Live data from Hacker News

Estonian Electronic Identity Card: Security Flaws in Key Management

usenix.org

41–50 of 82 posts

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#41

> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]

I know your comment was tongue in cheek but this has come up in the digital Id space before. All these things get bootstrapped off government sources and spooks have no problems because governments control those databases. You don’t need technical hacks if you control the systems of record.

So what's to stop the ruling party from issuing its loyal spooks thousands of ID cards in key districts, which they then use to cast fraudulent votes in the election?

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#42
post #34

Earlier quoted context omitted.

Yeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.

Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…

> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible.

As candidates & parties become more competitive, the difference in their voting shares tends to narrow. Eventually you end up with large coalitions that split the electorate fairly evenly. A small adjustment is all it'd take to tip the scales. If landslide victories are common, I'd say your political system is doing something wrong.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#43
post #4
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

Regarding your last point, I have a hard time seeing what you mean. The system is audited both internally and externally fairly regularly, the latest report being released just December last year [0]. There is also frequent news coverage, both supporting and criticizing the system [1][2]. One of the current government parties [3] is an active critic of the system. So it seems like a fair stretch to say that discussin…

> The system is audited both internally and externally fairly regularly, the latest report being released just December last year

Can you please clarify the 'fairly regularly' part? One of the members of that commission said that this is the first time that this kind of audit has been undertaken: https://digi.geenius.ee/rubriik/uudis/e-valimiste-tooruhma-l... To be fair, there are lots of other reviews having taken place, but none of them are regular with the exception of the OECD ones happening during elections: https://et.wikipedia.org/wiki/Elektrooniline_h%C3%A4%C3%A4le...

> There is also frequent news coverage, both supporting and criticizing the system

ERR is government-funded and seems to me quite neutral, not sure how it is relevant here. But it still seems to me that mainstream media is supportive and you have to go to "alternative" news sources to find any true criticism.

> One of the current government parties [3] is an active critic of the system.

Actually 2, if you count both KE and EKRE. And this is one of the major criticisms against those parties and has been so for years.

A good example of the prevailing attitude can be seen in this thread from 2017 about the security hole back then from Hinnavaatlus, probably biggest IT-related forum in Estonia: https://foorum.hinnavaatlus.ee/viewtopic.php?t=715076&postda... The general tonality in the beginning was that this is a tinfoil problem and somehow brought up by KE and EKRE before elections until the reality of the situation sunk in.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#44

> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at.

If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and not vice versa, then this is not acceptable.

[0] https://www.youtube.com/watch?v=LkH2r-sNjQs Tom Scott's video about e-voting. Funniest rebuttal I saw on Estonian social media was that we are secure, since he is talking about e-voting, but we have i-voting. So I guess once we will call it c-voting, it will be even better...?

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#45
post #39
post #36

I'm from the EU and considering incorporating my next company in Estonia. Anyone else in a similar situation has any recommendations or ideas about this?

Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there. See my older comment [1] for some related topcis to research. [1] https://news.ycombinator.com/item?id=21321451

Yes, I'd definitely echo that, a huge amount of tax implications are based on individual residency/permanent establishment so if you're living in say, Germany, for 1/2 of the year + 1 day, you should be expecting to pay at least your personal income taxes there, and likely the business taxes if you're a sole prop without local employees and local business. Of course, if you're a true 'digital nomad' who doesn't establish residency anywhere it gets much trickier. But in general, my advice it to pay for 1-2 hours with an accountant up front before you go through setting up a new entity somewhere

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#46
post #12

Earlier quoted context omitted.

Ha, I'm an American who lived in Estonia for a bit, I'm not familiar with any related US term. Maybe we just don't have this as much as Europe - I know I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August

> I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday…

One time here in the US I had to work late hours and weekends to hit an ambitious deadline for a French customer who wanted to review our work before they all went on their vacations.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#47
post #19

"The jTOP SLE78-powered ID cards were issued until the end of 2018. ID cards manufactured currently are powered by the chip platform supplied by IDEMIA (not covered in this work)." If my memory serves me right, there was an easy way to check if your ID card was affected and it got replaced for free. The flaws described in paper are not known to exist in cards issued since the end of 2018, beginning of 2019.

Yeah, an "offline tester" [0] was made available by the researchers who discovered ROCA [1] and a company with "close links" to the researchers created a "ROCA Vulnerability Test Suite" [2]. The Estonian government also had one on their web site [3] but it is, apparently, no longer available.

ROCA didn't just affect Estonian ID cards, though. It also affected also TPMs (from Infineon), certain Yubikeys [4], and even some PGP keys!

---

[0]: https://github.com/crocs-muni/roca

[1]: https://roca.crocs.fi.muni.cz/

[2]: https://keychest.net/roca/

[3]: http://www.id.ee/?lang=en&id=38239

[4]: https://www.yubico.com/support/security-advisories/ysa-2017-...

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#48
post #6
post #2

Brave guy to publish this, hopefully it won't end up similar to the Dreyfus affair — depends on which the media will roll due to it being "pickled cucumber season" (everybody is on vacation, nothing much happening during summer in Estonia). The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata.

> "pickled cucumber season" Funny, it's called "cucumber time" (agurketid) in Danish. I wonder if it's a related term in Nordic countries + Estonia.

Okurková sezóna in Czech

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#49
post #44

Earlier quoted context omitted.

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at. If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and no…

That video had outdated information regarding the Estonian e-voting system. The report from 2014 has been invalidated by the newer system, IVXV, which has been redesigned to address previous criticism. The newer system is open source, available at https://github.com/vvk-ehk/ivxv. A good source to quickly familiarize yourself with the architecure, is "Improving the verifiability of the Estonian Internet Voting scheme"[0] by Jan Willemson et al

[0] https://research.cyber.ee/~janwil/publ/ivxv-evoteid.pdf

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#50
post #39

Earlier quoted context omitted.

Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there. See my older comment [1] for some related topcis to research. [1] https://news.ycombinator.com/item?id=21321451

Yes, I'd definitely echo that, a huge amount of tax implications are based on individual residency/permanent establishment so if you're living in say, Germany, for 1/2 of the year + 1 day, you should be expecting to pay at least your personal income taxes there, and likely the business taxes if you're a sole prop without local employees and local business. Of course, if you're a true 'digital nomad' who doesn't estab…

Even if my personal account was in an Estonian bank?
Post reply on HN