https://g.nh.ee/images/pix/1200x0/lYFSVUXJ5XY/1d2e261794d4d3... This QR code proves Adolf Hitler has received 2 doses of Pfizer vaccine. At the moment you can still use the Estonian app to verify this ( https://kontroll.digilugu.ee ). Probably this specific cert will be revoked soon in all the apps. But the cat is out of the bag. Everyone's grandparents will need to do the certificate retrieval dance again, which is…
It (already?) records as invalid in the Italian app.
Private keys used to sign EU Digital Covid Certificate might have been leaked
101–110 of 214 posts
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#102https://marcan2020.medium.com/reversing-smart-health-cards-e...
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#103https://g.nh.ee/images/pix/1200x0/lYFSVUXJ5XY/1d2e261794d4d3... This QR code proves Adolf Hitler has received 2 doses of Pfizer vaccine. At the moment you can still use the Estonian app to verify this ( https://kontroll.digilugu.ee ). Probably this specific cert will be revoked soon in all the apps. But the cat is out of the bag. Everyone's grandparents will need to do the certificate retrieval dance again, which is…
It's also shown as valid by the German CovPassCheck app.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#104Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...
The apps for Latvia, Luxembourg and Switzerland say OK, the one for France says "OK but fraudulent", the one for Iceland says no. From the article it looks like the Italian app also says no.
Not revoked everywhere it seems. Also, the French app seems to check against a blacklist, so it is possible that only the Hitler code is considered invalid and not the signing key.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#105Earlier quoted context omitted.
> Did literally anyone not see this coming? The system's designers did, which is why key revocation is built into the system. The practical effects of this leak will be the people who refused the app and don't read the news will be surprised when their paper certificates are rejected.
As far as I'm aware there was no technical solution for key revocation when the EU Covid Certificate was first launched in July. The only possibility I saw for revocation was to revoke the whole CA, instead of e.g CRL check. Can you elaborate what makes you think that key revocation is built into the system?
My understanding was that each node in a certificate tree/list consists of a key pair (public/private), and the entity metadata which needs to be verified. eg. the root CA has a private key that it uses to sign CAs, and those CAs have their own private key that it used to sign individual leaf node certificates.
Meanwhile, revocations are distributed as a separate CRL - certificate revocation list - which contains a list of certificates whose signees are no longer to be trusted. I'm not very clear on how this process works, but in any case I don't think keys can be revoked.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#106Earlier quoted context omitted.
It varies widely by country. From personal experience and what I've heard from relatives, at private venues: * Germany: usually quick glance at the QR code * France: usually properly scanned * Sweden: not even planned to be used * Italy: usually properly scanned
In Germany I've had some people scroll/interact with the app to make sure it's not just a screenshot, but so far nobody ever scanned my QR code.
I'm alway taking screenshot of my qr code for boarding pass and things like that so I don't have to keep the airline app open and it works without network.
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#107Seems the keys have already been revoked. Doesn't mean it can't leak again, but doesn't seem to be a problem with a leaked key at the moment. Actual source seems to be here: https://rfmirror.com/Thread-TRADING-make-EU-green-pass?page=...
I checked the Hitler code with apps from Latvia, Switzerland, Luxembourg, Iceland and France. The apps for Latvia, Luxembourg and Switzerland say OK, the one for France says "OK but fraudulent", the one for Iceland says no. From the article it looks like the Italian app also says no. Not revoked everywhere it seems. Also, the French app seems to check against a blacklist, so it is possible that only the Hitler code i…
Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#108Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#109Re: Private keys used to sign EU Digital Covid Certificate might have been leaked
#110Did literally anyone not see this coming? We all know the government can’t hold on to keys. I fear this will be used as an excuse to make the passport system even more centralized.
78 governments have ICAO private keys, and most have done so for >10 years now. If what "we all know" is true, then you should be able to find a leaked key easily. Try googling. Or you might fall back to claiming that while governments evidently can hold on to ICAO private keys, they can't hold on to this other kind of private key, because...