Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

11–20 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#12

Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...

What about people who got legit certificates but now the key it used has been revoked?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#13
post #12

Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...

What about people who got legit certificates but now the key it used has been revoked?

At least in UK the app will generate a new certificate on the fly.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#14
post #12

Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...

What about people who got legit certificates but now the key it used has been revoked?

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#15
post #7

Certificates in Sweden are valid for 3 months. So, if it's the same for Italy then it's not good but not catastrophic either.

Apparently the leaked keys have already been blacklisted. So all certificates signed with the leaked keys will need to be reissued. FWIW, it wasn't the Italian key that was leaked.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#16
post #8
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

Why the downvotes? For sure, this will just have us install (or have preinstalled) DRM-locked proprietary apps on our phones. Ugh.

Downvotes because governments regularly hold secrets for years, decades, sometimes centuries.

But yeah yeah, you can point to more than a few failures in the massive sample pool of “the government” so “government can’t hold keys.”

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#17
post #9

Earlier quoted context omitted.

I had it verified constantly, both in airports and (on a trip to Italy) on pretty much every restaurant or bar I went to. I think it was only once that they were fine with showing it, all the others had scanners.

But did you have to show an ID or could you just show a John Doe certificate?

In the case of airports, ID was needed. For restaurants I guess I could have shown any valid QR.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#18
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period.

The certificate I am using is printed on a piece of paper I carry with me.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#19
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

As opposed to private entities that are known to be able to keep keys secret all the time?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#20
post #14
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

Please don't belittle people for not knowing things like this, it's entirely rude and unnecessary. See https://xkcd.com/1053/
Post reply on HN