Live data from Hacker News

Estonian Electronic Identity Card: Security Flaws in Key Management

usenix.org

11–20 of 82 posts

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#11
post #6
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

> "pickled cucumber season" Funny, it's called "cucumber time" (agurketid) in Danish. I wonder if it's a related term in Nordic countries + Estonia.

Yeah, we also use 'time of pickled cucumbers' in Slovenia. So not just a nordic thing ;)

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#12
post #7

Earlier quoted context omitted.

We also call it "agurktid"/"agurknyheter" in Norwegian, and I know the Germans use "Sauregurkenzeit". I've never heard any similar expression in English, nor in any Romance languages. The Brits use "silly season" for the same concept in journalism/news.

Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August

> I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August

Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday in July.

They then asked if he couldn't just tell us we had to work anyway, which -luckily for us- wasn't an option.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#13
Are there any Estonians here on HN who would be willing to chat a bit about digital identities in your country? I'm working on bringing e-ID to more people (https://getpass.app/) and looking to get a better understanding of current solutions.

Feel free to reach out, my email is fabian (at) flapplabs.se

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#14
> n this paper, we describe several security flaws found in the ID card manufacturing process ..

Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#15
post #3

Anyone wondering if this is a new issue; it's not, it's a more detailed writing of some previous issues, one of which being the Gemalto affair[0]. The new cards issued in 2018 are not known to have any vulnerabilities. [0]: https://www.linkedin.com/pulse/timeline-estonian-id-card-vul...

Didn't read the paper but it appears to be fresh, so maybe the newsworthy part is that they are still not fixed?

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#16
post #15
post #3

Anyone wondering if this is a new issue; it's not, it's a more detailed writing of some previous issues, one of which being the Gemalto affair[0]. The new cards issued in 2018 are not known to have any vulnerabilities. [0]: https://www.linkedin.com/pulse/timeline-estonian-id-card-vul...

Didn't read the paper but it appears to be fresh, so maybe the newsworthy part is that they are still not fixed?

The paper is half for giving a technical overview of the issues and part new analysis based on datamining old certificates. The issues have been mostly fixed, compliance violations however are still badly monitored.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#18

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

I know your comment was tongue in cheek but this has come up in the digital Id space before. All these things get bootstrapped off government sources and spooks have no problems because governments control those databases. You don’t need technical hacks if you control the systems of record.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#19
"The jTOP SLE78-powered ID cards were issued until the end of 2018. ID cards manufactured currently are powered by the chip platform supplied by IDEMIA (not covered in this work)."

If my memory serves me right, there was an easy way to check if your ID card was affected and it got replaced for free. The flaws described in paper are not known to exist in cards issued since the end of 2018, beginning of 2019.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#20

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

As an American residing in Estonia, I’m not sure what the benefit of a state compromising the card crypto would be. There are four broad categories of uses for the ID cards:

1) Obviously, a government-issued photo ID

2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to...

3) Authentication, including: logging into your bank, government websites (the state portal, the tax authority, the the “digital story” - all your medical records, the online booking website for booking some combination of surgeons/specialists that operate under the public healthcare system), the (one) online pharmacy that exists, etc.

4) Signing things. I’ve signed my lease with it (though “paperless” Estonia still wanted me to sign a paper version as well) and more routinely you have to “digitally sign” any bank transfers... which are the standard way to pay bills in Estonia, so you do it a lot. Finally, voting online.

I don’t see how broadly compromising the crypto would really benefit anyone for any of those things, it would have to be a more specific individual attack, like draining your bank accounts.

Edit: formatting, added voting

Post reply on HN