7 ms·
Estonia blocks electronic ID cards over identity-theft risk
- paulajohnson 9y agoOther governments take note: this is what good electronic security looks like.
- walshemj 9y agoOther governments take note his is what putting all your eggs in one basket looks like.
- DennisP 9y agoIn the U.S. we also put all our eggs in one basket, but instead of that basket being a digital certificate/smartcard, it's a nine-digit number that we use as both userid and password.
- porfirium 9y agoComparing many things to the US is setting a pretty low bar.
- tauntz 9y agoExcept all eggs aren't in one basket - ID card cert usage will be blocked but you can still use Mobile-ID to sign documents, log into govt websites and do everything else that you can do with your ID card. https://e-estonia.com/solutions/e-identity/mobile-id/ https://e-estonia.com/solutions/e-identity/mobile-id/
- martinraag 9y agoMore like 3 baskets. Estonians can also use a Mobile ID, where private keys, authentication and signature functions are stored on a special SIM card. More recently, an app based Smart ID was also introduced. If you're on one of those services, the certificate revocation doesn't really affect you.
- walshemj 9y agoAll easy targets for the bear next door - and maybe having a national ID card is not such a good idea in the first place
- tauntz 9y agoClarification: Smart ID does not (yet) have the same functionality as Mobile-ID or ID Card (you can log into some supported services with it but that's about it). AFAIK they're working on it to get it to the same level so you could give official signatures and log into govt services etc using that as well.
- dekrg 9y agoThere is only one basket that is made to look that there are three baskets. To get a Mobile-ID need to have an ID-card with valid certificates. If the certs are revoked you can't activate your Mobile-ID. Also you have to pay a monthly fee for Mobil-ID service. Smart-ID requires that you have an ID-Card or Mobile-ID and more importantly it's practically useless as you can't use it for any government services.
- dullgiulio 9y agoID cards have been usable until yesterday and will be again soon. Mine was upgraded and is still useful. You don't need it all the time, only to sign up. Your argument doesn't quite make sense.
- dekrg 9y agoIf you need another basket to have access to it (even if only initially) then it's not really a separate basket on a national level.
- dullgiulio 9y agoJust like you need a valid e-mail to sign up somewhere. Except that here you won't need it afterwards (even if your ID is compromised, it can be blocked and the other systems provide secure identity.) All of this is backed by the "single basket" of people actually showing up in the population registry office... PS: I see, you have just joined HN to write these unsubstantiated comments.
- lxtx 9y agoNot really, I can still use my mobile ID just fine. Not even in a hurry to get my certificates updated.
- Faaak 9y agoSpain does the same. With you ID card chip, you can: - sign your emails digitally - login to secure websites with your id card (bank, DMV, taxes, …). Sometimes you can only do it with the ID card - they opened many of their tools, so you can design your website to allow login with Spain's ID cards (that was a fun project)
- dullgiulio 9y agoWere these cards affected? Were there any official notices from authorities? Even if not affected, it would be nice to hear an official comment. I was discussing this with someone from Belgium and we agreed that silence from the Belgian government meant only one thing: nobody used the service. (Specifically: Belgian cards are the older Gemalto generation, thus not affected, like the older Estonian IDs.)
- pfg 9y agoWe have a similar system in Austria and I got curious when ROCA was announced. Turns out the cards here generate ECDSA keys and are thus not affected. Naturally, there was no announcement of any kind, so this took quite a bit of sleuthing to figure out. Maybe Spain happens to use ECC keys too.
- dullgiulio 9y agoFor those wondering: "upgrading the Estonian ID cards" means switching to ECC (P-384). New certificates are generated on the chip, and the public part is then transmitted to the government public keys directory.
- bdonlan 9y agoHow do they authenticate the new ECC policy key when the RSA key is already compromised?
- dullgiulio 9y ago
- sccxy 9y agoGovernment handled it pretty well, but the chip maker (Gemalto) hid the security problem for months before telling its customers. And can't find any information about security breach in Gemalto's website...
- s14ve 9y agoSlovakia invalidated them 3 days ago and is moving to 3072bit keys. However, our minister of the interior "Robert Kalinak" announced that they should hack his if its real threat. The only thing which he didn't mention is that his public key isn't publicly available...
- jackvalentine 9y ago> As of October 31, all users of faulty ID cards can update their security certificates remotely and at Estonian police and border guard service points. I have been trying every day to do so but constantly getting “server is overloaded” errors.
- emerongi 9y agoOfficial announcement: https://www.valitsus.ee/en/news/estonia-will-block-certificates-760-000-id-cards-evening-3-november https://www.valitsus.ee/en/news/estonia-will-block-certifica... It was claimed that software for cracking the private keys has entered the black market, so they had to block the sertificates earlier than expected.
- dullgiulio 9y agoWho claimed there is cracking software in the black market? I don't find it hard to believe, of course. The Estonian government is legally bound to applying such countermeasures as soon as there is reasonable doubt about the security of the system. It's pretty important that such things are encoded in law and are not up to whim.
- s14ve 9y agoFull paper is out: https://crocs.fi.muni.cz/_media/public/papers/nemec_roca_ccs17_preprint.pdf https://crocs.fi.muni.cz/_media/public/papers/nemec_roca_ccs... Anyone with good programming skill can make the exploit in matter of hours => it surely is somewhere on black market.
- DocG 9y ago>ID Card is compulsory >760,000 ID cards will be blocked >in country of 1.3 million >I have no idea how I can declare monthly VAT numbers It is bad but could be worse. People are signing up for MobileID and there is still possible to update ID cards via going to the office. But poor people abroad. Basically they will be cut off from all the services.
- dvfjsdhgfv 9y agoOther nations can watch and learn on Estonia's mistakes. The big question is: can such a scenario (a faulty chip) be completely eliminated?
- deleted 9y ago[deleted]
- DocG 9y agoAs I understand, not really. Only prepare. Although people are unhappy and annoyed, I think it is right decision to close the ID cards. This can be recovered from. If they were compromised, the trust would be gone.
- matiasb 9y agoI'm located in South America and I was able to update the certificates online.
- smcl 9y agoBeen trying with little luck to arrange my appointment to pick up my card from the local embassy - I guess this is why
- pjc50 9y agoThis is fallout from the Infineon private key weakness, isn't it?
- kristjankalm 9y agohttp://news.err.ee/640385/government-to-close-id-card-certificates-with-security-risk-at-midnight http://news.err.ee/640385/government-to-close-id-card-certif... "Information System Authority (RIA) Director General Taimar Peterkop likewise confirmed that the threat assessment had changed after the research published by the Czech researchers on Monday revealed that the security flaw affecting Estonian ID cards is easier to exploit than previously believed." is what you are reffering to "the research published by the Czech researchers"?
- pjc50 9y agohttps://arstechnica.co.uk/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/ https://arstechnica.co.uk/information-technology/2017/10/cry...
- IndrekR 9y agoYes, the Infineon case. Gemalto uses their chips. One interesting thing. As Gemalto was the first frontier, the stock market reacted quickly to them (-25%). However, the Infineon stock went to the other direction (+27%) since the vulnerability was discovered. Ok, they are also 9 times larger and digital security is not their main market.
- tauntz 9y agoThe vulnerability in question: *The Return of Coppersmith’s Attack: Practical Factorization of Widely Used RSA Moduli∗ https://crocs.fi.muni.cz/_media/public/papers/nemec_roca_ccs17_preprint.pdf https://crocs.fi.muni.cz/_media/public/papers/nemec_roca_ccs... Estonian ID card uses 2048 byte keys which means generating a private key from a public key takes 140.8 CPU years which is quite fast/trivial/cheap using a distributed approach (botnet, your already existing HW that you use for mining etc).. considering the implications. https://www.schneier.com/blog/archives/2017/09/security_flaw_i.html https://www.schneier.com/blog/archives/2017/09/security_flaw...
- ProblemFactory 9y ago> Estonian ID card uses 2048 byte keys which means generating a private key from a public key takes 140.8 CPU years To clarify, 2048 bit RSA keys are fine. But the smartcard that generates these used a too predictable algorithm for generating the keys.
- baccredited 9y agoestonia id card question: can ANYONE create a website that uses the card to authenticate? Or is it a estonia whitelist of services only?
- daeroth 9y agoYou can request your service to be whitelisted: https://www.sk.ee/en/services/validity-confirmation-services/?service/validity_confirmation https://www.sk.ee/en/services/validity-confirmation-services... Pricing is here: https://www.sk.ee/en/services/pricelist/certificate-validation-services https://www.sk.ee/en/services/pricelist/certificate-validati... So it's not quite as simple as Google or Facebook oAuth. But the government does support the idea that if you want then add this as a login option to your forum for dogs or an e-store for sweaters. The main value is still in the fact that the authentication gives you the ability to create legally binding contracts that get signed online.
- j_s 9y agoThis is paying for revoke checking, right? Validating the certificate the same way servers validate client certificates should be enough to verify it as a date/time-valid Estonian ID.
- AndresAlla 9y agoYes, this is to use OCSP. You do not have to pay if you download revocation lists manually. Ofcourse lists become stale rather quickly. Very basic - hello world level - implementation is as simple as enabling client certificate authentication in Apache config.
- dullgiulio 9y agoTo be precise: the system offers both identification and authentication (by using two different certificates, with two different pin codes.) Even if you don't sign-up and whitelist your service you can sign documents or verify other people documents signatures (both online or with a desktop client). There are usage quotas, though.
- askz 9y agoAnd then, we'll discover that ecdsa is also vulnerable on these chips?