3 ms·
I suppose the Estonians are partially at fault for trusting Gemalto with anything, post Snowden.
by willsr 8y ago
I suppose the Estonians are partially at fault for trusting Gemalto with anything, post Snowden.
- Xylakant 8y agoThe article stipulates that the contract dates back until 2002, about 11 years before the Snowden allegations came to light. So while they could have switched afterwards, the contract may have had a longer contract period, locking them in for a while. You also can’t just switch the identity provider for your national ID system, such a move would need at least some lead time.
- pisipisipisi 8y agoThe contract has been renewed several times, IIRC 2006 and 2010 Reference: (in Estonian) https://tehnika.postimees.ee/4358415/gemalto-kaebus-politsei-id-kaardi-hanke-vastu-porus-kohtus https://tehnika.postimees.ee/4358415/gemalto-kaebus-politsei...
- gmueckl 8y agoThat was all well before the Snowden relevations.
- dullgiulio 8y agoNothing to do with Snowden revelations, but with RSA prime number generation. Because of a bug on the chip, primes were generated starting from numbers divisble by ten, which are way rarer than those divisble by two (pardon the extreme simplification.) That's a hardware design error. The claim is that Gemalto failed to fullfil the contractual clauses about quickly informing the customer (the Estonian state) of the security breach, not the existance of the security breach itself.
- anemic 8y agoWell, there was this revelation that NSA had the 'Gemalto network wide open'. After week long investigation Gemalto denied any breach, leading to situation where you could either believe NSA or Gemalto. https://www.wired.com/2015/02/gemalto-confirms-hacked-insists-nsa-didnt-get-crypto-keys/ https://www.wired.com/2015/02/gemalto-confirms-hacked-insist...
- IndrekR 8y agoI believe it is not a design error. It rahter sounds like an incorrectly implemented manufacturing optimisation. And in that sense close to the Volkswagen diesel-test optimisation -- compromising the reason for the RNG/exhaust test in the first place.
- kodablah 8y agoSeems related if they trusted an untrustworthy company to inform them.
- the_clarence 8y agoGemalto is french.
- jaclaz 8y agoNot Franco-Dutch as stated in the article?
- TazeTSchnitzel 8y agoGemalto issues all of Sweden's forms of state ID right now, the NSA must be laughing.
- pisipisipisi 8y agoThe problem is mandatory blind trust in single entity, be it Gemalto or Oberthur or NSA^H^HIST. Same issue with CA-s.
- y04nn 8y agoExactly, this crazy to think you can keep you sovereignty while giving to a foreign (French), NSA/CIA infiltrated (In-Q-Tel/Snowden) company the keys to all your citizens ID, moreover with internet voting. While ahead of its time, maximum caution must be taken, and the balance must be made between convenience and independence.
- dfox 8y agoIn fact the root cause of the flaw is in the attempt to make the keys inaccessible to any single entity by generating them on the card. This needs the card to have circuitry and software to generate RSA primes and some reliable source of entropy, both of which are somewhat non-trivial problems (as in easy to subtly screw up) in the smartcard environment.