Live data from Hacker News

Private keys used to sign EU Digital Covid Certificate might have been leaked

nitter.net

91–100 of 214 posts

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#91
post #90
post #51

Earlier quoted context omitted.

Given it is the same "poorly implemented digital identity platform" that has been in use for the last 40 years, and secures basically every form of non in person communication you conduct, I am expecting that to continue for a bit longer.

It's a shame the comment of throwawayfear has been flagged/censored as it is a valid discussion about the oppressive nature of these passports (and apparently the discussion about it). In the Netherlands: As an unvaccinated individual you have to show a recent negative test before being able to enter a club/restaurant. So very low risk of unvaccinated people spreading Covid19. Yet, vaccinated individuals are allowed…

> It's hard to believe these passports are about reducing hospital admissions or the public health

Go ahead.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#92
post #81

Does it have to be the keys that are leaked? There should be hundreds of healthcare workers who have access to the covid certificate system. I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.

I think that's absolutely the most likely. And it's not hundreds, it's probably more like tens of thousands (or more). For example, when I got mine issued in Germany, I just went to a pharmacy, gave them my ID and (paper) vaccination record, and the pharmacist came back in a couple of minutes with my QR code. The interesting thing to watch, over the coming days, is this: will the public policy response do the technic…

I am not sure how the key management works, maybe they are just issuing private keys to each pharmacy, and if any pharmacy just went rogue, it should be extremely easy to know which one the certificate is coming from.

Also, it is easy to get a valid vaccination code anyways, for example, I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked. The yellow booklet is easy to forge as well.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#94
post #81

Earlier quoted context omitted.

I think that's absolutely the most likely. And it's not hundreds, it's probably more like tens of thousands (or more). For example, when I got mine issued in Germany, I just went to a pharmacy, gave them my ID and (paper) vaccination record, and the pharmacist came back in a couple of minutes with my QR code. The interesting thing to watch, over the coming days, is this: will the public policy response do the technic…

I am not sure how the key management works, maybe they are just issuing private keys to each pharmacy, and if any pharmacy just went rogue, it should be extremely easy to know which one the certificate is coming from. Also, it is easy to get a valid vaccination code anyways, for example, I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They…

> maybe they are just issuing private keys to each pharmacy

That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing.

> I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked.

This seems no different than Joe pharmacist punching in Hitler. It's still a big problem, but it's not nearly as bad as leaking the actual private key.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#95
post #76

Earlier quoted context omitted.

It varies widely by country. From personal experience and what I've heard from relatives, at private venues: * Germany: usually quick glance at the QR code * France: usually properly scanned * Sweden: not even planned to be used * Italy: usually properly scanned

Berlin: Seems like most places will actually scan it.

But, they do not check your id. You can just get a valid certificate from your friend (a screen shot even!), and enter the premises.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#96
post #89

https://g.nh.ee/images/pix/1200x0/lYFSVUXJ5XY/1d2e261794d4d3... This QR code proves Adolf Hitler has received 2 doses of Pfizer vaccine. At the moment you can still use the Estonian app to verify this ( https://kontroll.digilugu.ee ). Probably this specific cert will be revoked soon in all the apps. But the cat is out of the bag. Everyone's grandparents will need to do the certificate retrieval dance again, which is…

It (already?) records as invalid in the Italian app.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#97

Earlier quoted context omitted.

I am not sure how the key management works, maybe they are just issuing private keys to each pharmacy, and if any pharmacy just went rogue, it should be extremely easy to know which one the certificate is coming from. Also, it is easy to get a valid vaccination code anyways, for example, I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They…

> maybe they are just issuing private keys to each pharmacy That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing. > I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no q…

> That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing.

Yeah, but if they provide an web app that can create CSRs and automatically get them signed certificates, which then can be used to create QR codes, it is easy to provide traceable individual private keys for each pharmacy. E.g. when the pharmacy logs in, they just click "Generate Credentials" button, and they are done!

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#98

Nobody verified my code so far, they just eyeball the app. So the practical impact of such a leak is probably small, since people will fall for dumb forgeries already.

I haven't had my Canadian QR code properly scanned once either.

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#99
post #3

Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.

> Did literally anyone not see this coming? The system's designers did, which is why key revocation is built into the system. The practical effects of this leak will be the people who refused the app and don't read the news will be surprised when their paper certificates are rejected.

As far as I'm aware there was no technical solution for key revocation when the EU Covid Certificate was first launched in July. The only possibility I saw for revocation was to revoke the whole CA, instead of e.g CRL check.

Can you elaborate what makes you think that key revocation is built into the system?

Re: Private keys used to sign EU Digital Covid Certificate might have been leaked

#100
post #89

https://g.nh.ee/images/pix/1200x0/lYFSVUXJ5XY/1d2e261794d4d3... This QR code proves Adolf Hitler has received 2 doses of Pfizer vaccine. At the moment you can still use the Estonian app to verify this ( https://kontroll.digilugu.ee ). Probably this specific cert will be revoked soon in all the apps. But the cat is out of the bag. Everyone's grandparents will need to do the certificate retrieval dance again, which is…

It's also shown as valid by the German CovPassCheck app.
Post reply on HN