Earlier quoted context omitted.
What about people who got legit certificates but now the key it used has been revoked?
At least in UK the app will generate a new certificate on the fly.
Private keys used to sign EU Digital Covid Certificate might have been leaked
21–30 of 214 posts
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#22Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#23Earlier quoted context omitted.
At least in UK the app will generate a new certificate on the fly.
I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#24Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.
As opposed to private entities that are known to be able to keep keys secret all the time?
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#25Earlier quoted context omitted.
What about people who got legit certificates but now the key it used has been revoked?
It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#26Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.
I had it verified constantly, both in airports and (on a trip to Italy) on pretty much every restaurant or bar I went to. I think it was only once that they were fine with showing it, all the others had scanners.
And I’m not even using the official app for Germany, but the "Corona Tracing" fork.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#27Earlier quoted context omitted.
At least in UK the app will generate a new certificate on the fly.
I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#28Earlier quoted context omitted.
What about people who got legit certificates but now the key it used has been revoked?
At least in UK the app will generate a new certificate on the fly.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#29Earlier quoted context omitted.
It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.
Please don't belittle people for not knowing things like this, it's entirely rude and unnecessary. See https://xkcd.com/1053/
So that was pretty poor shot at me.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#30I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.