Live data from Hacker News

Estonian Electronic Identity Card: Security Flaws in Key Management

usenix.org

21–30 of 82 posts

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#21
post #19

"The jTOP SLE78-powered ID cards were issued until the end of 2018. ID cards manufactured currently are powered by the chip platform supplied by IDEMIA (not covered in this work)." If my memory serves me right, there was an easy way to check if your ID card was affected and it got replaced for free. The flaws described in paper are not known to exist in cards issued since the end of 2018, beginning of 2019.

Yes, the Police and Border Guard has an online tool to check. They also supposedly contacted all the people with bad chips (my card was not vulnerable, so I can’t verify that).

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#22
post #12

Earlier quoted context omitted.

Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August

> I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday…

Yeah that sounds like a classic American move - who cares if they're on vacation, just make them work! Glad your employer stood up for you all (or that the law forced him/her to)!

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#23
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

[deleted]

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#24
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

He is a well-known researcher in Estonia, with his scope of work both known as well as appreciated (at least by the non-politicians). Of course some have the "too big to fail", thus "you don't talk about Vo..." attitude, but those want to turn technical argumentation into political "agreement" and it is hard to debate a 0 to become 1. You can't argue with computers, "lets agree this 0 is as good as 1, even better and greater!"

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#25

Seems interesting, but security flaws were in a countable (small) number of cases. Is this a general issue?

This shows the issues in process and attitude. Even in the case of ROCA, you do not really break the crypto part itself, you wiggle around the implementation and procedure issues to bypass it.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#26

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

As an American residing in Estonia, I’m not sure what the benefit of a state compromising the card crypto would be. There are four broad categories of uses for the ID cards: 1) Obviously, a government-issued photo ID 2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to... 3) Authentication, including: logging into your bank, government websites (the state port…

A single leak can be bad, multiple leaks piled into a single actor can be life changing.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#27
> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What these statements usually are is that "ID card has a flaw X, therefore we should immidiately ban it, close the R&D and burn it with fire", forgetting that crypto and computing in general, changes over time. My view is that, of course each flaw has to be resolved and sometimes this is political, but this just means the work has to continue.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#28

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

As an American residing in Estonia, I’m not sure what the benefit of a state compromising the card crypto would be. There are four broad categories of uses for the ID cards: 1) Obviously, a government-issued photo ID 2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to... 3) Authentication, including: logging into your bank, government websites (the state port…

Getting asked as an expert "can this id card thing be trusted?" my answer has been "for communicating with the government you inherently don't trust, the method or security of an authentication device does not really matter" (filing your taxes or logging to services being the scope). Some claiming encryption privacy issues ... Well, for any meaningful opsec you should not be using the id card for encrypting messages about overthrowing the same government issuing the encryption devices in the first place, if government reading your messages is a threat in your model.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#29
post #6
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

> "pickled cucumber season" Funny, it's called "cucumber time" (agurketid) in Danish. I wonder if it's a related term in Nordic countries + Estonia.

and "sezon ogórkowy" (cucumber time) also in Poland :)

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#30
post #7

Earlier quoted context omitted.

We also call it "agurktid"/"agurknyheter" in Norwegian, and I know the Germans use "Sauregurkenzeit". I've never heard any similar expression in English, nor in any Romance languages. The Brits use "silly season" for the same concept in journalism/news.

Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August

Most people in Europe have at least 5 weeks paid leave a year guaranteed by law.

The US does not sent a mandatory minimum, and consequently many employers don't offer anywhere near as much time off.

Post reply on HN