Live data from Hacker News

I faked tons of Covid passes – “Weak Key Cryptography in real world”

ctrsec.io

141–150 of 222 posts

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#141
In Russia (and I suspect much of the rest of the world) you don't need to fake anything. You pay off the doctor and get a shot of saline instead, along with a totally valid record in the government DB. They catch them from time to time, but doctors there are paid laughably little money (as in nearly all countries with fully socialized medicine), so they do what they can to get by. Price of admission is between 3000 and 15000 rubles ($40-200) depending on where you are.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#142

Earlier quoted context omitted.

I think most people who are smart enough to fake the certificate are smart enough to get vaccinated. What do you win by using a fake certificate vs. getting protected by the vaccine?

Unfortunately, you’d be surprised. I know of at least one

I know dozens of people working in the healthcare sector skeptical of covid vaccines, among them virologists specialized in RNA viruses.

Their skepticism is far more nuanced, and evidence based, than the "All vaccines are poison/bill gates gonna 5G us!" covid vaccine skepticism is usually framed as.

They do not oppose any other common sense measures, like mask wearing, they simply want to be careful about vaccines that have been pushed to markets in record times on very questionable, mostly political, narratives.

Like vaccines allegedly saving us with "heard immunity" when most people familiar with the topic knew very well how that was extremely unlikely to happen.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#144

Here is how government-issued QR codes (not only vaccination ones) works in my country: it's just a link to government site. Why reinvent crypto, PKI and all? Also solves updates/invalidation issues.

If you want to minimize the time people spent waiting in queue to have these passes scanned, an offline validation method makes a lot of sense. Also optimizes time spent in queue while site is down or overloaded.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#145
post #126

This kind of breach isn't possible in Australia since their laws can beat the laws of math. Countries with less powerful laws are apparently not so lucky. https://www.gizmodo.com.au/2017/07/prime-minister-says-the-l... (Yeah, tongue firmly in cheek. Laws of math oddly enough seem to work just fine for taxation, depreciation, etc etc)

It's unfortunate that we've had successive governments (both sides) attacking privacy and security. From a casual glance, it looks to be done out of incompetence, when you see such headlines. But boy is that a long streak of coincidences.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#146

Earlier quoted context omitted.

Thanks for the link. For fun I downloaded the referenced CDC dataset. One thing I noticed is that the fraction of deaths per case for the vaccinated population was higher than for the unvaccinated population until July, at which point it "snapped" to match for the rest of the dataset. It seems like a curious anomaly. https://imgur.com/a/QGJqs0S

Where older and more venerable people being vaccinated early? They still are more likely to die if infected. Then a spread of vaccination to the general population. You would have to look at a breakdown of who was vaccinated at the time you saw the lower vaccine benefit.

I thought about that, but it seems like whatever changed must have happened nearly instantaneously. Looking at the plot, it's a rather pronounced step change.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#147
post #46

Earlier quoted context omitted.

Why would anyone use RSA when we have X25519?

The real question is why use 512 bit RSA when you can use 2048+?

     RSA 512-bits key was proven breakable years ago
Even so, I am amazed they were able to break it so quickly and cheaply.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#148
post #28

Here in Mexico the gov issued vaccination certificates always have errors. People have resorted to downloading the PDF and "hacking it" (editing it in Acrobat). Nobody ever actually checks whether the certificate is valid or not.

I think most people who are smart enough to fake the certificate are smart enough to get vaccinated. What do you win by using a fake certificate vs. getting protected by the vaccine?

More likely smart enough not to.

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#149
Real talk: are people saying they wanted this to be secure? If we are going to do this "vaccine paperwork to do anything" regime, I wouldn't want it to be some super secure mechanism that had digital proof of personhood provided by some government entity with an unhackable key! This key size frankly seems like the perfect balance: it took some months for someone to get around to breaking it, and then it took some months for a service that used that cracked key to become popular enough to make a real impact on safety, and maybe maybe just maybe soon we won't need this anymore, and none of these existing digital records will be trustable... and, if we are stuck doing this for another year, we should roll another weak key. (If nothing else, if you make an actually secure mechanism that ties a person to their vaccine record with a signature, you just know that tomorrow some WorldCoin-like company is going to try to use it for some stupid crypto "airdrop" ;P.)

Re: I faked tons of Covid passes – “Weak Key Cryptography in real world”

#150
post #149

Real talk: are people saying they wanted this to be secure? If we are going to do this "vaccine paperwork to do anything" regime, I wouldn't want it to be some super secure mechanism that had digital proof of personhood provided by some government entity with an unhackable key! This key size frankly seems like the perfect balance: it took some months for someone to get around to breaking it, and then it took some mon…

Why though when it's very little effort to use a stronger key? What's the downside?
Post reply on HN