The university of Giessen is providing it’s members identity services for the DFN Network (German Research Network) with a high degree of reliance called _advanced_.
This degree requires that „for identification, users must present themselves in person with an official ID. The enrolment and recruitment procedures established by the universities are considered as equivalent.“ ( see https://doku.tid.dfn.de/en:degrees_of_reliance )
It seems to me that this university’s services are a very interesting target.
I'm almost surprised they haven't gone the same route as Estonia, but there are lots of federated systems so it might just be inertia.
(a) Estonia is a very young country, so they could start from scratch
(b) Estonia has very few citizens. At a guided tour in Tallinn the guide said that many of us came from cities more populous than their country. :-)
(c) Estonia is more... adventurous in some regards. They have a National DNA Database, for example. Try selling that in the country of the Gestapo and the Stasi.
(d) But first and foremost, it is great that there is a smallish country experimenting with all kinds of new stuff. The rest of Europe will benefit a lot, just by watching them and picking some of the things they already implemented and tested.
The Gemalto overview is fantastic: https://www.gemalto.com/govt/inspired/eid-in-germany
https://www.bsi.bund.de/EN/Topics/ElectrIDDocuments/German-e...
Edit: trying to submit the Gemalto Dec 2019 update as a new story but I seem to be banned from submitting stories. Merry xmas HN.
While a lot more information would be interesting, I gather the sysadmins involved have to priotitize as they are right now. I hope that there will be an interesting post mortem, though.
In theory it should be sufficient. In practice there is very little awareness of the capabilities of these smartcards and that they could, in theory, be used as a 2FA token. These cards are mostly used for physical access control, library pass and cafeteria payment.
There's left a lot to be desired in most (german) university networks. Yes, there is usually some sort of Radius and 801.1X infrastructure in place, but it's only used for WiFi login and eduroam, not for machines plugged into wall sockets. Yes, there usually is some sort of Active Directory and/or Kerberos infrastructure in place (yes, I am aware that AD is essentially LDAP + Kerberos), but it's often used only for the student computer pools, but not office workstations.
There seems to be zero awareness, that if you have AD and/or Kerberos authentication working in place (one can only dream of it being coupled to the student / staff smartcards), you can use it GSSAPI for web single sign-on which would instantly neuter any attempts of phishing.
Also you will still often find the preconception of there being such a thing as a "secure network" and an "insecure, hostile" internet. The notion of lateral movement and treating every network segment as insecure, no matter where or how it's managed in your org, is more or less nonexisting.
When I was a student and later staff member at the Technical University of Kaiserslautern, Eduroam authentication infrastructure (801.1X) was also used to authenticate at ethernet ports in the walls of public rooms.
I have no stats on hand for this, but my work is in developing integrations towards major eID providers in Europe.
I don't see why a German university demanding the same for a comparable cryptographic certificate is bad.
It's just a plaintext password
It is a stupid law because they're being way too thorough and abrasive when they shouldn't.
How much do you wanna bet the German parliament is not protected in the same way... actually don't answer that... here's an article published today about a stupid vulnerability in the Bundestag's internal chat app: https://zero.bs/osintrecon-vs-pentestschwachstellenscan.html
Note that institutions such as ESA, CERN or the local space agencies are also involved in the network. There absolutely are very interesting targets, even if you are a state actor.