I faked tons of Covid passes – “Weak Key Cryptography in real world”
11–20 of 222 posts
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#12Anyone knows if this is applicable to Covid passes used in the European Union as well?
The private keys for the European Green Pass have been leaked and fake passes signed with the keys are being sold on the dark web. https://threatpost.com/eus-green-pass-vaccination-id-private...
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#13> Although the code was provided, we took around 2 days to get this running since the code was written back in 2015. Some libraries are not currently supported forced us to make several changes on the code. The project was then running smoothly. Why not use a VM with older libraries and tools ?
Looks like the source code is meant for Amazon's EC2, so it was depending on the python/libraries on the EC2 back then, 5-6 years ago.
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#14Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#15Earlier quoted context omitted.
The private keys for the European Green Pass have been leaked and fake passes signed with the keys are being sold on the dark web. https://threatpost.com/eus-green-pass-vaccination-id-private...
They haven't been revoked yet?
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#16I remember here in Canada there were concerns about this sort of thing when rolling out our proof-of-vaccination system, but practically speaking, the number of people with both the technical understanding and inclination to do this is surely too small to have a meaningful impact on COVID spread.
It seems that actually nothing has had a meaningful impact on coronavirus spread.
Not sure if trolling, but in case not, vaccination has had “a substantial impact on mitigating COVID-19 outbreaks” in America [1].
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#17I remember here in Canada there were concerns about this sort of thing when rolling out our proof-of-vaccination system, but practically speaking, the number of people with both the technical understanding and inclination to do this is surely too small to have a meaningful impact on COVID spread.
The current standard all provinces have switched to uses "Elliptic Curve keys using the P-256 curve", does it not? https://spec.smarthealth.cards/
Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#18Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”
#19Anyone knows if this is applicable to Covid passes used in the European Union as well?
The private keys for the European Green Pass have been leaked and fake passes signed with the keys are being sold on the dark web. https://threatpost.com/eus-green-pass-vaccination-id-private...
Afaik it was a leaked login, not a leak of the keys.