10 ms·
Reversing 'France Identité': The New French Digital ID
- tecleandor 3y agoDidn't notice it at first, but this is Ruben Santamarta's site.
- usr1106 3y agoNot a name known to me. But he seems to understand his business.
- unwind 3y agoMe neither but I don't security if I can avoid it. Here's his site, for those who don't want to do a search right now: [1]. [1]: https://www.reversemode.com/p/about-me.html https://www.reversemode.com/p/about-me.html
- usr1106 3y agoI am far from understanding the technical details. But it feels like they severly violated the rule of not running your own cryptography. If they had used TLS the MITM would have been much less likely as long as the app does not accept user-defined cerificates?
- qweqwe14 3y agoSee my comment here: https://news.ycombinator.com/item?id=37790260 https://news.ycombinator.com/item?id=37790260
- lxgr 3y agoTLS is powerful, but not a fit for literally every scenario, especially if you have more than one, possibly variably trusted entities in your protocol. That's why there are still encryption and authentication layers above TLS. One simple example are apt repositories: It's desirable to be able to host deb packages on many servers, often controlled by semi-trustworthy parties, and still allow clients to authenticate them. It would be possible to use TLS alone for package download, but that would require handing over your authentication keys to every single mirror server. So arguably, Debian did "roll their own crypto" – but it was strictly for the better.
- Nextgrid 3y agoI wonder why do they need the whole secure channel thing instead of making the card hold a client certificate and use standard mutual TLS with their backend server.
- adev_ 3y agoI would not bet on it. But there is pretty low constraints on what you can do and can not with an NFC chip. Your budget in term of compute and memory is extremely low. I would be surprised a proper RSA/ECDSA signature from an X509 certificate can hold there. Very likely I would say no. And that's why the home made crypto.
- throwaway10965 3y agoWhy not do the same thing credit cards or access smartcards do? There are many electronic ID systems in EU already and none of them have homegrown crypto...
- adev_ 3y ago> Why not do the same thing credit cards or access smartcards do? I think you would be surprised how bad the security on these systems is. The credit card security relies mainly on the ability of the bank to rollback in case of "a shit happened" and in the payment terminal itself. Probably not something you want to see to protect against identity thief nation wide. And you also can not trust individuals smartphone to do the right thing.
- nucatus 3y agoI think this is not true in most of the cases. The (security) technology behind the debit/credit cards using the SmartCard chip (IC) is pretty ubiquitous. It is the same as the security technology guarding the SIM cards in your phone and even your eSIM. Basically the protocols and the interface specifications are the same. In the end, they are just smart cards. Imagine this technology not being strong enough, because I remember the days when the security of the pre-paid public phone cards was quite rabish and any kid with some skills and knowledge could forge a card with unlimited credit. It very happens that the father of the smart card technology to be a french guy [1] and the current biggest provider of this technology is the french aero-space/defense/security company Thales Group[2] followed by another frech company called IDEMIA. There is a very nice biography of the technology [3]. [1] https://artsandculture.google.com/story/roland-moreno-s-ubiquitous-invention-archives-moreno/IgVxBPG64UEjJw?hl=en https://artsandculture.google.com/story/roland-moreno-s-ubiq... [2] https://www.thalesgroup.com/en/markets/digital-identity-and-security/technology/smart-cards-basics https://www.thalesgroup.com/en/markets/digital-identity-and-... [3] https://computer.rip/2023-09-03-plastic-money.html https://computer.rip/2023-09-03-plastic-money.html
- realusername 3y agoThe idea is terrible even from the first lines, relying on the hardware key attestation means giving up the id card to Google and Apple approved devices which is absolutely not what you want as a country.
- lxgr 3y agoI generally agree, although I do understand the motivation for requiring device attestation here: Since the card neither has a PIN pad, nor a display, there is a lot of trust on the mobile device to be honest when it comes to signature operations. Another solution would be an external, Bluetooth-connected terminal with both a PIN pad (or biometric authentication) and a display, but that would mostly defeat the purpose of using smartcards: The entire point of schemes like this is that users don't need to buy and carry yet another device beyond the smartphone and an ID card that they already own.
- realusername 3y agoWhat they probably want to know here I guess is "is this device secure?" and there's just no technical answer to that, the result of the key attestation doesn't help you one bit to decide that. The only way to do it is indeed to run some kind of computation on the device, usually those get plugged in to have more power. The key attestation has a very small list of things it's actually useful for anyways, it's generally a bad idea to use it.
- lxgr 3y agoI mean, it can, to some extent: By only accepting attestations from an opt-in list of devices that the scheme operator has validated to be sufficiently secure. That approach has a lot of downsides, obviously. Unfortunately, what I'm often seeing is a "worst of both worlds" type of solution: There is a list of trusted (used as a proxy for secure) devices, but it's generated in a pretty arbitrary way. My government actually requires FIDO attestation in such a way, but for the longest time, the only trusted hardware authenticator was by a company I've never even heard of in this space – Yubico was not considered trusted.
- louison11 3y agoDoes anyone know why a private govtech business like Palantir doesn’t take over all these use cases? Governments are notoriously bad at tech, why isn’t there a massive private corporation catering to all these use cases and ensuring state of the art security? Instead of hiring local clowns that release half baked solutions like this.
- rubenfiszel 3y agoPalantir is a particularly bad example, it being american. France care a lot about sovereignty and would never allow (and for good reasons) an external entity to have that much control. It probably did ask for a contractor on an "appel d'offre" to build this so it's the same but with a french actor.
- liotier 3y agoWe, French, do actually have seriously competent people in charge of central government IT infrastructure. Local governments not so much and that is an euphemism, but French central government doesn't cut corners about that. Also, ANSSI is among the world's best in security auditing and they take very diligently their public service role of sticking their noses into your information system if you are legally classified as an "Opérateur d'Importance Vitale". Also, f*k Palantir. No one wants such vampire squids anywhere near the crown jewels.
- possiblelion 3y agoPalantir is not trusted, at all anywhere outside the U.S.
- fmajid 3y agoIt's not trusted in the US either.
- fmajid 3y agoAlso competent technology companies like Thalès (Gemalto).
- motohagiography 3y agoThis is so good and important to show that these identity schemes are more about surveillance than security, as the security guarantees are limited and insufficient for any long period of time. An additional approach I might recommend for exploration would be to find the "offline mode," where it would have to re-use IVs and challenges over a short window when the app can't validate against the back end service. Other similar schemes I have seen implemented a single-use-key as a re-used limited-use-key to enable that use case. The card he tested was apparently live in production, but one of the main vulnerabilities in protocols like these is in the 'personalization' stage of the setup, where each card gets a set of default 'provisioning keys,' which are used to register the card and get unique user keys for it. A sample of unpersonalized blanks would yield that, and the costs associated with mitigating this with batch specific keys for provisioning is typically too much complexity. There may be a DoS vulnerability in some card schemes where you can use 'torn' NFC connections to get the key and transaction counter on the card applet to increment and desynchronize from the counter recorded on the server, bricking the card - or potentially many en masse with some SDR equipment. Given the physical user enrollment costs, there are some basic impossibilities in these protocols that will always reduce their security to a set of trade-offs that depend on economics and obscurity. Security research like this acts as a check on the efficacy of totalitarian controls like digital id, and it is important work to continually demonstrate that there are risks and costs to the regimes that impose them. I am very grateful this researcher has done work to discredit this scheme.
- mariusor 3y agoCould you please expand how any of the findings, or any attempts at digital ID are about surveillance and totalitarianism? Your post, as it is now, is brandishing big and scary words based on flimsy assumptions and without any real backup.
- motohagiography 3y agoI worked on digital identity schemes that used similar protocols to these a decade ago, and they were technologies in search of a use case because the vendors and project sponsors just wanted a mandate to implement controls nobody wanted. They're called domestic passports and a gesundheitpasses and the 20th century was defined by the regimes who implemented them. Identity and cryptography are areas where technologists cannot avoid moral culpability for their design and implementation decisions. This area is as real as it gets. Those big scary words are technical terms of art in political science (defined by Arendt), and people who actually work in privacy and identity to ensure these technologies are not exploited by governments to abuse citizens, are engaged in the real work of governance. Part of that is demonstrating how even governments are bound by the laws of math and accountable to reason. I also understand how smaller words could be more broadly persuasive.
- danwee 3y agoNoob question: why don't governments issue a private key to every citizen so that they can identify themselves "easily" in web forms and the like? The government would keep the corresponding public key. You could go in person to any government building and request a new private key to override the previous one if needed.
- runeks 3y agoDid you mean "why doesn't the government allow every citizen to register a set of public keys for identification purposes"? The citizens obviously wouldn't want the government generating their private keys. Because then it wouldn't be a private key any more.
- workfromspace 3y agoEstonia has been doing this for a long time now with their ID cards. It can be extended to sim-based (mobile ID) or device/app based (smart ID) key pairs as well. It's not just for the citizens but all residency cards and e-residency works this way, too.
- PeterisP 3y agoBecause securely storing the keys is quite difficult, and the whole system doesn't work if the keys are routinely compromised ("You could go in person to any government building and request a new private key to override the previous one if needed." doesn't cut it) - so the only reasonable way of issuing such private keys would be on a smartcard where it's reasonably difficult to extract/copy, and you could know if the actual card was lost.
- BrandoElFollito 3y agoI cannot understand, seriously, how we could have built a system where you have to have French documents in order to identify yourself to various services. A friend's of mine dad is Polish. He is retired and worked for years in France. Now he cannot access all of his retirement data because some sites require France Connect and he does not have any French papers anymore. When asked about that, France Connect's support basically replied "fuck you" (in French). There must be thousands of people in his situation and yet, nobody cares.
- CogitoCogito 3y agoThere are similar hassles in Sweden with their BankID for people who can't get it, but have connections to Sweden one way or another. Swedish bureaucracy works quite well if you fit the mold, but can be totally useless if you don't. I think the issue is that as long as enough of the "normal" population thinks it work, no one really cares about those it doesn't work for.
- BrandoElFollito 3y agoThis is exactly the same in France. The system is fine when you are in the mold as you are saying. It is at least much better than in the recent past. Another aspect of French bureaucracy is that it becomes fuzzy when you are dealing at a more local level. Say you want to get a library card for which you have to show proof that you live in the city. I did not have mine handy, and after a lengthy exchange of gazes and after everyone has done "pfffff", "hmmmmm", they got a form from a drawer on wich you could state on your honor that you live there. Lots of foreigners are rebutted after an initial no, when it is sometimes just an invitation to a longer exchnage.