Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

31–40 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#31
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

78 governments have ICAO private keys, and most have done so for >10 years now. If what "we all know" is true, then you should be able to find a leaked key easily. Try googling.

Or you might fall back to claiming that while governments evidently can hold on to ICAO private keys, they can't hold on to this other kind of private key, because...

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#33
post #25
post #14

Earlier quoted context omitted.

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

What prevents you from backdating a forged certificate then?

I'm not aware of how the COVID certs work, but the way that's solved in TLS certificates (used for https) is that when signing, you have to use an approved timestamping authority. A timestamping authority will basically say "Yes, this action was taken at exactly this time". See [0].

[0]: https://en.wikipedia.org/wiki/Trusted_timestamping

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#34
post #18

Earlier quoted context omitted.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

well, print it again then.

I know this, but a lot of people may not know because they don't care to read HN. Then they try to board a plane and get rejected.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#35
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

As opposed to private entities that are known to be able to keep keys secret all the time?

Don't know if this is whst the OP has in mind, but the first thing that comes to my mind is the backdoor that many states want to impose on all encrypted communications. That would create a single point of attack, so even assuming competence, it makes the system significantly weaker. And this episode if confirmed makes competence a strong assumption.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#36
post #9

Earlier quoted context omitted.

But did you have to show an ID or could you just show a John Doe certificate?

In the case of airports, ID was needed. For restaurants I guess I could have shown any valid QR.

Same here. Only when entering a non-EU country after flying there, they checked with a scanner. Nowhere else. Not that I do a lot of risky activities at the moment, though, so perhaps I've just gotten unlucky with the places where it should have been checked.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#37
post #14
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

Not only is that comment arrogant, spiteful but it is also not necessarily correct.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#40
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

> Did literally anyone not see this coming?

The system's designers did, which is why key revocation is built into the system. The practical effects of this leak will be the people who refused the app and don't read the news will be surprised when their paper certificates are rejected.

Post reply on HN