3 ms·
There is talk that private keys have been compromised and people were getting fake vaccination certificates. North Macedonia did not safeguard the signing key
by aritmo 5y ago
There is talk that private keys have been compromised and people were getting fake vaccination certificates.
North Macedonia did not safeguard the signing key properly and it got leaked?
- denysvitali 5y agoThe private keys didn't leak (at least publicly). What happened is that North Macedonia (among other countries [1]) was running a public facing and without authentication (or w/ hard coded credentials) server used as a frontend to generate the COVID-19 certificates for their country. You can follow the discussion here [2] and read my comment [3] here. On top of that, you can follow my analysis on this repo (RESULTS.md contains the generated results) [4]. [1]: https://sizeof.cat/post/private-keys-sign-eu-greenpass-leaked/ https://sizeof.cat/post/private-keys-sign-eu-greenpass-leake... [2]: https://github.com/ehn-dcc-development/hcert-spec/issues/103 https://github.com/ehn-dcc-development/hcert-spec/issues/103 [3]: https://github.com/ehn-dcc-development/hcert-spec/issues/103#issuecomment-953382640 https://github.com/ehn-dcc-development/hcert-spec/issues/103... [4]: https://github.com/denysvitali/covid-cert-analysis https://github.com/denysvitali/covid-cert-analysis