Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.
> "pickled cucumber season" Funny, it's called "cucumber time" (agurketid) in Danish. I wonder if it's a related term in Nordic countries + Estonia.
Estonian Electronic Identity Card: Security Flaws in Key Management
11–20 of 82 posts
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#12Earlier quoted context omitted.
We also call it "agurktid"/"agurknyheter" in Norwegian, and I know the Germans use "Sauregurkenzeit". I've never heard any similar expression in English, nor in any Romance languages. The Brits use "silly season" for the same concept in journalism/news.
Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August
Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday in July.
They then asked if he couldn't just tell us we had to work anyway, which -luckily for us- wasn't an option.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#13Feel free to reach out, my email is fabian (at) flapplabs.se
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#14Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#15Anyone wondering if this is a new issue; it's not, it's a more detailed writing of some previous issues, one of which being the Gemalto affair[0]. The new cards issued in 2018 are not known to have any vulnerabilities. [0]: https://www.linkedin.com/pulse/timeline-estonian-id-card-vul...
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#16Anyone wondering if this is a new issue; it's not, it's a more detailed writing of some previous issues, one of which being the Gemalto affair[0]. The new cards issued in 2018 are not known to have any vulnerabilities. [0]: https://www.linkedin.com/pulse/timeline-estonian-id-card-vul...
Didn't read the paper but it appears to be fresh, so maybe the newsworthy part is that they are still not fixed?
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#17Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#18> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#19If my memory serves me right, there was an easy way to check if your ID card was affected and it got replaced for free. The flaws described in paper are not known to exist in cards issued since the end of 2018, beginning of 2019.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#20> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]
1) Obviously, a government-issued photo ID
2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to...
3) Authentication, including: logging into your bank, government websites (the state portal, the tax authority, the the “digital story” - all your medical records, the online booking website for booking some combination of surgeons/specialists that operate under the public healthcare system), the (one) online pharmacy that exists, etc.
4) Signing things. I’ve signed my lease with it (though “paperless” Estonia still wanted me to sign a paper version as well) and more routinely you have to “digitally sign” any bank transfers... which are the standard way to pay bills in Estonia, so you do it a lot. Finally, voting online.
I don’t see how broadly compromising the crypto would really benefit anyone for any of those things, it would have to be a more specific individual attack, like draining your bank accounts.
Edit: formatting, added voting