Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

81–90 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#81

Does it have to be the keys that are leaked? There should be hundreds of healthcare workers who have access to the covid certificate system. I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.

I think that's absolutely the most likely. And it's not hundreds, it's probably more like tens of thousands (or more). For example, when I got mine issued in Germany, I just went to a pharmacy, gave them my ID and (paper) vaccination record, and the pharmacist came back in a couple of minutes with my QR code.

The interesting thing to watch, over the coming days, is this: will the public policy response do the technically correct thing, and make sure that you need all your original documentation (signed records from the doctor's office, etc.) to get your new covpass issued? Or will they do something incorrect (but easy), like let people come in with their now-invalid pass plus a government ID to get a new one issued?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#82

Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...

Very unlikely that the key has been revoked. Instead probably that single certificate has been blocked in the Italian app.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#83

What will last longer, the pandemic or a poorly implemented digital identity platform?

These tyrants would love to hold on to these these digital “covid passports” because it gives them complete control over who can participate in society. They’d be able to exclude people who don’t comply with increasingly invasive protocols. It’s about power. The pandemic technically should already be considered endemic. For example in the USA the vast majority of the population has antibodies, in a significantly high…

> More than 80% of Americans have coronavirus antibodies acquired through infection or vaccination, according to a new study of over 1.4 million blood donations across the U.S. [0]

Just to add some additional detail: The article explains that 83% had antibodies as of May 2021, and that number should be expected to have increased based on additional vaccinations and delta wave infections. Their research will continue until December 2021.

I agree with you that the response of many governments to this does not appear to be following the science.

[0] https://www.miamiherald.com/news/coronavirus/article25398704...

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#84

What will last longer, the pandemic or a poorly implemented digital identity platform?

These tyrants would love to hold on to these these digital “covid passports” because it gives them complete control over who can participate in society. They’d be able to exclude people who don’t comply with increasingly invasive protocols. It’s about power. The pandemic technically should already be considered endemic. For example in the USA the vast majority of the population has antibodies, in a significantly high…

Actually getting COVID can cause permanent damage to the heart, lungs and blood vessels of some people, which is thought to be the cause of so-called "long covid" which some people experience.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#85

Does it have to be the keys that are leaked? There should be hundreds of healthcare workers who have access to the covid certificate system. I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.

These QR codes are the most obvious things to make, but they're also least useful as proof you've got the keys.

Certainly if you have a private key and you want to prove that you know the key, you can trivially make documents that only somebody with the key could make, that aren't documents any system would give people who don't have the key and yet also aren't useful fictitious documents if you're acting as a whistleblower.

That's what was done when a certificate reseller emailed the private keys of their customers to the CA they were reselling - for some reason that's unclear. The CA minted CSRs that showed they now knew the private key, without revealing what it is, and so we could all see that yup, somebody sent this CA the private keys, game over for those certificates.

[ PSA: They're called private keys, not secret keys or shared keys for a reason. Where possible you should choose your own private keys randomly and never reveal them to anybody ]

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#86

What will last longer, the pandemic or a poorly implemented digital identity platform?

These tyrants would love to hold on to these these digital “covid passports” because it gives them complete control over who can participate in society. They’d be able to exclude people who don’t comply with increasingly invasive protocols. It’s about power. The pandemic technically should already be considered endemic. For example in the USA the vast majority of the population has antibodies, in a significantly high…

> 60 to 70 percent threshold that Fauci and other public servants claimed as the target over the last year.

That number changed because the delta variant is far more infectious now. It's closer to 90 %. But you already knew that, which is why you mentioned the time frame of those statements. If I know that you're making disingenuous arguments, and you know that you're making disingenuous arguments, the healthy reaction would be to change your position until you know longer have to walk around compartmentalizing schizophrenic beliefs.

As for that meaning the pandemic has ended: it just hasn't. 1,400 people died every day over the last two week (https://www.nytimes.com/interactive/2021/us/covid-cases.html). Now I don't necessarily care about the death of people who themselves don't care, although even idiots don't deserve to die for their stupidity. But the toll on HCWs is something I would rather avoid.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#87

Earlier quoted context omitted.

I'm not aware of how the COVID certs work, but the way that's solved in TLS certificates (used for https) is that when signing, you have to use an approved timestamping authority. A timestamping authority will basically say "Yes, this action was taken at exactly this time". See [0]. [0]: https://en.wikipedia.org/wiki/Trusted_timestamping

Timestamping does exist but it isn't used in the Web PKI (what you're calling "TLS certificates") Both backdating and forward dating have been done in the Web PKI for various reasons, both legitimate (e.g. historically if you couldn't randomise serial numbers enough it was acceptable to randomise the notBefore time parameters slightly, this is no longer allowed) and illegitimate (we have pretty good circumstantial ev…

Something that is currently being used (sort of widely) is X509 OCSP. As the Cert gets signed, the CA also embeds an OCSP URL which clients can later use on the fly to determine if a cert is revoked.

In case of a leaked private key where the actual PKI wasn't breached, they still have authority over the CA itself and can therefore determine which certs are valid and which are fake.

This retains validity of the known issued certificates, but invalidates fraudulently issued certificates. The downside is that its an optional check and that every client needs an online connection in order to validate the cert.

Anyway, the COVID certificates don't seem to be actual X.509 certificates and are rather just a signed message, so this isn't something that could be utilized right now.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#88

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

It varies widely by country. From personal experience and what I've heard from relatives, at private venues: * Germany: usually quick glance at the QR code * France: usually properly scanned * Sweden: not even planned to be used * Italy: usually properly scanned

In Germany I've had some people scroll/interact with the app to make sure it's not just a screenshot, but so far nobody ever scanned my QR code.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#89
https://g.nh.ee/images/pix/1200x0/lYFSVUXJ5XY/1d2e261794d4d3...

This QR code proves Adolf Hitler has received 2 doses of Pfizer vaccine. At the moment you can still use the Estonian app to verify this (https://kontroll.digilugu.ee). Probably this specific cert will be revoked soon in all the apps.

But the cat is out of the bag. Everyone's grandparents will need to do the certificate retrieval dance again, which is another confusion that we did not need at this critical junction.

Someone out there has a serious problem with ethics. Or someone really screwed up to the point where it was obvious that a responsible disclosure was already a moot point. In my experience, CERT-EU is normally very competent and would have handled it professionally.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#90
post #51

What will last longer, the pandemic or a poorly implemented digital identity platform?

Given it is the same "poorly implemented digital identity platform" that has been in use for the last 40 years, and secures basically every form of non in person communication you conduct, I am expecting that to continue for a bit longer.

It's a shame the comment of throwawayfear has been flagged/censored as it is a valid discussion about the oppressive nature of these passports (and apparently the discussion about it).

In the Netherlands: As an unvaccinated individual you have to show a recent negative test before being able to enter a club/restaurant. So very low risk of unvaccinated people spreading Covid19. Yet, vaccinated individuals are allowed in, even when tested positive and feeling ill. There are numerous [0] cases of vaccinated individuals causing major outbreaks, resulting in the temporary closure of clubs and restaurants.

It's hard to believe these passports are about reducing hospital admissions or the public health especially in light of increased breakthrough cases [1].

[0] (Dutch) http://www.destentor.nl/zutphen/zutphens-cafe-camelot-weeken... https://www.rtvutrecht.nl/nieuws/3106637/ [1] https://www.nature.com/articles/s41591-021-01413-7

Post reply on HN