Live data from Hacker News

I faked tons of Covid passes – “Weak Key Cryptography in real world”

ctrsec.io

61–70 of 222 posts

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#61

Anyone knows if this is applicable to Covid passes used in the European Union as well?

EU is in discussions right now to expire COVID passes unless you have had recent vaccines i.e. booster shots. Which means any security mechanism that is defeated will just be fixed every 9 months.

Seems like a lot of hassle for a vaccine that is safe and will save your life.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#62
post #46

Short version if they get taken down: The validation apps used a 512 bit RSA public key. They used a factoring app and spend $200 on amazon to factor the private key from the public key. They were then able to generate the COVID passes. This is for the Honai Police Dept.

Why would anyone use RSA when we have X25519?

Take your pick: Needs to be certified FIPS-140-? Or backwards comparability with really old infrastructure that no one really understands? Or it was just conveniently at the top of the list of ciphers to pick?

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#63
post #28

Here in Mexico the gov issued vaccination certificates always have errors. People have resorted to downloading the PDF and "hacking it" (editing it in Acrobat). Nobody ever actually checks whether the certificate is valid or not.

I think most people who are smart enough to fake the certificate are smart enough to get vaccinated.

What do you win by using a fake certificate vs. getting protected by the vaccine?

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#64
post #6

I remember here in Canada there were concerns about this sort of thing when rolling out our proof-of-vaccination system, but practically speaking, the number of people with both the technical understanding and inclination to do this is surely too small to have a meaningful impact on COVID spread.

The QR-code based solutions, using elliptic curve asymmetric cryptography, aren't breakable by anyone at present (maybe someone has some monster quantum computer and they could, but they wouldn't be making fake vaccination certificates). The private keys could be stolen or misused of course, but there are very well proven solutions to that given how much of the industry relies upon asymmetric encryption and signing.

Originally the certificates were simple "yeah, they are vaccinated" PDFs that people would alter, which was a pretty low bar.

In discussions like this I think we really need to frame this in the proper context. We're talking about a certificate saying that you did something that you could do for free, which has significant personal benefits, and even greater social benefits, and that a large majority of the public is entirely behind. Making a fake vaccination certificate is like making a fake Grade school graduation certificate -- if someone is at that point in their life, something has gone seriously wrong.

The demand for certificates was just trying to entice the small percentage of holdouts, and of those surely there will be some who will go to great lengths, including committing pretty significant crimes, to avoid it. That pathology can't be fixed easily.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#65
post #46

Earlier quoted context omitted.

Why would anyone use RSA when we have X25519?

The real question is why use 512 bit RSA when you can use 2048+?

Key size determines number of bytes the signature takes up, which is one of the determinants of the complexity of a QR code. I suppose if you don't know what you are doing, and want to reduce QR code complexity, you lower the key size.

To turn up speculation to 100, this might also be a third world issue, because here in the west we have high quality smartphones with good cameras, but the smartphone cameras there might not be as good, so they might be challenged reading QR codes. 8 years ago I built a thing that had customized links accessible via QR codes, but my buddy's cheap phone couldn't read them due to issues with the camera resolution. A lot has happened in 8 years in terms of progress, but they still put crappy cameras into cheaper phones, and this might still pose a problem for reading complex QR codes.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#66
post #34
post #32

Earlier quoted context omitted.

weight gain isn't contagious

Actually, it is , as it tends to be intergenerational[1]. Parents that don't care about their health will raise kids that don't care about their health. [1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5305001/

That's not what contagious means.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#67
post #42
post #21

Good! Keep it up. Let things be, enough of this vaccine pass comrade BS. We who are vaccinated should be at peace and trust this vaccine will reduce the likelihood of severe illness. Those who aren’t, I wish them the best, but that’s their choice. Hopefully this will finally encourage smokers to quit and the obese to cut out a few sodas per day.

Choosing not to be vaccinated is a harm to society. Being vaccinated isn't just about protecting yourself. It is people's choice not to be vaccinated, and they're responsible for the consequences of that choice, including not being allowed in spaces where they're a hazard to others.

No, stripping unvaccinated people of their fundamental freedoms (as happened in countries like Lithuania and Austria) is a harm to society. More than harm, it's a complete disintegration.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#68
post #60

Earlier quoted context omitted.

"immunisation with either the Pfizer or AstraZeneca vaccine reduced the chance of onward virus transmission by 40–60%" [1] That is not marginally less and which is why people should be vaccinated. Also unvaccinated people place significant strain on the hospital system preventing elective surgery and increasing my costs as a taxpayer. [1] https://khub.net/documents/135939561/390853656/Impact+of+vac...

> "immunisation with either the Pfizer or AstraZeneca vaccine reduced the chance of onward virus transmission by 40–60%" [1] so why are there still soaring case rates in the countries with the most vaccines? I'll trust my lying eyes, thank you. it's honestly insulting that you can post some pissant "study" like this and expect to be taken seriously when anyone can just look at the case rates and vax rates by country…

a) There are still soaring case rates because vaccination rates are not 100% and you have waning immunity. People who are dying are the ones who are unvaccinated. But you will still get breakthrough cases which nobody has ever denied will happen.

b) If you some independent study which proves your statement that vaccines only "marginally" affect transmission then please post it.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#69
post #6

I remember here in Canada there were concerns about this sort of thing when rolling out our proof-of-vaccination system, but practically speaking, the number of people with both the technical understanding and inclination to do this is surely too small to have a meaningful impact on COVID spread.

The problem is that the people that are a) evil enough and b) technical enough to understand this will sell COVID passes for hundreds of dollars each. Here in the NL there have been tons of people that sold COVID passes, some working at vaccination places, others working at testing places. Instead of hacking anything, they've just been committing regular fraud. The street value of these passes seems to be round €300…

How did the government recognize the fake passes? Just asking so I can alert my government if I see them somewhere.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#70
post #46

Earlier quoted context omitted.

Why would anyone use RSA when we have X25519?

The real question is why use 512 bit RSA when you can use 2048+?

My guess is Vietnam’s spec was to achieve the same level of integrity as a paper document (ie. Minimal) and optimize for cheap/poor quality cameras.

Longer keylengths make it difficult to deliver sufficient payload in a QR. not sure about EU, but the SMART health passes that are the emerging standard use ES256 signatures.

The lack of global leadership for interoperable standards early on made this more difficult. You had the EU, Israel, US states and others who were ahead of the curve, but that approach had limits that were reached.

Now in the US we also have the issue of dealing with states with wacky political stances. States like California, New York and Louisiana, combined with private sector leaders like Walmart and Epic made SMART the defacto US standard, and other countries are recognizing them.

Post reply on HN