Earlier quoted context omitted.
At least in UK the app will generate a new certificate on the fly.
I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.
Private keys used to sign EU Digital Covid Certificate might have been leaked
41–50 of 214 posts
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#42Earlier quoted context omitted.
At least in UK the app will generate a new certificate on the fly.
I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.
Just out of curiosity, is that for privacy reasons or ? Seems rather strange for a smartphone ?
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#43Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#44Certificates in Sweden are valid for 3 months. So, if it's the same for Italy then it's not good but not catastrophic either.
Apparently the leaked keys have already been blacklisted. So all certificates signed with the leaked keys will need to be reissued. FWIW, it wasn't the Italian key that was leaked.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#45Earlier quoted context omitted.
I had it verified constantly, both in airports and (on a trip to Italy) on pretty much every restaurant or bar I went to. I think it was only once that they were fine with showing it, all the others had scanners.
But did you have to show an ID or could you just show a John Doe certificate?
Some places have no checks at all; other places you need to show one of {show the QR code, use the Luca contact tracking site, fill out a paper form}; at least one needs the QR code and a valid ID card (not sure what, but excluding the health insurance cards despite those being photo ID).
They didn’t scan the QR codes in the places I’ve been to, they just looked at them. This isn’t the first time I’ve seen cargo-cult attitudes to how the content of mobile or tablet screens relates to security.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#46Earlier quoted context omitted.
At least in UK the app will generate a new certificate on the fly.
I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#47Earlier quoted context omitted.
What about people who got legit certificates but now the key it used has been revoked?
It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#48Earlier quoted context omitted.
What about people who got legit certificates but now the key it used has been revoked?
At least in UK the app will generate a new certificate on the fly.
Since the French app is pretty terrible (it used to be the barely functional contact tracing app that didn't want to use Google/Apple's API, so there's a pretty strong popular stigma against it), even a sizeable portion of smartphone users use an alternative too (I personally have my QR code in Apple's Wallet, but there are other 3rd party solutions).
Depending on when that key was in use, this may be an epic bureaucratic mess to solve here in France if they have to reissue many.
Edit : I'll quickly add that while there's a database of vaccinated people handled by CNAM (the single payer social security administration), it doesn't seem extremely accurate : my best friend and one of his collegues were vaccinated, issued a QR code, but they weren't added to said database and had a terrible time getting the situation fixed. In the end, a pharmacist reissued a "vaccination" for them to "get them in the system". So that database is probably at best incomplete (for the process of reissuing).
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#49Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#50Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.