Live data from Hacker News

Estonian Electronic Identity Card: Security Flaws in Key Management

usenix.org

31–40 of 82 posts

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#31

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

The spooks are the same government issuing the ID. They can just call up the department issuing the IDs and ask for a batch of new identities. No technical flaws necessary.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#32

> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#33

Earlier quoted context omitted.

As an American residing in Estonia, I’m not sure what the benefit of a state compromising the card crypto would be. There are four broad categories of uses for the ID cards: 1) Obviously, a government-issued photo ID 2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to... 3) Authentication, including: logging into your bank, government websites (the state port…

Getting asked as an expert "can this id card thing be trusted?" my answer has been "for communicating with the government you inherently don't trust, the method or security of an authentication device does not really matter" (filing your taxes or logging to services being the scope). Some claiming encryption privacy issues ... Well, for any meaningful opsec you should not be using the id card for encrypting messages…

Yeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#34

Earlier quoted context omitted.

Getting asked as an expert "can this id card thing be trusted?" my answer has been "for communicating with the government you inherently don't trust, the method or security of an authentication device does not really matter" (filing your taxes or logging to services being the scope). Some claiming encryption privacy issues ... Well, for any meaningful opsec you should not be using the id card for encrypting messages…

Yeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.

Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed.

Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the "digital results in rigging, keep it physical for safety" kind isn't super convincing.

--

[1] https://en.wikipedia.org/wiki/1940_Estonian_parliamentary_el...

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#35
post #4
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

Regarding your last point, I have a hard time seeing what you mean. The system is audited both internally and externally fairly regularly, the latest report being released just December last year [0]. There is also frequent news coverage, both supporting and criticizing the system [1][2]. One of the current government parties [3] is an active critic of the system. So it seems like a fair stretch to say that discussin…

Being spammed with reviews after mentioning that there might be a disagreement about electronic id data collection drives the original point a bit.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#37

> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

ID card is mandatory by law, but there aren't sanctions (in my knowledge). You need some kind document though, in US that is usually drivers license. I don't see big difference here.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#38
post #4

Earlier quoted context omitted.

Regarding your last point, I have a hard time seeing what you mean. The system is audited both internally and externally fairly regularly, the latest report being released just December last year [0]. There is also frequent news coverage, both supporting and criticizing the system [1][2]. One of the current government parties [3] is an active critic of the system. So it seems like a fair stretch to say that discussin…

Being spammed with reviews after mentioning that there might be a disagreement about electronic id data collection drives the original point a bit.

While I try to sympathize, I'm not entirely sure I see what you mean. Neither the research linked in the submission nor anything that I linked to discusses data collection, unless I'm grossly misunderstanding you.

As for the things I linked, none of them are reviews. The first link is a ministry report from last year that outlines 25 shortcomings of the system and how to address them — a clear example that there's open discussion about any problems the current system has. The second and third links are national news coverage that clearly show articles from both pro and con sides. The last link is about the current government in general.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#39
post #36

I'm from the EU and considering incorporating my next company in Estonia. Anyone else in a similar situation has any recommendations or ideas about this?

Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there.

See my older comment [1] for some related topcis to research.

[1] https://news.ycombinator.com/item?id=21321451

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#40
post #34

Earlier quoted context omitted.

Yeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.

Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…

> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible.

How many more votes would the party in second place at the last election have needed in order to have won instead?

> If some party suddenly receives a lot more votes than they polled for - it will be noticed.

Is there a mechanism by which the election could be run again (before the winners of the election have a chance to prevent this)?

> Also Estonia already has a history of (non-digital) election rigging

Or it's an argument that a voting system should have both hand-counting and digital counting, because rigging both counts is at least twice as difficult as rigging one.

Post reply on HN