North Macedonia did not safeguard the signing key properly and it got leaked?
North Macedonia did not safeguard the signing key properly and it got leaked?
What happened is that North Macedonia (among other countries [1]) was running a public facing and without authentication (or w/ hard coded credentials) server used as a frontend to generate the COVID-19 certificates for their country.
You can follow the discussion here [2] and read my comment [3] here.
On top of that, you can follow my analysis on this repo (RESULTS.md contains the generated results) [4].
[1]: https://sizeof.cat/post/private-keys-sign-eu-greenpass-leake...
[2]: https://github.com/ehn-dcc-development/hcert-spec/issues/103
[3]: https://github.com/ehn-dcc-development/hcert-spec/issues/103...