Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

41–50 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#41
post #18

Earlier quoted context omitted.

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

In general? Or just COVID apps?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#42
post #18

Earlier quoted context omitted.

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

> not installing any third party apps on my phone

Just out of curiosity, is that for privacy reasons or ? Seems rather strange for a smartphone ?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#43

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

My experience was very mixed with my (limited) travel I did this year. In Austria they just eyeball your certificate. In Italy everyone used an app to verify the qr code (although I've still only gotten my ID checked once).

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#44
post #7

Certificates in Sweden are valid for 3 months. So, if it's the same for Italy then it's not good but not catastrophic either.

Apparently the leaked keys have already been blacklisted. So all certificates signed with the leaked keys will need to be reissued. FWIW, it wasn't the Italian key that was leaked.

They seem to be quite thorough with checking QR certificates in Italy so it doesn't surprize me if this was discovered there.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#45
post #9

Earlier quoted context omitted.

I had it verified constantly, both in airports and (on a trip to Italy) on pretty much every restaurant or bar I went to. I think it was only once that they were fine with showing it, all the others had scanners.

But did you have to show an ID or could you just show a John Doe certificate?

In Berlin this is wildly variable.

Some places have no checks at all; other places you need to show one of {show the QR code, use the Luca contact tracking site, fill out a paper form}; at least one needs the QR code and a valid ID card (not sure what, but excluding the health insurance cards despite those being photo ID).

They didn’t scan the QR codes in the places I’ve been to, they just looked at them. This isn’t the first time I’ve seen cargo-cult attitudes to how the content of mobile or tablet screens relates to security.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#46
post #18

Earlier quoted context omitted.

At least in UK the app will generate a new certificate on the fly.

I am not using an app. I am not installing any third party apps on my phone, government or not, period. The certificate I am using is printed on a piece of paper I carry with me.

Can't you keep it in a jpeg file and show that?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#47
post #14
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

It doesn't matter because the key was used to sign before it got revoked. You should know this on a site like hackernews.

It matters to the people whose true certificate is now invalid, which is probably what the GP meant.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#48
post #12

Earlier quoted context omitted.

What about people who got legit certificates but now the key it used has been revoked?

At least in UK the app will generate a new certificate on the fly.

It's definitely a solution when you have an app (assuming you have a 3rd party source of identification of users), but since it's a French key, a sizeable portion of people, mostly elderly, are not using the "official" app but a paper printed QR code that was given to them at the time of the second injection (or a picture of said code).

Since the French app is pretty terrible (it used to be the barely functional contact tracing app that didn't want to use Google/Apple's API, so there's a pretty strong popular stigma against it), even a sizeable portion of smartphone users use an alternative too (I personally have my QR code in Apple's Wallet, but there are other 3rd party solutions).

Depending on when that key was in use, this may be an epic bureaucratic mess to solve here in France if they have to reissue many.

Edit : I'll quickly add that while there's a database of vaccinated people handled by CNAM (the single payer social security administration), it doesn't seem extremely accurate : my best friend and one of his collegues were vaccinated, issued a QR code, but they weren't added to said database and had a terrible time getting the situation fixed. In the end, a pharmacist reissued a "vaccination" for them to "get them in the system". So that database is probably at best incomplete (for the process of reissuing).

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#50

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

In Greece, the vast majority verifies certificates, with high-density venues like clubs asking for ID as well.
Post reply on HN