EU investigating leak of private key used to forge Covid passes
bleepingcomputer.com
bleepingcomputer.com
So what’s the likely cause then? I’d guess a design flaw in the system and it leaks keys somehow.
Normally I’d say everything should be done with a hardware token that requires a physical presence, but I’m not sure how you do that at scale.
It should be noted that these certificates do contain two different country identifiers: one of which is in the signed data, and one of which is the applied signature. According to what I picked up from the thread where this issue was first reported, a significant amount of these forged certificates were signed by one country's keys, but had a different country identifier in the signed data.
It is therefore likely that, if any, only one country has had it's private key material leaked. But above compromised key materials, a more likely possibility would be compromised issuing endpoints; the infrastructure for these certificates was built and implemented in several months under high pressure to achieve, and government IT projects don't always excel in security.