I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.
I find it more likely there's an option to enter custom data for non-citizens and someone was just messing around.
The interesting thing to watch, over the coming days, is this: will the public policy response do the technically correct thing, and make sure that you need all your original documentation (signed records from the doctor's office, etc.) to get your new covpass issued? Or will they do something incorrect (but easy), like let people come in with their now-invalid pass plus a government ID to get a new one issued?
Also, it is easy to get a valid vaccination code anyways, for example, I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked. The yellow booklet is easy to forge as well.
That seems too complicated for every single pharmacy in Europe. I bet they just punch in some data to a web app and it does the actual cryptographic signing.
> I took a friend of mine, who was vaccinated out of EU, to a pharmacy and nicely asked if he can have a certificate for travel. They just glanced at the his vaccination dates and gave us qr codes, no questions asked.
This seems no different than Joe pharmacist punching in Hitler. It's still a big problem, but it's not nearly as bad as leaking the actual private key.
Yeah, but if they provide an web app that can create CSRs and automatically get them signed certificates, which then can be used to create QR codes, it is easy to provide traceable individual private keys for each pharmacy. E.g. when the pharmacy logs in, they just click "Generate Credentials" button, and they are done!
So I expect each country’s national health service has been issued a key. But what mechanism for revocation might be there I’ve no idea.
Certainly if you have a private key and you want to prove that you know the key, you can trivially make documents that only somebody with the key could make, that aren't documents any system would give people who don't have the key and yet also aren't useful fictitious documents if you're acting as a whistleblower.
That's what was done when a certificate reseller emailed the private keys of their customers to the CA they were reselling - for some reason that's unclear. The CA minted CSRs that showed they now knew the private key, without revealing what it is, and so we could all see that yup, somebody sent this CA the private keys, game over for those certificates.
[ PSA: They're called private keys, not secret keys or shared keys for a reason. Where possible you should choose your own private keys randomly and never reveal them to anybody ]