17 ms·
I faked tons of Covid passes – “Weak Key Cryptography in real world”
- gaius_baltar 5y agoRandom question, but related: Like this example, I see lots of other applications that require a QR code storing binary data and chose to encoded this data as Base64 (or others) and then add it to a ASCII-only QR code format. Why don't they use a binary-mode QR code? Compatibility?
- sgtnoodle 5y agoPerhaps so that generic QR code scanners can parse it and then know to forward it along to the appropriate app?
- dmurray 5y agoAlmost always technical incompetence, I think. At some level "compatibility" is correct. System 1 outputs binary data, system 2 takes that and turns it into JSON, system 3 encodes that in base64, system 4 turns that into QR codes, and system 4 was what was mandated for producing all of the organisation's QR codes.
- umurkontaci 5y ago> The reason for representing Health Cards using Numeric Mode QRs instead of Binary Mode (Latin-1) QRs is information density: with Numeric Mode, 20% more data can fit in a given QR, vs Binary Mode. This is because the JWS character set conveys only log_2(65) bits per character (~6 bits); binary encoding requires log_2(256) bits per character (8 bits), which means ~2 wasted bits per character https://spec.smarthealth.cards/#encoding-chunks-as-qr-codes https://spec.smarthealth.cards/#encoding-chunks-as-qr-codes
- Dylan16807 5y agoWhoever wrote this makes my head hurt. If you were using binary storage, you wouldn't use "the JWS character set" (aka base64). You'd store it directly and have 0 wasted bits. Also, they're not acknowledging the bits wasted by their current system. Numeric mode in QR codes spends 3.33 bits per digit. At two digits per character, they're spending 6.67 bits to store only 6 bits of information.
- zirror 5y agoThe EU's Digital Green Certificate [1] uses Base45, which I think they basically invented. They do this because "even in Byte mode a typical QR-code reader tries to interpret a byte sequence as a UTF-8 or ISO/IEC 8859-1 encoded text."[2] They use the 45 chars allowed by the alphanumeric-mode IIRC. [1]: https://github.com/eu-digital-green-certificates/dgc-overview https://github.com/eu-digital-green-certificates/dgc-overvie... [2]: https://datatracker.ietf.org/doc/draft-faltstrom-base45/ https://datatracker.ietf.org/doc/draft-faltstrom-base45/
- Dylan16807 5y agoWait, why are they using 45 characters to encode 16 bits when you only need 41? Especially when they could have avoided % and space.
- zirror 5y agoWell, tbh, I don't know the reason, I can only speculate. It is meant to encode pure binary data (cbor) and not to be human readable or URI or anything like that. It is specifically designed for QR Codes. I read through some Github issue [1] just now and as far as I can tell, it is more or less a design oversight, which might be remedied by a later version. [1]: https://github.com/ehn-dcc-development/hcert-spec/issues/64 https://github.com/ehn-dcc-development/hcert-spec/issues/64
- Dylan16807 5y ago> It is meant to encode pure binary data (cbor) and not to be human readable or URI or anything like that. Well the reason to care is to avoid QR decoder quirkiness, otherwise you should probably just use the binary encoding. > I read through some Github issue [1] According to a comment near they end they were originally going to try to pack everything as a single base 45 bignum, so that half explains it. But not why they'd stick with 45 characters when changing that.
- gnabgib 5y agoIt's a weird situation, but it's very obvious with HC1 and SHC cards. It starts with JWT. JSON is a human readable format (in utf-8), if humans don't need to read, the data could be binary, and the format could be exact. JSON isn't an exact spec, which is mostly inherited from JavaScript (there's no such thing as an integer only floating point, so 1e3==1000==1000.0==1.00e3 in human-readable form, as a stored number they are identical). Then there's differences in white-space (new lines, indentation) - although this could likely be overcome with convention. Because of this the JWT creators said instead of signing the data, we'll sign the exact representation in the payload - but of course with white-space and formatting variance (including a deserialize/serialize loops changing representations, or - in the case of bearer tokens, the HTTP spec allowing newlines/white space to be inserted at the protocol level) they had to encode it as non-human readable (base64). Now everyone agrees you're signing that exact Base64 representation of the JSON object. But! We've build a(n arguably verbose) human readable format that isn't readable by humans. The SHC spec (common in North America) actually holds a JWT that's signed by an elliptic curve private key. You can validate the signature with a public key. The public/private choice here is great, the JWT is terrible.. they've doubled down on the mistakes. Further to keep the QR smallish, they zipped the payload portion (which is supported by JWT - this is done before the base64 stage), and use only the minimum QR resilience setting (which is fine if it's on a screen, if it's printed this may lead to reading problems). Now we have human readable (JSON) compressed in machine readable (deflate) in machine readable (base 64) in machine readable (QR) - for machine reading purposes. They didn't even trim the fluff (every SHC begins with 56 because.. you guessed it, the `{` character), or use sensible choices (they don't use IssuedAt/iat, but NotBefore/nbf to indicate the generation date). Anyway, SHC (reasonably) noticed because of the (mostly) base64 encoding the character set is only 64 characters (6 bits) which doesn't use the ASCII space (7 bits) very well, so they store the first 'shc://' in ASCII and the rest is a number (there are three modes in QR: ASCII, binary, numeric - the density loosely matches binary representations - a numeric digit (0-9) takes 4 bits, ascii char takes 7 and binary takes 8). ASCII doesn't support the world very well, UTF8 isn't supported by QR (except as binary). In the SHC case, because it's signing a specific format/output of the JSON data, it doesn't have the white-space formatting concerns that JWTs have to overcome. If they wanted to stick with a JWT like format (JSON object), they could have skipped the base64 before sign step, at which point they might as well get rid of the header (we're no longer to JWT spec), deflate the message to be signed, and put the signature after the deflated message. All the same data, less of the overhead, and better use of the binary space.
- TechBro8615 5y agoThe most common reason is probably because it’s easier to develop, debug and test code that outputs ASCII strings rather than binary blobs.
- jsiepkes 5y ago> we found all hard-coded Public keys were using RSA 512 > Next, the data was hashed using a custom hashing algorithm developed by lachongtech. Yeahhhh.....soooo.......
- slownews45 5y agoShort version if they get taken down: The validation apps used a 512 bit RSA public key. They used a factoring app and spend $200 on amazon to factor the private key from the public key. They were then able to generate the COVID passes. This is for the Honai Police Dept.
- akomtu 5y agoWhy would anyone use RSA when we have X25519?
- stonewareslord 5y agoThe real question is why use 512 bit RSA when you can use 2048+?
- mastax 5y agoSo it can fit on a reasonably sized QR code probably.
- est31 5y agoKey size determines number of bytes the signature takes up, which is one of the determinants of the complexity of a QR code. I suppose if you don't know what you are doing, and want to reduce QR code complexity, you lower the key size. To turn up speculation to 100, this might also be a third world issue, because here in the west we have high quality smartphones with good cameras, but the smartphone cameras there might not be as good, so they might be challenged reading QR codes. 8 years ago I built a thing that had customized links accessible via QR codes, but my buddy's cheap phone couldn't read them due to issues with the camera resolution. A lot has happened in 8 years in terms of progress, but they still put crappy cameras into cheaper phones, and this might still pose a problem for reading complex QR codes.
- dundarious 5y agoTake a look at QR image in the post. I haven't seen a QR code in the first world that carries more data, especially not a printed one. It's doubtful they're optimizing for poor cameras or printers any more than is done in the first world, and to be clear, in the first world we still have to optimize for poor cameras and printers. Decreasing the message size while improving security would obviously be ideal and most likely quite achievable, but there are plenty of wealthy municipalities in the US who don't exactly cover themselves in honor in similar situations. While I'm not at all saying it's illegitimate to speculate on wealth disparities as a cause, in this case I think it's lazy to call this a "third world issue", even with speculation up to 100.
- muterad_murilax 5y agoAnyone knows if this is applicable to Covid passes used in the European Union as well?
- jinpa_zangpo 5y agoThe private keys for the European Green Pass have been leaked and fake passes signed with the keys are being sold on the dark web. https://threatpost.com/eus-green-pass-vaccination-id-private-key-leaked/175857/ https://threatpost.com/eus-green-pass-vaccination-id-private...
- stavros 5y agoThey haven't been revoked yet?
- acqbu 5y agoSome have, but not all... yet.
- CorrectHorseBat 5y ago>UPDATE: French & Polish authorities found no sign of cryptographic compromise in the leak of the private key used to sign the vaccine passports and to create fake passes for Mickey Mouse and Adolf Hitler, et al. Afaik it was a leaked login, not a leak of the keys.
- jokethrowaway 5y agoShouldn't they have a record of all the things they signed? I would expect them to know where and when that Adolf pass was generated
- lucb1e 5y agoAh yes, repeat the evil dark web narrative. As if a VPS in Russia would get you into trouble. Criminals will be criminals, also if tor etc. wouldn't exist and non-criminals wouldn't get to be anonymous, too.
- johnchristopher 5y ago> Although the code was provided, we took around 2 days to get this running since the code was written back in 2015. Some libraries are not currently supported forced us to make several changes on the code. The project was then running smoothly. Why not use a VM with older libraries and tools ?
- fouc 5y agoLooks like the source code is meant for Amazon's EC2, so it was depending on the python/libraries on the EC2 back then, 5-6 years ago.
- josefx 5y ago> 5-6 years ago. Why does it still surprise me that that most software companies treat backwards compatibility as a joke?
- johnchristopher 5y agoDoh, of course. Thanks :).
- yissp 5y agoI remember here in Canada there were concerns about this sort of thing when rolling out our proof-of-vaccination system, but practically speaking, the number of people with both the technical understanding and inclination to do this is surely too small to have a meaningful impact on COVID spread.
- sushsjsuauahab 5y agoIt seems that actually nothing has had a meaningful impact on coronavirus spread.
- JumpCrisscross 5y ago> seems…nothing has had a meaningful impact on coronavirus spread Not sure if trolling, but in case not, vaccination has had “a substantial impact on mitigating COVID-19 outbreaks” in America [1]. [1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7709178/ https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7709178/
- sgtnoodle 5y agoThe link you provided describes a simulation based on assumed vaccine effectiveness. It's also from 1 year ago. It doesn't seem to reflect any statistically backed insights into what's actually happened over the past year. Or am I missing something?
- sgtnoodle 5y agoTrying to find some actual data, I googled "covid deaths by month" and I stumbled upon this: https://www.worldometers.info/coronavirus/coronavirus-death-toll/ https://www.worldometers.info/coronavirus/coronavirus-death-... Notably, the "Growth Factor" plot looks qualitatively very similar from April 2020 until now. Before then, the data looks more noisy to me but not necessarily different on average. I believe folk started getting vaccinated in December 2020? Based on that plot, it doesn't look like the vaccine is helping much for the death rate. Maybe that data source is not legitimate, or maybe "growth factor" isn't the right metric to look at?
- tehjoker 5y agolmao we use pieces of paper with no safeguards, even with a cryptographic break Hanoi is leagues ahead of us
- acqbu 5y agoWell done, great job!
- deleted 5y ago[deleted]
- coolso 5y agoGood! Keep it up. Let things be, enough of this vaccine pass comrade BS. We who are vaccinated should be at peace and trust this vaccine will reduce the likelihood of severe illness. Those who aren’t, I wish them the best, but that’s their choice. Hopefully this will finally encourage smokers to quit and the obese to cut out a few sodas per day.
- dvt 5y ago> Good! Keep it up. Let things be, enough of this vaccine pass comrade BS. You're going to get heavily downvoted, but I totally agree. The vaccine pass is a complete farce. I even have non-technical friends that have faked vaccine passes. For someone even remotely technical, it's trivial to Photoshop. If only we had the same fervor when it comes to demonizing weight gain, we could save 10x more lives.
- asddubs 5y agoweight gain isn't contagious
- dvt 5y agoActually, it is, as it tends to be intergenerational[1]. Parents that don't care about their health will raise kids that don't care about their health. [1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5305001/ https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5305001/
- coolso 5y agoFurthermore, even outside of an immediate family, the more overweight people are, the more socially acceptable it becomes, resulting in more obesity. There’s also the massive costs to our healthcare system and insurance premiums.
- threeseed 5y agoAnd yet obesity whilst being a problem for decades has not caused an epidemic of obese people. Why is that ? Because obesity is not contagious and most people don't make decisions about what they eat and their activity levels based on choices other people make.
- pier25 5y agoHere in Mexico the gov issued vaccination certificates always have errors. People have resorted to downloading the PDF and "hacking it" (editing it in Acrobat). Nobody ever actually checks whether the certificate is valid or not.
- galaxyLogic 5y agoI think most people who are smart enough to fake the certificate are smart enough to get vaccinated. What do you win by using a fake certificate vs. getting protected by the vaccine?
- golemiprague 5y agoI know many educated and smart people who are anti vaccine, including doctors, some of them got fake certificates and that is in a modern western country. Nobody is checking it properly, they just see the green colour and let you in, nobody even compare the name to some ID. So the benefit is to get into places they couldn't get into without the vaccine.
- pawelmurias 5y agoYou can sell fake ones to retards who are scared of the vaccine. Some might be stupid enough to pay good money for it.
- artursapek 5y agoThis is disrespectful to the countless people who have suffered injuries and death from the covid vaccine.
- roca 5y agoPlease don't bring your antivaxxer lies here. The documented rates of injury/death caused by the major vaccines are incredibly low.
- pier25 5y ago
- t0bia_s 5y agoIt is easier to find someone who give you just papers and flush your dose out. But anyway... Proof of anything based on digital ID is pointless and should be abandoned as soon as possible.
- bigodbiel 5y agoSecurity theatre, like washing streets with chlorine solution
- bellyfullofbac 5y agohttps://www.nytimes.com/2021/05/07/opinion/coronavirus-airborne-transmission.html https://www.nytimes.com/2021/05/07/opinion/coronavirus-airbo... In hindsight, the washing was overreaction, but you do have to realize there wasn't enough knowledge in the beginning, and people were assuming the virus was like the influenza virus, and we usually (at least the common wisdom was) catch influenza through touching snot-laden surfaces. It didn't help when China was saying things like they found some viruses on surfaces after 3 days. Sure, but how much virus, i.e. would they be enough to make you sick? The lack of information also made the virus like a super monster, where any trace of it could be deadly... Now that we've figured out the virus is airborne, I'm a bit disappointed that governments haven't focused on good ventilation, but still on disinfecting and keeping distance. Where I live the bus can be full of people but it seems the governments are saying "It'll be fine to sit so close to each other if you have a mask on", and people also don't know any better...
- t0bia_s 5y agoI remember early articles about how long virus stay on different surfaces. 30 days on metal, 20 days on plastic, 10 days on wood, etc. Also governments tried to convince as that we should wear masks alone in woods or cannot go out in night. Same governments told us that vaccination end spreading virus. It was all lies but still most people believe those lies because propaganda of fear is strong. Today... We still don't know origin of virus. Seriously, this is total resignation on common sense, science, logic, rationalism, etc. It is all about emotions and feelings.
- questiondev 5y agodoes not surprise me, in the future there will only be two governments in the world, polarization will become the norm. each party will think they are right. it will be an umbrella me echo chamber. but it will only exist online. it will manifest in real life but people who dare or who are brave enough to understand someone outside of their comfort zone will quickly realize that we are not 1’s and 0’s within a machine.
- airesearcher 5y agoPhysical Covid certificates are also not secure at all. They are easy to copy or fake. Any scheme which simply puts a cryptographic number on a some Physical card - or behind a regular QR is not secure. A simple photocopy will work just as well as the original. Not to mention Photoshop. But there is actually a new way to make physical things - like printed Covid vaccination cards - provably unique and authentic. Much more powerful than holograms and also much more secure, unclonable and authenticatable. Take a look at Blocktag (blocktag dot com) - Next gen QR codes that anyone can print, yet cannot be counterfeited. And of course linked to blockchain and ready for physical NFTs too.
- heinrich5991 5y agoThe QR codes in Germany include your name and a digital signature. You can photocopy them, but the photocopy doesn't work for another person (if the venues would actually ask for your ID).
- Jenda_ 5y agoThere is another problem even after asking for your ID - how can they verify it's you (based on the photo on the ID) when you have a face mask?
- sofixa 5y agoThey ask you to take it down momentarily to check your face. Come on now, a kid could have thought of that and it has been used for months ( just go to an airport or whatever).
- jazzyjackson 5y agousa has a real problem with this, afaik there is no way to get a duplicate/back up of your hard copy vaccination record. so i’m supposed to carry a piece of paper with me, and not lose it, i guess that’s what makes it a passport. meanwhile ime most places with vaccine requirement accept a photo on my cell phone - not exactly cryptographically signed stuff over here.
- jgeralnik 5y agoThe author went out of their way to hide the factors of N, presumably so that nobody else would actually be able to generate signed certificates. However, they did this by hiding half the digits of the factors. Revealing so many digits of the factors actually allows easily factoring the original number using a version of coppersmith's method (easy as in under a second on my laptop instead of the 9 hours on a distributed cluster the authors used). This is actually a pretty classic CTF exercise. If I'm still nerdsniped by this tomorrow I'll try my hand at implementing this and factoring the number myself
- DavidHilbert 5y agolooks like there are more digits cropped out so it's going to make it a lot harder since you won't know which bits you have
- dzhiurgis 5y agoOffline first seems such an oversight from contact tracing perspective. Also NFC tags could’ve been better solution, but probably would’ve sent too much Bill Gates vibes.
- crocodiletears 5y agoFrom what I've been able to gather, these QR code systems are mostly based off of the WEF's Commonpass digitial identity standard (either directly, or inspired by), which seems to be a graduated version of the ID2020 project (many of the same ideas and sponsors). The projects are meant to present a standardized format for the provision of easily validated information about an individual in environments where low-end hardware is common and internet connectivity is unreliable. The QR code was chosen as the standard form of information transfer because it can be printed on paper and remain easily validated if someone lacks a device to put it on. The codes aren't primarily meant to control pandemic spread, this just happens to be the first thing driving their widespread adoption.
- dzhiurgis 5y agoCredit cards are widespread (esp in places that bother with covid passes) and where I live something like 90% of payments are contactless. Takes about 5 seconds. Cynic in me says - just disable cards for the unvacced at specific venues…
- mensetmanusman 5y agoI wonder if these tools will be required after the pandemic to only offer services and entry to citizens with documentation.
- dlsa 5y agoThis kind of breach isn't possible in Australia since their laws can beat the laws of math. Countries with less powerful laws are apparently not so lucky. https://www.gizmodo.com.au/2017/07/prime-minister-says-the-laws-of-australia-can-beat-the-laws-of-math/ https://www.gizmodo.com.au/2017/07/prime-minister-says-the-l... (Yeah, tongue firmly in cheek. Laws of math oddly enough seem to work just fine for taxation, depreciation, etc etc)
- jimmydorry 5y agoIt's unfortunate that we've had successive governments (both sides) attacking privacy and security. From a casual glance, it looks to be done out of incompetence, when you see such headlines. But boy is that a long streak of coincidences.
- Perenti 5y agoSadly, it seems to be power for the sake of power. I've been involved with a few govt green papers over the last 20 years, and most of the proposals are about bureaucrats extending their reach. It's why I vote Green now, as both Labor and Liberal have become so focused on preserving their power that they ignore the Rest Of The World and The Science. For non-Australians, our Liberals are your Republicans, with all their faults, and our Labor is your Democrats, with all their faults. Our Greens seem to have broadened their platform to include social justice and true libertarianism, so they're no _as_ powerhungry.
- hiisukun 5y agoNot sure if you're aware, but the Aussie covid vaccination "certificate" from the government App uses a "digital hologram" to prevent forgery. It's essentially an animated gif.
- dlsa 5y agoUnfortunately the governments implementing these measures seem absolutely determined to treat Orwell's 1984 as a training or howto manual. As we descend further into authoritarianism, tracking and other privacy busting measures will become even more normalised and entrenched. You'll soon need to show identity and other papers to get into a shop to buy a hammer.
- m0zg 5y agoIn Russia (and I suspect much of the rest of the world) you don't need to fake anything. You pay off the doctor and get a shot of saline instead, along with a totally valid record in the government DB. They catch them from time to time, but doctors there are paid laughably little money (as in nearly all countries with fully socialized medicine), so they do what they can to get by. Price of admission is between 3000 and 15000 rubles ($40-200) depending on where you are.
- IngvarLynn 5y agoHere is how government-issued QR codes (not only vaccination ones) works in my country: it's just a link to government site. Why reinvent crypto, PKI and all? Also solves updates/invalidation issues.
- infotogivenm 5y agoIf you want to minimize the time people spent waiting in queue to have these passes scanned, an offline validation method makes a lot of sense. Also optimizes time spent in queue while site is down or overloaded.
- Jenda_ 5y agoOffline method also helps with privacy, as there is no central online database where the validation requests can be observed.
- saurik 5y agoReal talk: are people saying they wanted this to be secure? If we are going to do this "vaccine paperwork to do anything" regime, I wouldn't want it to be some super secure mechanism that had digital proof of personhood provided by some government entity with an unhackable key! This key size frankly seems like the perfect balance: it took some months for someone to get around to breaking it, and then it took some months for a service that used that cracked key to become popular enough to make a real impact on safety, and maybe maybe just maybe soon we won't need this anymore, and none of these existing digital records will be trustable... and, if we are stuck doing this for another year, we should roll another weak key. (If nothing else, if you make an actually secure mechanism that ties a person to their vaccine record with a signature, you just know that tomorrow some WorldCoin-like company is going to try to use it for some stupid crypto "airdrop" ;P.)
- barbazoo 5y agoWhy though when it's very little effort to use a stronger key? What's the downside?
- walterbell 5y agoDystopian sci-fi is for mental immunization, not emulation.
- closeparen 5y agoDystopian sci-fi is when carefully crafted internet memes convince people to kill themselves and each other en masse. We're well past that point.
- barbazoo 5y agoWhat do you mean by that?
- godmode2019 5y agoHere is the New Zealand version - https://nzcp.covid19.health.nz/#examples https://nzcp.covid19.health.nz/#examples