4 ms·
I think that's absolutely the most likely. And it's not hundreds, it's probably more like tens of thousands (or more). For example, when I got mine issued in Ge
by tkfu 5y ago
I think that's absolutely the most likely. And it's not hundreds, it's probably more like tens of thousands (or more). For example, when I got mine issued in Germany, I just went to a pharmacy, gave them my ID and (paper) vaccination record, and the pharmacist came back in a couple of minutes with my QR code.
The interesting thing to watch, over the coming days, is this: will the public policy response do the technically correct thing, and make sure that you need all your original documentation (signed records from the doctor's office, etc.) to get your new covpass issued? Or will they do something incorrect (but easy), like let people come in with their now-invalid pass plus a government ID to get a new one issued?
- csunbird 5y agoI am not sure how the key management works, maybe they are just issuing private keys to each pharmacy, and if any pharmacy just went rogue, it should be extremely easy to know which one the certificate is coming from. Also, it is easy to get a valid vaccination code anyways, for example, I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked. The yellow booklet is easy to forge as well.
- jagger27 5y ago> maybe they are just issuing private keys to each pharmacy That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing. > I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked. This seems no different than Joe pharmacist punching in Hitler. It's still a big problem, but it's not nearly as bad as leaking the actual private key.
- csunbird 5y ago> That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing. Yeah, but if they provide an web app that can create CSRs and automatically get them signed certificates, which then can be used to create QR codes, it is easy to provide traceable individual private keys for each pharmacy. E.g. when the pharmacy logs in, they just click "Generate Credentials" button, and they are done!
- topranks 5y agoAt least for my (Irish) pass the cert is signed by the Irish Health service. So I expect each country’s national health service has been issued a key. But what mechanism for revocation might be there I’ve no idea.