mozilla.org/wp-content/mu-plugins/mozilla-custom/ga-snippet.js?ver=.4' id='ga-snippet-js'></script> <script type='text/javascript' src='https://blog.mozilla.org/netpolicy/wp-includes/js/jquery/jquery.min.js?ver=3.7.0' id='jquery-core-js'></script> <script type='text/javascript' src='https://blog.mozilla.org/netpolicy/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1' id='jquery-migrate-js'></script> <script type='text/javascript' src='https://blog.mozilla.org/netpolicy/wp-content/plugins/wp-hide-post/public/js/wp-hide-post-public.js?ver=2.0.10' id='wp-hide-post-js'></script> <link rel="https://api.w.org/" href="https://blog.mozilla.org/netpolicy/wp-json/" /><link rel="alternate" type="application/json" href="https://blog.mozilla.org/netpolicy/wp-json/wp/v2/posts/1845" /><link rel="EditURI" type="application/rsd+xml" title="RSD" href="https://blog.mozilla.org/netpolicy/xmlrpc.php?rsd" /> <link rel='shortlink' href='https://blog.mozilla.org/netpolicy/?p=1845' /> <link rel="alternate" type="application/json+oembed" href="https://blog.mozilla.org/netpolicy/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fblog.mozilla.org%2Fnetpolicy%2F2020%2F10%2F08%2Fthe-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web%2F" /> <link rel="alternate" type="text/xml+oembed" href="https://blog.mozilla.org/netpolicy/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fblog.mozilla.org%2Fnetpolicy%2F2020%2F10%2F08%2Fthe-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web%2F&format=xml" /> <style type="text/css" id="wp-custom-css"> .entry-content .faq { counter-reset: faq-counter; } .entry-content .faq .faq-question { font-size: 24px; font-weight: bold; background: #ededf0; color: #20123a; font-style: normal; padding: 4px 16px 4px 64px; margin: 0 0 1em; position: relative; } .entry-content .faq .faq-question:before { content: counter(faq-counter); counter-increment: faq-counter; position: absolute; left: 0; top: 0; bottom: 0; padding: 4px 8px; width: 48px; box-sizing: border-box; height: 100%; background: #e31587; color: white; } .entry-content .faq .faq-answer { margin: 0 0 3em; padding: 0; } </style> </head> <body class="post-template-default single single-post postid-1845 single-format-standard color-scheme-lime pattern-none" data-blogname="Open Policy & Advocacy"> <nav id="nav-global" class="nav-global can-stick"> <div class="content"> <div class="logo"><a href="https://www.mozilla.org/?utm_source=blog.mozilla.org&utm_medium=referral&utm_campaign=blog-nav" rel="external" title="Visit mozilla.org">Mozilla</a></div> <div class="nav-mozilla"> <span class="toggle" role="button" aria-controls="nav-mozilla-menu" aria-expanded="false" tabindex="0">Menu</span> <ul class="nav-mozilla-menu" id="nav-mozilla-menu"> <li class="nav-global-health"><a href="https://www.mozilla.org/about/?utm_source=blog.mozilla.org&utm_medium=referral&utm_campaign=blog-nav" rel="external">About Mozilla</a></li> <li class="nav-global-tech"><a href="https://www.mozilla.org/firefox/products/?utm_source=blog.mozilla.org&utm_medium=referral&utm_campaign=blog-nav" rel="external">Products</a></li> <li class="nav-global-donate"><a href="https://donate.mozilla.org/?presets=50,30,20,10&amount=30&currency=usd&utm_source=blog.mozilla.org&utm_medium=referral&utm_campaign=blog-nav" rel="external">Give</a></li> <li class="nav-global-firefox"><a href="https://www.mozilla.org/firefox/?utm_source=blog.mozilla.org&utm_medium=referral&utm_campaign=blog-nav" rel="external">Discover Firefox</a></li> </ul> </div> </div> </nav> <header id="masthead" class="section"> <div class="site-id"> <div class="site-title-wrap content"> <a href="https://blog.mozilla.org/netpolicy/" rel="home" title="Go to the front page"> <h4 id="site-title"><span>Open Policy & Advocacy</span></h4> <p id="site-description"><span>Mozilla's official blog on open Internet policy initiatives and developments</span></p> </a> </div> </div> </header> <div class="site-wrap"> <nav id="nav-util" class="can-stick has-sidebar has-categories"> <ul class="content"> <li class="nav-util-sidebar"><a href="#sidebar" aria-controls="sidebar" id="toggle-sidebar">Explore</a></li> <li class="nav-util-categories"><a href="#categories" aria-controls="categories" id="toggle-categories">Categories</a></li> <li class="nav-util-search"> <form id="search" class="fm-search" method="get" action="https://blog.mozilla.org/netpolicy/"> <fieldset> <p> <label for="s">Search this site</label> <input type="search" value="" name="s" id="s"> <button type="submit" class="button button-minor">Search</button> </p> </fieldset> </form> </li> </ul> </nav> <main id="content"> <div class="content"> <article id="post-1845" class="post post-1845 type-post status-publish format-standard hentry category-cybersecurity category-europe category-identity category-openness tag-security tag-user-experience"> <header class="entry-header"> <div class="entry-tools"> <div class="categories"> <b>Categories:</b> <a href="https://blog.mozilla.org/netpolicy/category/cybersecurity/" rel="category tag">Cybersecurity</a> <a href="https://blog.mozilla.org/netpolicy/category/europe/" rel="category tag">Europe</a> <a href="https://blog.mozilla.org/netpolicy/category/identity/" rel="category tag">Identity</a> <a href="https://blog.mozilla.org/netpolicy/category/openness/" rel="category tag">Openness</a> </div> <div class="social-share"> <b>Share:</b> <ul> <li><a rel="external nofollow noopener" target="_blank" class="twitter" data-network="Twitter" data-blog="Open Policy & Advocacy" href="https://twitter.com/intent/tweet/?text=The+EU%E2%80%99s+Current+Approach+to+QWACs+%28Qualified+Website+Authentication+Certificates%29+will+Undermine+Security+on+the+Open+Web&url=https%3A%2F%2Fblog.mozilla.org%2Fnetpolicy%2F2020%2F10%2F08%2Fthe-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web%2F&via=mozilla&utm_source=twitter&utm_medium=social&utm_campaign=shares_from_blog">Twitter</a></li> </ul> </div> </div> <h1 class="entry-title"> The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web </h1> <div class="entry-info"> <address class="vcard"> Udbhav Tiwari and Ben Wilson </address> <time class="date published" datetime="2020-10-08T05:42:24-08:00">October 8, 2020</time> </div> </header> <div class="entry-content"> <p><span style="font-weight: 400;">Since its founding in 1998, Mozilla has championed human-rights-compliant innovation as well as choice, control, and privacy for people on the Internet. We have worked hard to actualise this belief for the billions of users on the Web by actively leading and participating in the creation of Web standards that drive the Internet. We recently submitted our thoughts to the European Commission on its survey and public consultation regarding the </span><a href="https://ec.europa.eu/digital-single-market/en/discover-eidas"><span style="font-weight: 400;">eIDAS regulation</span></a><span style="font-weight: 400;">, advocating for an interpretation of eIDAS that is better for user security and retains innovation and interoperability of the global Internet. </span></p> <p><span style="font-weight: 400;">Given our background in the creation of the Transport Layer Security (TLS) standard for website security, we believe that mandating an interpretation of eIDAS that requires Qualified Website Authentication Certificates (</span><a href="https://ec.europa.eu/futurium/en/blog/commission-runs-pilot-project-qualified-web-authentication-certificates-qwacs"><span style="font-weight: 400;">QWACs</span></a><span style="font-weight: 400;">) to be bound with TLS certificates is deeply concerning. Along with weakening user security, it will cause serious harm to the single European digital market and its place within the global internet. </span></p> <p><span style="font-weight: 400;">Some high-level reasons for this position, as elucidated in our </span><a href="https://blog.mozilla.org/netpolicy/files/2020/10/2020-10-01-eIDAS-Open-Public-Consultation-EU-Commission-.pdf"><span style="font-weight: 400;">multiple</span></a><span style="font-weight: 400;"> recent </span><a href="https://blog.mozilla.org/netpolicy/files/2020/09/Mozilla-Attachment-to-the-European-Commission-Review-of-eIDAS.pdf"><span style="font-weight: 400;">submissions</span></a><span style="font-weight: 400;"> to the European Commission survey, are:</span></p> <ol> <li style="font-weight: 400;"><b>It violates the eIDAS Requirements: </b><span style="font-weight: 400;">The cryptographic binding of a QWAC to a connection or TLS certificate will </span><b>violate several provisions of the eIDAS regulation,</b><span style="font-weight: 400;"> including Recital 67 (website authentication), Recital 27 (technological neutrality), and Recital 72 (interoperability). The move to cryptographically bind a QWAC to a connection or TLS certificate will negate this wise consideration and go against the legislative intent of the Council.</span></li> <li style="font-weight: 400;"><b>It will undermine technical neutrality and interoperability: </b><span style="font-weight: 400;">Mandating TLS binding with QWACs will hinder </span><b>technological neutrality and interoperability</b><span style="font-weight: 400;">, as it will go against established best practices which have successfully helped keep the Web secure for the past two decades. Apart from being central to the goals of the eIDAS regulation itself, technological neutrality and interoperability are the pillars upon which innovation and competition take place on the web. Limiting them will severely hinder the ability of the EU digital single market to remain competitive within the global economy in a safe and secure manner.</span></li> <li style="font-weight: 400;"><b>It will undermine privacy for end users:</b><span style="font-weight: 400;"> Validating QWACs, as currently envisaged by ETSI, poses serious privacy risks</span> <span style="font-weight: 400;">to end users. In particular, the proposal uses validation procedures or protocols that would reveal a user’s browsing activity to a third-party validation service. This third party service would be in a position to track and profile users based on this information. Even if this were to be limited by policy, this information is largely indistinguishable from a privacy-problematic tracking technique known as “link decoration”.</span></li> <li style="font-weight: 400;"><b>It will create dangerous security risks for the Web: </b><span style="font-weight: 400;">It has been repeatedly suggested that Trust Service Providers (TSPs) who issue QWACs under the eIDAS regulation automatically be included in the root certificate authority (CA) stores of all browsers. Such a move will amount to forced website certificate whitelisting by government dictate and will </span><b>irremediably harm users’ safety and security. </b><span style="font-weight: 400;">It goes against established best practices of website authentication that have been created by consensus from the varied experiences of the Internet’s explosive growth. The technical and policy requirements for a TSP to be included in the root CA store of Mozilla Firefox, for example, compare much more favourably than the framework created by the eIDAS for TSPs. They are more transparent, have more stringent audit requirements and provide for improved public oversight as compared to what eIDAS requires of TSPs.</span></li> </ol> <p><span style="font-weight: 400;">As stated in our </span><a href="https://www.mozilla.org/en-US/about/manifesto/"><span style="font-weight: 400;">Manifesto</span></a><span style="font-weight: 400;"> and our </span><a href="https://blog.mozilla.org/netpolicy/files/2020/01/Mozilla-Digital-ID-White-Paper.pdf"><span style="font-weight: 400;">white paper</span></a><span style="font-weight: 400;"> on bringing openness to digital identity, we believe individuals’ security and privacy on the Internet are fundamental and must not be treated as optional. The eIDAS regulation (even if inadvertently) using TLS certificates, enabling tracking, and requiring a de-facto whitelisting of TLS certificate issuers on the direction of government agencies is fundamentally incompatible with this vision of a secure and open Internet. We look forward to working with the Commission to achieve the objectives of eIDAS without harming the Open Web.</span></p> </div> <footer class="entry-tags"> <p><b>Tags:</b> <a href="https://blog.mozilla.org/netpolicy/tag/security/" rel="tag">Security</a>, <a href="https://blog.mozilla.org/netpolicy/tag/user-experience/" rel="tag">User Experience</a></p> </footer> </article><!-- #post --> </div> <nav id="adjacent-posts" class="section nav-paging"> <div class="content"> <p class="nav-paging-prev" role="navigation"> <a href="https://blog.mozilla.org/netpolicy/2020/10/04/open-letter-to-south-koreas-ict-minister-mr-ki-young-choe-ensure-the-tba-amendments-dont-harm-the-open-internet-in-south-korea/"> <span class="label">Previous article</span> <strong class="entry-title">Open Letter to South Korea's ICT Minister, Mr. Ki-Young Choe: Ensure the TBA amendments don’t harm the open internet in South Korea</strong> <time class="date" datetime="2020-10-04T19:18:13-08:00">October 4, 2020</time> <svg class="arrow-left" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 23.62 43"><defs><style>.cls-1{fill:none;stroke:#000;stroke-linecap:round;stroke-miterlimit:10;stroke-width:3px;}</style></defs><polyline class="cls-1" points="22.12 1.5 2.12 21.5 22.12 41.5"/></svg> </a> </p> <p class="nav-paging-next" role="navigation"> <a href="https://blog.mozilla.org/netpolicy/2020/10/19/mozilla-mornings-on-addressing-online-harms-through-advertising-transparency/"> <span class="label">Next article</span> <strong class="entry-title">Mozilla Mornings on addressing online harms through advertising transparency</strong> <time class="date" datetime="2020-10-19T07:52:34-08:00">October 19, 2020</time> <svg class="arrow-right" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 23.62 43"><defs><style>.cls-1{fill:none;stroke:#000;stroke-linecap:round;stroke-miterlimit:10;stroke-width:3px;}</style></defs><polyline class="cls-1" points="1.5 1.5 21.5 21.5 1.5 41.5"/></svg> </a> </p> </div> </nav> <aside id="related-posts" class="section"> <div class="content"> <div class="in-category"> <h4 class="module-title">More articles in “Cybersecurity”</h4> <ul class="cat-posts"> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2023/07/13/european-parliaments-version-of-the-cra-threatens-cybersecurity-and-open-source-development/">European Parliament’s version of the CRA threatens cybersecurity and open source development</a></h5> <time class="date" datetime="2023-07-13T21:50:24-08:00">July 13, 2023</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2023/05/15/mozilla-weighs-in-on-the-eu-cyber-resilience-act/">Mozilla weighs in on the EU Cyber Resilience Act</a></h5> <time class="date" datetime="2023-05-15T07:21:12-08:00">May 15, 2023</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2022/05/31/enhancing-trust-and-security-on-the-internet-browsers-are-the-first-line-of-defence/">Enhancing trust and security on the internet – browsers are the first line of defence</a></h5> <time class="date" datetime="2022-05-31T23:45:44-08:00">May 31, 2022</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2021/06/10/working-in-the-open-enhancing-privacy-and-security-in-the-dns/">Working in the open: Enhancing privacy and security in the DNS</a></h5> <time class="date" datetime="2021-06-10T05:00:45-08:00">June 10, 2021</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2021/06/04/the-van-buren-decision-is-a-strong-step-forward-for-public-interest-research-online/">The Van Buren decision is a strong step forward for public interest research online</a></h5> <time class="date" datetime="2021-06-04T13:30:52-08:00">June 4, 2021</time> </li> </ul> </div> <div class="popular"> <h4 class="module-title">Recent articles</h4> <ul class="recent-posts"> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2024/11/21/mozilla-responds-to-does-rfi-on-the-frontiers-in-ai-for-science-security-and-technology-fasst/">Mozilla Responds to DOE’s RFI on the Frontiers in AI for Science, Security, and Technology (FASST)</a></h5> <time class="date" datetime="2024-11-21T06:09:08-08:00">November 21, 2024</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2024/11/07/join-us-to-mark-20-years-of-firefox/">Join Us to Mark 20 Years of Firefox</a></h5> <time class="date" datetime="2024-11-07T06:13:08-08:00">November 7, 2024</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2024/11/07/behind-the-scenes-of-eidas-a-look-at-article-45-and-its-implications/">Behind the Scenes of eIDAS: A Look at Article 45 and Its Implications</a></h5> <time class="date" datetime="2024-11-07T02:43:18-08:00">November 7, 2024</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2024/10/23/mozilla-participates-to-ofcoms-draft-transparency-reporting-guidance/">Mozilla Participates to Ofcom’s Draft Transparency Reporting Guidance</a></h5> <time class="date" datetime="2024-10-23T08:09:33-08:00">October 23, 2024</time> </li> <li> <h5 class="entry-title"><a href="https://blog.mozilla.org/netpolicy/2024/10/21/mozilla-responds-to-bis-proposed-rule-on-reporting-requirements-for-the-development-of-advanced-ai-models-and-computing-clusters/">Mozilla Responds to BIS’ Proposed Rule on Reporting Requirements for the Development of Advanced AI Models and Computing Clusters</a></h5> <time class="date" datetime="2024-10-21T05:00:07-08:00">October 21, 2024</time> </li> </ul> </div> </div> </aside> <aside id="newsletter-subscribe" class="section"> <form id="newsletter_form" class="content newsletter_form" name="newsletter_form" action="https://www.mozilla.org/en-US/newsletter/" method="post" data-blog="Open Policy & Advocacy"> <input type="hidden" id="newsletters" name="newsletters" value="mozilla-foundation"> <input type="hidden" id="source_url" name="source_url" value="https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web"> <div class="form-title"> <h3>Love the Web?</h3> <h4>Get the Mozilla newsletter and help us keep it open and free.</h4> </div> <div id="form-contents" class="form-contents"> <div id="newsletter_errors" class="newsletter_errors"></div> <div class="field field-email"> <label for="email">Your e-mail address</label> <input type="email" id="email" name="email" required placeholder="yourname@example.com" size="30"> </div> <div class="form-details"> <div class="field field-language"> <label for="lang">Language</label> <select id="lang" name="lang" required="required"> <option value="de">Deutsch</option> <option value="en" selected="selected">English</option> <option value="es">Español</option> <option value="fr">Français</option> <option value="pl">Polski</option> </select> </div> <div class="field field-format"> <label for="format-h"><input checked="checked" id="format-h" name="fmt" value="H" type="radio"> HTML</label> <label for="format-t"><input id="format-t" name="fmt" value="T" type="radio"> Text</label> </div> <div class="field field-privacy"> <label for="privacy"> <input type="checkbox" id="privacy" name="privacy" required> I’m okay with Mozilla handling my info as explained in this <a href="https://www.mozilla.org/privacy/">Privacy Policy</a>. </label> </div> </div> <div class="form-submit"> <button id="newsletter_submit" type="submit" class="form-button button-dark">Sign up now</button> <p class="form-details promise"> <small>We will only send you Mozilla-related information.</small> </p> </div> </div> <div id="newsletter_thanks" class="thanks"> <h2>Thanks!</h2> <p> If you haven’t previously confirmed a subscription to a Mozilla-related newsletter you may have to do so. Please check your inbox or your spam filter for an e-mail from us. </p> </div> </form> </aside> </main> <aside id="sidebar" class="section widgets can-stick"> <div class="content"> <aside id="nav_menu-2" class="widget widget_nav_menu"><h3 class="widget-title">More Mozilla Blogs</h3><div class="menu-more-mozilla-blogs-container"><ul id="menu-more-mozilla-blogs" class="menu"><li id="menu-item-1107" class="menu-item menu-item-type-custom menu-item-object-custom menu-item-1107"><a href="https://blog.mozilla.org/">The Mozilla Blog</a></li> <li id="menu-item-1198" class="menu-item menu-item-type-custom menu-item-object-custom menu-item-1198"><a href="https://blog.mozilla.org/firefox/">The Firefox Frontier</a></li> <li id="menu-item-1110" class="menu-item menu-item-type-custom menu-item-object-custom menu-item-1110"><a href="https://blog.mozilla.org/internetcitizen/">Internet Citizen</a></li> <li id="menu-item-1109" class="menu-item menu-item-type-custom menu-item-object-custom menu-item-1109"><a href="https://blog.mozilla.org/community/">about:community</a></li> <li id="menu-item-1111" class="menu-item menu-item-type-custom menu-item-object-custom menu-item-1111"><a href="https://hacks.mozilla.org">Mozilla Hacks</a></li> </ul></div></aside> </div> </aside> <aside id="categories" class="can-stick"> <div class="content"> <h3 class="module-title">More articles</h3> <ul class="cat-list" role="navigation"> <li><a href="#cat-privacy">privacy</a></li> <li><a href="#cat-uncategorized">Uncategorized</a></li> <li><a href="#cat-trust">Trust</a></li> <li><a href="#cat-security">Security</a></li> <li><a href="#cat-europe">Europe</a></li> <li><a href="#cat-transparency">Transparency</a></li> <li><a href="#cat-data-protection">Data protection</a></li> <li><a href="#cat-cybersecurity">Cybersecurity</a></li> </ul> <div class="categories"> <div class="category" id="cat-privacy"> <h4 class="category-title">privacy</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/10/10/how-lawmakers-can-help-people-take-control-of-their-privacy/"> <img class="post-image image-fallback color-3" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-3.png"> <h5 class="entry-title">How Lawmakers Can Help People Take Control of Their Privacy</h5> </a> <time class="date" datetime="2024-10-10T06:23:56-08:00">October 10, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/04/26/work-gets-underway-on-a-new-federal-privacy-proposal/"> <img class="post-image image-fallback color-3" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-3.png"> <h5 class="entry-title">Work Gets Underway on a New Federal Privacy Proposal</h5> </a> <time class="date" datetime="2024-04-26T11:48:55-08:00">April 26, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/01/11/mozilla-weighs-in-on-state-comprehensive-privacy-proposals/"> <img class="post-image image-fallback color-3" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-3.png"> <h5 class="entry-title">Mozilla Weighs in on State Comprehensive Privacy Proposals</h5> </a> <time class="date" datetime="2024-01-11T11:23:35-08:00">January 11, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/12/22/mozillas-comments-to-fcc-net-neutrality-essential-for-competition-innovation-privacy/"> <img class="post-image image-fallback color-4" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-4.png"> <h5 class="entry-title">Mozilla’s Comments to FCC: Net Neutrality Essential for Competition, Innovation, Privacy</h5> </a> <time class="date" datetime="2023-12-22T06:44:29-08:00">December 22, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/11/21/global-privacy-control-empowers-individuals-to-limit-privacy-invasive-tracking/"> <img class="post-image image-fallback color-6" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-6.png"> <h5 class="entry-title">Global Privacy Control Empowers Individuals to Limit Privacy-Invasive Tracking</h5> </a> <time class="date" datetime="2023-11-21T07:16:32-08:00">November 21, 2023</time> </div> </li> </ul> </div> <div class="category" id="cat-uncategorized"> <h4 class="category-title">Uncategorized</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/11/21/mozilla-responds-to-does-rfi-on-the-frontiers-in-ai-for-science-security-and-technology-fasst/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Mozilla Responds to DOE’s RFI on the Frontiers in AI for Science, Security, and Technology (FASST)</h5> </a> <time class="date" datetime="2024-11-21T06:09:08-08:00">November 21, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/11/07/join-us-to-mark-20-years-of-firefox/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2024/11/Fx_20-Year_Lockup_Full-Color_Light@1x-300x165.png"> <h5 class="entry-title">Join Us to Mark 20 Years of Firefox</h5> </a> <time class="date" datetime="2024-11-07T06:13:08-08:00">November 7, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/11/07/behind-the-scenes-of-eidas-a-look-at-article-45-and-its-implications/"> <img class="post-image image-fallback color-2" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-2.png"> <h5 class="entry-title">Behind the Scenes of eIDAS: A Look at Article 45 and Its Implications</h5> </a> <time class="date" datetime="2024-11-07T02:43:18-08:00">November 7, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/08/19/mozilla-eleutherai-and-hugging-face-provide-comments-on-californias-sb-1047/"> <img class="post-image image-fallback color-2" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-2.png"> <h5 class="entry-title">Mozilla, EleutherAI, and Hugging Face Provide Comments on California’s SB 1047</h5> </a> <time class="date" datetime="2024-08-19T04:40:40-08:00">August 19, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/03/05/mozilla-mornings-choice-or-illusion-tackling-harmful-design-practices/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2024/03/Mozilla-Morning-Mailchimp-300x165.png"> <h5 class="entry-title">Mozilla Mornings: Choice or Illusion? Tackling Harmful Design Practices</h5> </a> <time class="date" datetime="2024-03-05T12:00:19-08:00">March 5, 2024</time> </div> </li> </ul> </div> <div class="category" id="cat-trust"> <h4 class="category-title">Trust</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2020/12/18/kazakhstan-root-2020/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Continuing to Protect our Users in Kazakhstan</h5> </a> <time class="date" datetime="2020-12-18T00:01:24-08:00">December 18, 2020</time> </div> </li> </ul> </div> <div class="category" id="cat-security"> <h4 class="category-title">Security</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2020/12/18/kazakhstan-root-2020/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Continuing to Protect our Users in Kazakhstan</h5> </a> <time class="date" datetime="2020-12-18T00:01:24-08:00">December 18, 2020</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2018/02/02/its-time-for-the-first-g20-digital-agenda/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2018/02/2048px-Congress_Plaza_Buenos_Aires_at_Sunset-300x165.jpg"> <h5 class="entry-title">It’s time for the G20’s first digital agenda</h5> </a> <time class="date" datetime="2018-02-02T06:00:49-08:00">February 2, 2018</time> </div> </li> </ul> </div> <div class="category" id="cat-europe"> <h4 class="category-title">Europe</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/04/08/mozilla-provides-feedback-to-acms-dsa-guidelines/"> <img class="post-image image-fallback color-6" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-6.png"> <h5 class="entry-title">Mozilla provides feedback to ACM’s DSA Guidelines</h5> </a> <time class="date" datetime="2024-04-08T05:14:00-08:00">April 8, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/10/26/global-network-fee-proposals-are-troubling-here-are-three-paths-forward/"> <img class="post-image image-fallback color-6" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-6.png"> <h5 class="entry-title">Global Network Fee Proposals are Troubling. Here are Three Paths Forward.</h5> </a> <time class="date" datetime="2023-10-26T23:00:37-08:00">October 26, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2020/10/19/mozilla-mornings-on-addressing-online-harms-through-advertising-transparency/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2020/10/Social-Media1-300x165.jpg"> <h5 class="entry-title">Mozilla Mornings on addressing online harms through advertising transparency</h5> </a> <time class="date" datetime="2020-10-19T07:52:34-08:00">October 19, 2020</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2020/10/08/the-eus-current-approach-to-qwacs-qualified-website-authentication-certificates-will-undermine-security-on-the-open-web/"> <img class="post-image image-fallback color-1" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-1.png"> <h5 class="entry-title">The EU’s Current Approach to QWACs (Qualified Website Authentication Certificates) will Undermine Security on the Open Web</h5> </a> <time class="date" datetime="2020-10-08T05:42:24-08:00">October 8, 2020</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2020/09/17/mozilla-files-comments-with-the-european-commission-on-safeguarding-democracy-in-the-digital-age/"> <img class="post-image image-fallback color-6" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-6.png"> <h5 class="entry-title">Mozilla files comments with the European Commission on safeguarding democracy in the digital age</h5> </a> <time class="date" datetime="2020-09-17T00:45:12-08:00">September 17, 2020</time> </div> </li> </ul> </div> <div class="category" id="cat-transparency"> <h4 class="category-title">Transparency</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2024/10/23/mozilla-participates-to-ofcoms-draft-transparency-reporting-guidance/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Mozilla Participates to Ofcom’s Draft Transparency Reporting Guidance</h5> </a> <time class="date" datetime="2024-10-23T08:09:33-08:00">October 23, 2024</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/08/18/mozilla-applauds-cfpb-for-taking-on-the-data-broker-ecosystem/"> <img class="post-image image-fallback color-1" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-1.png"> <h5 class="entry-title">Mozilla applauds CFPB for taking on the Data Broker Ecosystem</h5> </a> <time class="date" datetime="2023-08-18T08:32:03-08:00">August 18, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/06/09/mozilla-weighs-in-on-accountability-legislation-public-policies-like-pata-can-help-to-keep-the-internet-in-the-publics-best-interest/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Mozilla Weighs in on Accountability Legislation: Public policies like PATA can help to keep the Internet in the public’s best interest.</h5> </a> <time class="date" datetime="2023-06-09T09:28:32-08:00">June 9, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/03/28/open-fibre-data-standard-understanding-the-true-extent-of-the-internet/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2023/03/African_Cables_3-300x165.jpg"> <h5 class="entry-title">Open Fibre Data Standard: Understanding the True Extent of the Internet</h5> </a> <time class="date" datetime="2023-03-28T13:25:06-08:00">March 28, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2022/05/26/mozilla-meetups-the-building-blocks-of-a-trusted-internet/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2022/05/MM-social-graphic-5-300x165.png"> <h5 class="entry-title">Mozilla Meetups: The Building Blocks of a Trusted Internet</h5> </a> <time class="date" datetime="2022-05-26T13:49:01-08:00">May 26, 2022</time> </div> </li> </ul> </div> <div class="category" id="cat-data-protection"> <h4 class="category-title">Data protection</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2021/11/11/mozilla-submits-comments-to-the-california-privacy-protection-agency/"> <img class="post-image image-fallback color-5" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-5.png"> <h5 class="entry-title">Mozilla submits comments to the California Privacy Protection Agency</h5> </a> <time class="date" datetime="2021-11-11T06:07:25-08:00">November 11, 2021</time> </div> </li> </ul> </div> <div class="category" id="cat-cybersecurity"> <h4 class="category-title">Cybersecurity</h4> <ul class="category-posts"> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/07/13/european-parliaments-version-of-the-cra-threatens-cybersecurity-and-open-source-development/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2019/12/privacy-image-300x165.png"> <h5 class="entry-title">European Parliament’s version of the CRA threatens cybersecurity and open source development</h5> </a> <time class="date" datetime="2023-07-13T21:50:24-08:00">July 13, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2023/05/15/mozilla-weighs-in-on-the-eu-cyber-resilience-act/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2019/12/privacy-image-300x165.png"> <h5 class="entry-title">Mozilla weighs in on the EU Cyber Resilience Act</h5> </a> <time class="date" datetime="2023-05-15T07:21:12-08:00">May 15, 2023</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2022/05/31/enhancing-trust-and-security-on-the-internet-browsers-are-the-first-line-of-defence/"> <img class="post-image" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/files/2022/05/HTTPS_and_padlock_in_website_address_bar-300x165.jpg"> <h5 class="entry-title">Enhancing trust and security on the internet – browsers are the first line of defence</h5> </a> <time class="date" datetime="2022-05-31T23:45:44-08:00">May 31, 2022</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2021/06/10/working-in-the-open-enhancing-privacy-and-security-in-the-dns/"> <img class="post-image image-fallback color-3" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-3.png"> <h5 class="entry-title">Working in the open: Enhancing privacy and security in the DNS</h5> </a> <time class="date" datetime="2021-06-10T05:00:45-08:00">June 10, 2021</time> </div> </li> <li class="category-post"> <div class="post-mini"> <a class="entry-link" href="https://blog.mozilla.org/netpolicy/2021/06/04/the-van-buren-decision-is-a-strong-step-forward-for-public-interest-research-online/"> <img class="post-image image-fallback color-4" width="300" height="165" alt="" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/place-thumb.png" data-src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/img/fallbacks/pattern-4.png"> <h5 class="entry-title">The Van Buren decision is a strong step forward for public interest research online</h5> </a> <time class="date" datetime="2021-06-04T13:30:52-08:00">June 4, 2021</time> </div> </li> </ul> </div> </div> </div> </aside> </div><!-- /.site-wrap --> <footer id="site-info" class="section"> <div class="content"> <nav class="primary"> <div class="logo"> <a href="https://www.mozilla.org/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Mozilla">Mozilla</a> </div> <section class="mozilla"> <h5><a href="https://www.mozilla.org/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Mozilla">Mozilla</a></h5> <ul class="mozilla-links"> <li><a href="https://www.mozilla.org/about/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="About">About</a></li> <li><a href="https://www.mozilla.org/contact/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Contact Us">Contact Us</a></li> <li><a href="https://donate.mozilla.org/?presets=50,30,20,10&amount=30&currency=usd&utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" class="donate" data-link-type="footer" data-link-name="Donate">Donate</a></li> <li> <ul class="social-links"> <li><a class="twitter" href="https://twitter.com/mozilla" data-link-type="footer" data-link-name="Twitter (@mozilla)">Twitter<span> (@mozilla)</span></a></li> <li><a class="instagram" href="https://www.instagram.com/mozillagram/" data-link-type="footer" data-link-name="Instagram (@mozillagram)">Instagram<span> (@mozillagram)</span></a></li> </ul> </li> </ul> </section> <section class="firefox"> <h5><a href="https://www.mozilla.org/firefox/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Mozilla">Firefox</a></h5> <ul class="firefox-links"> <li><a href="https://www.mozilla.org/firefox/new/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Download Firefox">Download Firefox</a></li> <li><a href="https://www.mozilla.org/firefox/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Desktop">Desktop</a></li> <li><a href="https://www.mozilla.org/firefox/mobile/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Mobile">Mobile</a></li> <li><a href="https://www.mozilla.org/firefox/features/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Features">Features</a></li> <li><a href="https://www.mozilla.org/firefox/channel/desktop/?utm_source=blog.mozilla.org&utm_campaign=footer&utm_medium=referral" data-link-type="footer" data-link-name="Beta, Nightly, Developer Edition">Beta, Nightly, Developer Edition</a></li> <li> <ul class="social-links"> <li><a class="twitter" href="https://twitter.com/firefox" data-link-type="footer" data-link-name="Twitter (@firefox)">Twitter<span> (@firefox)</span></a></li> <li><a class="youtube" href="https://www.youtube.com/firefoxchannel" data-link-type="footer" data-link-name="YouTube (firefoxchannel)">YouTube<span> (firefoxchannel)</span></a></li> </ul> </li> </ul> </section> </nav> <nav class="secondary"> <div class="small-links"> <ul> <li><a rel="nofollow" href="https://www.mozilla.org/privacy/" data-link-type="footer" data-link-name="Privacy">Website Privacy Notice</a></li> <li><a rel="nofollow" href="https://www.mozilla.org/privacy/websites/#cookies" data-link-type="footer" data-link-name="Cookies">Cookies</a></li> <li><a rel="nofollow" href="https://www.mozilla.org/about/legal/" data-link-type="footer" data-link-name="Legal">Legal</a></li> </ul> <p class="license"> Visit Mozilla Corporation’s not-for-profit parent, the <a href="https://foundation.mozilla.org" data-link-type="footer" data-link-name="Mozilla Foundation">Mozilla Foundation</a>. </p> <p class="license"> Portions of this content are ©1998-2024 by individual contributors. Content available under a <a href="https://www.mozilla.org/foundation/licensing/website-content/" rel="external license">Creative Commons license</a>. </p> </div> </nav> </div> </footer> <!--[if IE 9]> <script type="text/javascript" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/js/matchMedia.js"></script> <script type="text/javascript" src="https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/js/matchMedia.addListener.js"></scrip> <![endif]--> <script type='text/javascript' src='https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/js/global.js?ver=2.2' id='global-js'></script> <script type='text/javascript' src='https://blog.mozilla.org/netpolicy/wp-content/themes/frontierline/js/basket-client.js?ver=1.2' id='basket-client-js'></script> </body> </html>