4 ms·
> maybe they are just issuing private keys to each pharmacy That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data
by jagger27 5y ago
> maybe they are just issuing private keys to each pharmacy
That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing.
> I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked.
This seems no different than Joe pharmacist punching in Hitler. It's still a big problem, but it's not nearly as bad as leaking the actual private key.
- csunbird 5y ago> That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing. Yeah, but if they provide an web app that can create CSRs and automatically get them signed certificates, which then can be used to create QR codes, it is easy to provide traceable individual private keys for each pharmacy. E.g. when the pharmacy logs in, they just click "Generate Credentials" button, and they are done!