> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]
I know your comment was tongue in cheek but this has come up in the digital Id space before. All these things get bootstrapped off government sources and spooks have no problems because governments control those databases. You don’t need technical hacks if you control the systems of record.
Estonian Electronic Identity Card: Security Flaws in Key Management
41–50 of 82 posts
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#42Earlier quoted context omitted.
Yeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.
Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…
As candidates & parties become more competitive, the difference in their voting shares tends to narrow. Eventually you end up with large coalitions that split the electorate fairly evenly. A small adjustment is all it'd take to tip the scales. If landslide victories are common, I'd say your political system is doing something wrong.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#43Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.
Regarding your last point, I have a hard time seeing what you mean. The system is audited both internally and externally fairly regularly, the latest report being released just December last year [0]. There is also frequent news coverage, both supporting and criticizing the system [1][2]. One of the current government parties [3] is an active critic of the system. So it seems like a fair stretch to say that discussin…
Can you please clarify the 'fairly regularly' part? One of the members of that commission said that this is the first time that this kind of audit has been undertaken: https://digi.geenius.ee/rubriik/uudis/e-valimiste-tooruhma-l... To be fair, there are lots of other reviews having taken place, but none of them are regular with the exception of the OECD ones happening during elections: https://et.wikipedia.org/wiki/Elektrooniline_h%C3%A4%C3%A4le...
> There is also frequent news coverage, both supporting and criticizing the system
ERR is government-funded and seems to me quite neutral, not sure how it is relevant here. But it still seems to me that mainstream media is supportive and you have to go to "alternative" news sources to find any true criticism.
> One of the current government parties [3] is an active critic of the system.
Actually 2, if you count both KE and EKRE. And this is one of the major criticisms against those parties and has been so for years.
A good example of the prevailing attitude can be seen in this thread from 2017 about the security hole back then from Hinnavaatlus, probably biggest IT-related forum in Estonia: https://foorum.hinnavaatlus.ee/viewtopic.php?t=715076&postda... The general tonality in the beginning was that this is a tinfoil problem and somehow brought up by KE and EKRE before elections until the reality of the situation sunk in.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#44> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…
Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.
If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and not vice versa, then this is not acceptable.
[0] https://www.youtube.com/watch?v=LkH2r-sNjQs Tom Scott's video about e-voting. Funniest rebuttal I saw on Estonian social media was that we are secure, since he is talking about e-voting, but we have i-voting. So I guess once we will call it c-voting, it will be even better...?
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#45I'm from the EU and considering incorporating my next company in Estonia. Anyone else in a similar situation has any recommendations or ideas about this?
Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there. See my older comment [1] for some related topcis to research. [1] https://news.ycombinator.com/item?id=21321451
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#46Earlier quoted context omitted.
Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August
> I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday…
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#47"The jTOP SLE78-powered ID cards were issued until the end of 2018. ID cards manufactured currently are powered by the chip platform supplied by IDEMIA (not covered in this work)." If my memory serves me right, there was an easy way to check if your ID card was affected and it got replaced for free. The flaws described in paper are not known to exist in cards issued since the end of 2018, beginning of 2019.
ROCA didn't just affect Estonian ID cards, though. It also affected also TPMs (from Infineon), certain Yubikeys [4], and even some PGP keys!
---
[0]: https://github.com/crocs-muni/roca
[1]: https://roca.crocs.fi.muni.cz/
[2]: https://keychest.net/roca/
[3]: http://www.id.ee/?lang=en&id=38239
[4]: https://www.yubico.com/support/security-advisories/ysa-2017-...
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#48Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.
> "pickled cucumber season" Funny, it's called "cucumber time" (agurketid) in Danish. I wonder if it's a related term in Nordic countries + Estonia.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#49Earlier quoted context omitted.
Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.
It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at. If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and no…
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#50Earlier quoted context omitted.
Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there. See my older comment [1] for some related topcis to research. [1] https://news.ycombinator.com/item?id=21321451
Yes, I'd definitely echo that, a huge amount of tax implications are based on individual residency/permanent establishment so if you're living in say, Germany, for 1/2 of the year + 1 day, you should be expecting to pay at least your personal income taxes there, and likely the business taxes if you're a sole prop without local employees and local business. Of course, if you're a true 'digital nomad' who doesn't estab…