Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

21–30 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#21
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

At least in UK the app will generate a new certificate on the fly.

So it also automatically resigns the forged certs, or how does it tell the difference?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#22

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

While I'm having great fun with my galaxy Fold, waving my huge QR code at the clubs all the way from the back of the line.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#23
post #18

Earlier quoted context omitted.

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

well, print it again then.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#24
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

As opposed to private entities that are known to be able to keep keys secret all the time?

They didn’t suggest that at all.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#25
post #14
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

What prevents you from backdating a forged certificate then?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#26

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

I had it verified constantly, both in airports and (on a trip to Italy) on pretty much every restaurant or bar I went to. I think it was only once that they were fine with showing it, all the others had scanners.

I don’t go out a lot, but I’ve had no verification in 2 restaurants and one bar so far. Just a check that it’s scrollable in one case, otherwise just that the name sounds like it could be mine. No scanning of the QR code, no ID check.

And I’m not even using the official app for Germany, but the "Corona Tracing" fork.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#27
post #18

Earlier quoted context omitted.

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

Similar here. I use the app since it doesn't do anything invasive, but I also have a paper backup (I don't always carry it) because it's a bit too important to be dependent on a phone only. I bet I'd first find out about my certificate being revoked at some check point where my phone isn't working and I can't easily get a new one...

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#28
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

At least in UK the app will generate a new certificate on the fly.

Don't know for covid passport (since it is not enforced in the UK), but for travel certificates I believe the QR code has a validity of 3 months.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#29
post #14

Earlier quoted context omitted.

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

Please don't belittle people for not knowing things like this, it's entirely rude and unnecessary. See https://xkcd.com/1053/

It is also wrong for one other funny reason. I have been a security officer for a credit card acquiring business and have been designing cryptographic infrastructure for credit card payment systems. I have also implemented a complete credit card terminal application with magstripe, chip&pin and contactless. I know (or at least known at some point in time) pretty much everything practical there is to know about certificates and I have even been able to parse TLV of X.509 by looking at the hex dump of it.

So that was pretty poor shot at me.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#30
Does it have to be the keys that are leaked? There should be hundreds of healthcare workers who have access to the covid certificate system.

I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.

Post reply on HN