I faked tons of Covid passes – “Weak Key Cryptography in real world”
ctrsec.io
ctrsec.io
Revealing so many digits of the factors actually allows easily factoring the original number using a version of coppersmith's method (easy as in under a second on my laptop instead of the 9 hours on a distributed cluster the authors used). This is actually a pretty classic CTF exercise.
If I'm still nerdsniped by this tomorrow I'll try my hand at implementing this and factoring the number myself
The validation apps used a 512 bit RSA public key.
They used a factoring app and spend $200 on amazon to factor the private key from the public key.
They were then able to generate the COVID passes.
This is for the Honai Police Dept.
To turn up speculation to 100, this might also be a third world issue, because here in the west we have high quality smartphones with good cameras, but the smartphone cameras there might not be as good, so they might be challenged reading QR codes. 8 years ago I built a thing that had customized links accessible via QR codes, but my buddy's cheap phone couldn't read them due to issues with the camera resolution. A lot has happened in 8 years in terms of progress, but they still put crappy cameras into cheaper phones, and this might still pose a problem for reading complex QR codes.
Decreasing the message size while improving security would obviously be ideal and most likely quite achievable, but there are plenty of wealthy municipalities in the US who don't exactly cover themselves in honor in similar situations.
While I'm not at all saying it's illegitimate to speculate on wealth disparities as a cause, in this case I think it's lazy to call this a "third world issue", even with speculation up to 100.
When I was vaccinated, I was given an A4 sheet with those QR codes on it, and I really wouldn't want to scan those with a crappy camera.
[0]: https://gir.st/blog/greenpass.html [1]: https://ec.europa.eu/health/sites/default/files/ehealth/docs... § 4.2.2
Primary Algorithm: The primary algorithm is Elliptic Curve Digital Signature Algorithm (ECDSA) as defined in (ISO/IEC 14888–3:2006) section 2.3, using the P–256 parameters as defined in appendix D (D.1.2.3) of (FIPS PUB 186–4) in combination the SHA–256 hash algorithm as defined in (ISO/IEC 10118–3:2004) function 4. This corresponds to the COSE algorithm parameter ES256.
Secondary Algorithm: The secondary algorithm is RSASSA-PSS as defined in (RFC 8230) with a modulus of 2048 bits in combination with the SHA–256 hash algorithm as defined in (ISO/IEC 10118–3:2004) function 4.
So not exactly 512 bit RSA.
Here is the nz version
Longer keylengths make it difficult to deliver sufficient payload in a QR. not sure about EU, but the SMART health passes that are the emerging standard use ES256 signatures.
The lack of global leadership for interoperable standards early on made this more difficult. You had the EU, Israel, US states and others who were ahead of the curve, but that approach had limits that were reached.
Now in the US we also have the issue of dealing with states with wacky political stances. States like California, New York and Louisiana, combined with private sector leaders like Walmart and Epic made SMART the defacto US standard, and other countries are recognizing them.
RSA 512-bits key was proven breakable years ago
Even so, I am amazed they were able to break it so quickly and cheaply.*Hanoi
https://www.gizmodo.com.au/2017/07/prime-minister-says-the-l...
(Yeah, tongue firmly in cheek. Laws of math oddly enough seem to work just fine for taxation, depreciation, etc etc)
For non-Australians, our Liberals are your Republicans, with all their faults, and our Labor is your Democrats, with all their faults.
Our Greens seem to have broadened their platform to include social justice and true libertarianism, so they're no _as_ powerhungry.
It's essentially an animated gif.
These vaccination cards are totally unprecedented[1] and authoritarian. Oceania had always been at war with Eastasia.
[1] https://www.kxan.com/wp-content/uploads/sites/40/2021/04/yel...
I'd point at the war-on-terror as a good example of a permanent or equivalent always-at-war situation. Its not a stretch to suggest that a lot of the privacy and surveillance is based around anti-terrorism initiatives and plenty of security theater is now in place because of that. The war-on-drugs was another version of that. The war-on-... rhetoric in general is almost cliché now. This is not to say its not serious but consider the 1970s had quite a lot of terrorism going on. eg The UK had regular bombings from the IRA.
Political correctness tends to adjust definitions in ways very reminiscent of Double-speak. It seems to be a rich source of new words and terms. Like a conveyor belt.
The surveillance aspect is obvious.
Why do people always have to jump to the slippery slope fallacy when anything happens? It's good to be cautious, but you're taking it to paranoia level.
People have resorted to downloading the PDF and "hacking it" (editing it in Acrobat).
Nobody ever actually checks whether the certificate is valid or not.
What do you win by using a fake certificate vs. getting protected by the vaccine?
Their skepticism is far more nuanced, and evidence based, than the "All vaccines are poison/bill gates gonna 5G us!" covid vaccine skepticism is usually framed as.
They do not oppose any other common sense measures, like mask wearing, they simply want to be careful about vaccines that have been pushed to markets in record times on very questionable, mostly political, narratives.
Like vaccines allegedly saving us with "heard immunity" when most people familiar with the topic knew very well how that was extremely unlikely to happen.
I wonder what kind of "smart" person ignores this evidence and puts their life at risk at will? Hey my chance of dying from Covid is 10 times bigger because I don't get vaccinated, but I won't because I believe an even worse fate awaits me if I do. What do they think that worse fate is?
About the vaccine not giving us herd-immunity, of course it doesn't if the herd refuses to get vaccinated.
https://ourworldindata.org/grapher/united-states-rates-of-co...
I'm not vaccinated. I did get Covid-19 and recovered well. The only lasting effect seems to be that I smell an anti-freeze odor at times. I don't feel like I was putting my life at risk by not getting vaccinated, in fact, I feel even more strongly against getting a vaccine that appears to be more beneficial to those who are at high risk of severe symptoms and/or death than the general population.
In any case, I respect others' opinions on the matter and don't judge them for their decisions on vaccination. The fact that vaccinated people can still get infected and possibly transmit the virus to others seems to indicate we should stop focussing on a general solution and focus on those in high risk categories. The Covid-19 pill seems like a good first step in that direction.
That depends on a lot of factors, among them the virus strain, the age group or how long ago the vaccinations happened.
Germany is already having death streaks in pension homes again, were vaccination rates of the elderly are 100% [0]. But those 100% happened earlier this year, since then the vaccine protection has heavily diminished.
[0] https://www.swr.de/swraktuell/rheinland-pfalz/mainz/corona-a...
odds of dying from COVID for vaxxed non risk groups are pretty much same as for vaxxed non risk group, 10 times zero is still a zero
nobody is denying vaccine is helping the risk groups, but there is hardly any benefit for people not at risk (healthy weight, no chronic disease)
These claims make sense to my layman understanding, but I really have no idea.
That's from USAMRIID research into broad-spectrum coronavirus antiviral drugs released in March 2019 [0], relevant citations in the paper.
They also mention the possibility of using a "modular vaccine platform", which would be RNA vaccines, but they only considered their use for emergency coverage and also point out how vaccines alone are unlikely to eradicate it, as long as the virus continues to circulate in potential animal reservoirs.
While earlier in the paper it's pointed out;
> Gammacoronaviruses and deltacoronaviruses have no known viruses that infect humans, but contain important agricultural pathogens of livestock.
Which is also an angle that seems weirdly lacking from the public debate [1]
[0] https://sci-hub.ru/10.1080/17460441.2019.1581171
[1] https://onlinelibrary.wiley.com/doi/full/10.1111/xen.12591
1. Gives you the real certificate
2. FOR FREE,
3. With no chance of getting charged with forgery.
4. Gets you vaccinated which will protect you against death and serious illness.
I think the choice is a "no-brainer"
Not sure if trolling, but in case not, vaccination has had “a substantial impact on mitigating COVID-19 outbreaks” in America [1].
Notably, the "Growth Factor" plot looks qualitatively very similar from April 2020 until now. Before then, the data looks more noisy to me but not necessarily different on average. I believe folk started getting vaccinated in December 2020? Based on that plot, it doesn't look like the vaccine is helping much for the death rate. Maybe that data source is not legitimate, or maybe "growth factor" isn't the right metric to look at?
Doesn't that tell us that vaccinations help to significantly reduce Covid-deaths?
https://ourworldindata.org/grapher/united-states-rates-of-co...
Theoretically it could be possible that non-vaccinated infect fewer others than those who are vaccinated -- because unvaccinated more readily die after which they can not keep on infecting others. Nevertheless the goal is not to reduce infections but to reduce deaths and serious illness.
Here's an article which says that vaccination does reduce the risk of you infecting others. But this effect diminishes over time quite fast. That would seem like a good reason to get the booster.
Whose goal? There is no shortage of people and organizations that are trying to force others to vaccinate “to prevent spread”. As your link shows the effectives of this is dubious.
My goal. I assume also your goal. And I assume people who try to "prevent spread" do so because spread of Covid-19 causes death and serious illness.
There have been 799,276 Covid-deaths in the US during the short period it's been around. Almost 800k people dead. Dead. If there was no "Covid spread" those people would not have caught Covid and thus would not have died because of it.
To reduce Covid deaths and serious Covid illness you must try to reduce its spread. If you stop it from spreading you stop it from killing people.
I'd love to see a paper explaining why some two months ago cases were already at or approaching record highs in countries with 70-90% vaccination rates, like UK, Israel, multiple EU nations...Gibraltar is particularly interesting because it has a nearly 100% vaccination rate, yet the case rate continues to climb unabated. [0]
People are treating these vaccines as though they were sacrosanct and unquestionable. Meanwhile the pandemic continues nearly unabated and no, this is not a "pandemic among the vaccinated", despite the fervor with which certain interests have attempted to paint such a picture. Public UK data suggests that vaccinated individuals may actually be more likely to be infected some months after their second doses. But no one is talking about that...
0. https://www.worldometers.info/coronavirus/country/gibraltar/
1. https://vladtepesblog.com/2021/10/10/is-this-ade-uk-data-sho... - yes, it's a blog, but it links to the data for you to review yourself. Check the last two columns of the chart on page 13.
This wouldn't be the first time that humans failed to solve a complex problem, I don't see why its so difficult for people to accept this possibility.
Cold/flu viruses come and go. This virus will do the same. People will see it as evidence that the vaccines worked when in reality the pandemic very likely would have ended without them, yet here we are facing mandates...
Ok fine, you want to enforce this: then just man up and imprison the unvaccinated using force. Don't hide behind employers and make them do your dirty work. Taking away a person's right to work is only 2 degrees separated from making them dependent on the state. It's a fear tactic they're hoping they won't ever have to enforce--not that much different than holding a gun to someone's head.
At the end of the day you're never going to be able make someone do something against their will. People who go against the mainstream will already suffer social consequences. If you have to do something with government resources then beef up the ICU beds .
While you're at it you may as well make it illegal to work if you're a smoker, or obese, or if you've ever had a car accident because those things may lead to eating up an ICU bed for some other person that stands on a higher moral ground.
Great. It's a no from me.
I will never lock down.
I don't mind taking a 0.5% risk to avoid 1% of my life spent in lockdown.
Neither does my mother or grandmother.
It is not an axiom that an increase in death rates at the population level is bad, because people are willing to put their lives at a small risk in order to preserve some semblance of meaning in them.
This is a point lost on essentially every lockdown proponent as far as I can tell. They are fundamentally unwilling to accept differing value systems and seek to enforce theirs.
Eat... less?
We've had < 10,000 confirmed COVID cases in Auckland so the vast majority of the 2M population cannot have natural immunity. Behavior restrictions have been relaxed gradually over the last two months, yet the COVID case numbers (which were increasing) have actually leveled out at an R value of around 1. Vaccination is the only thing that could plausibly have reduced that infection rate.
Seasonality is a confounder, for sure, but I haven't heard any experts claim it as an explanation here.
At a glance, infection rates and vaccination rates seem to be uncorrelated at best.
Arguing that the infection rates are uncorrelated is one thing, but serious illness and death is what we really need to care about with this virus. And for those metrics, vaccination is highly-correlated to better outcomes.
Here in the NL there have been tons of people that sold COVID passes, some working at vaccination places, others working at testing places. Instead of hacking anything, they've just been committing regular fraud. The street value of these passes seems to be round €300 to €500. The government has been blacklisting these passes ever since they were first spotted, leaving many of their "customers" angry now that they can no longer fraud their way through the necessary checks.
The problem is not so much a technical one, as modern crypto is quite unbreakable. The pass in the article is based on RSA-512, which has been proven to be breakable all the way back in 1999. With elliptic curve cryptography the system can still remain unbreakable even with shorter keys that can fit into a small QR code, though space is rarely a problem with these codes anyway.
I don't know the exact methodology the government uses to catch fraudsters, but from someone who just scans the certificates there's no way to find a fake record.
That is, a fake record that matches the person's ID card details. Here in the NL, that's your initials and your partial birthday. Most abuse is people using other people's certificates, which can trivially be caught by checking the necessary identification, as you're told to by the scanning app anyway.
Originally the certificates were simple "yeah, they are vaccinated" PDFs that people would alter, which was a pretty low bar.
In discussions like this I think we really need to frame this in the proper context. We're talking about a certificate saying that you did something that you could do for free, which has significant personal benefits, and even greater social benefits, and that a large majority of the public is entirely behind. Making a fake vaccination certificate is like making a fake Grade school graduation certificate -- if someone is at that point in their life, something has gone seriously wrong.
The demand for certificates was just trying to entice the small percentage of holdouts, and of those surely there will be some who will go to great lengths, including committing pretty significant crimes, to avoid it. That pathology can't be fixed easily.
At some level "compatibility" is correct. System 1 outputs binary data, system 2 takes that and turns it into JSON, system 3 encodes that in base64, system 4 turns that into QR codes, and system 4 was what was mandated for producing all of the organisation's QR codes.
If you were using binary storage, you wouldn't use "the JWS character set" (aka base64). You'd store it directly and have 0 wasted bits.
Also, they're not acknowledging the bits wasted by their current system. Numeric mode in QR codes spends 3.33 bits per digit. At two digits per character, they're spending 6.67 bits to store only 6 bits of information.
[1]: https://github.com/eu-digital-green-certificates/dgc-overvie...
[2]: https://datatracker.ietf.org/doc/draft-faltstrom-base45/
Especially when they could have avoided % and space.
[1]: https://github.com/ehn-dcc-development/hcert-spec/issues/64
Well the reason to care is to avoid QR decoder quirkiness, otherwise you should probably just use the binary encoding.
> I read through some Github issue [1]
According to a comment near they end they were originally going to try to pack everything as a single base 45 bignum, so that half explains it. But not why they'd stick with 45 characters when changing that.
It starts with JWT. JSON is a human readable format (in utf-8), if humans don't need to read, the data could be binary, and the format could be exact. JSON isn't an exact spec, which is mostly inherited from JavaScript (there's no such thing as an integer only floating point, so 1e3==1000==1000.0==1.00e3 in human-readable form, as a stored number they are identical). Then there's differences in white-space (new lines, indentation) - although this could likely be overcome with convention. Because of this the JWT creators said instead of signing the data, we'll sign the exact representation in the payload - but of course with white-space and formatting variance (including a deserialize/serialize loops changing representations, or - in the case of bearer tokens, the HTTP spec allowing newlines/white space to be inserted at the protocol level) they had to encode it as non-human readable (base64). Now everyone agrees you're signing that exact Base64 representation of the JSON object. But! We've build a(n arguably verbose) human readable format that isn't readable by humans.
The SHC spec (common in North America) actually holds a JWT that's signed by an elliptic curve private key. You can validate the signature with a public key. The public/private choice here is great, the JWT is terrible.. they've doubled down on the mistakes. Further to keep the QR smallish, they zipped the payload portion (which is supported by JWT - this is done before the base64 stage), and use only the minimum QR resilience setting (which is fine if it's on a screen, if it's printed this may lead to reading problems). Now we have human readable (JSON) compressed in machine readable (deflate) in machine readable (base 64) in machine readable (QR) - for machine reading purposes. They didn't even trim the fluff (every SHC begins with 56 because.. you guessed it, the `{` character), or use sensible choices (they don't use IssuedAt/iat, but NotBefore/nbf to indicate the generation date). Anyway, SHC (reasonably) noticed because of the (mostly) base64 encoding the character set is only 64 characters (6 bits) which doesn't use the ASCII space (7 bits) very well, so they store the first 'shc://' in ASCII and the rest is a number (there are three modes in QR: ASCII, binary, numeric - the density loosely matches binary representations - a numeric digit (0-9) takes 4 bits, ascii char takes 7 and binary takes 8).
ASCII doesn't support the world very well, UTF8 isn't supported by QR (except as binary).
In the SHC case, because it's signing a specific format/output of the JSON data, it doesn't have the white-space formatting concerns that JWTs have to overcome. If they wanted to stick with a JWT like format (JSON object), they could have skipped the base64 before sign step, at which point they might as well get rid of the header (we're no longer to JWT spec), deflate the message to be signed, and put the signature after the deflated message. All the same data, less of the overhead, and better use of the binary space.
https://threatpost.com/eus-green-pass-vaccination-id-private...
Afaik it was a leaked login, not a leak of the keys.
I would expect them to know where and when that Adolf pass was generated
Passes have been sold (through the clear web and the dark web) but many have also been revoked since. As far as I know, the certificates being sold right now are either someone else's certificate (for places that don't check your ID when you walk in) and certificates generated by people working for places that also give out legitimate certificates, such as some pharmacies and hospitals.
There have been fraudulently obtained passes sold on the dark web. There have also been numerous arrests throughout the whole of Europe for this.
The vast majority of the dark-web suppliers are scammers - many of the adverts include a mix of QRs people have posted to social media and a large number of example QR. Including examples that I have generated in the past and used in presentations / on github.
The article was about RSA 512 which has been known to be weak and crackable for a long time [2].
[0]: https://github.com/eu-digital-green-certificates/dgc-partici...
[1]: https://www.gnupg.org/faq/gnupg-faq.html#no_default_of_rsa40...
[2]: https://it.slashdot.org/story/99/08/29/0213230/512-bit-rsa-k...
Seems like a lot of hassle for a vaccine that is safe and will save your life.
Why not use a VM with older libraries and tools ?
Why does it still surprise me that that most software companies treat backwards compatibility as a joke?
Why reinvent crypto, PKI and all? Also solves updates/invalidation issues.
Also NFC tags could’ve been better solution, but probably would’ve sent too much Bill Gates vibes.
The projects are meant to present a standardized format for the provision of easily validated information about an individual in environments where low-end hardware is common and internet connectivity is unreliable.
The QR code was chosen as the standard form of information transfer because it can be printed on paper and remain easily validated if someone lacks a device to put it on.
The codes aren't primarily meant to control pandemic spread, this just happens to be the first thing driving their widespread adoption.
Cynic in me says - just disable cards for the unvacced at specific venues…
In hindsight, the washing was overreaction, but you do have to realize there wasn't enough knowledge in the beginning, and people were assuming the virus was like the influenza virus, and we usually (at least the common wisdom was) catch influenza through touching snot-laden surfaces. It didn't help when China was saying things like they found some viruses on surfaces after 3 days. Sure, but how much virus, i.e. would they be enough to make you sick? The lack of information also made the virus like a super monster, where any trace of it could be deadly...
Now that we've figured out the virus is airborne, I'm a bit disappointed that governments haven't focused on good ventilation, but still on disinfecting and keeping distance. Where I live the bus can be full of people but it seems the governments are saying "It'll be fine to sit so close to each other if you have a mask on", and people also don't know any better...
No, it was all evolving knowledge of an ongoing situation involving an unknown virus, with the initial outbreak happening in a not very transparent country. Many people haven't bothered to keep up with the latest information, even with the efforts of local health authorities to bring that information to them.
> We still don't know origin of virus
Yes, and? Would that change anything in our understanding of it and how to combat it? Or do you just need someone to point s finger at and say it's all been their fault? Even in that case we'd still have to combat spread and hospitalisations ( which vaccines help with). In any case, i personally doubt we'll have a conclusive origin story of the virus. It has been more or less ( as much as possible) conclusively confirmed that it came from around a Wuhan wet market, but it'd be pretty much impossible to retrace the steps of random animals there and the event(s) that passed it to the initial humans after so much time has passed and so many have died.
It could be just business. We have never ever before vaccine on new virus after 3 months. Censoring any other opinions than "in vax we trust" agenda in serious media just support this narrative.
> Next, the data was hashed using a custom hashing algorithm developed by lachongtech.
Yeahhhh.....soooo.......
They are easy to copy or fake.
Any scheme which simply puts a cryptographic number on a some Physical card - or behind a regular QR is not secure. A simple photocopy will work just as well as the original. Not to mention Photoshop.
But there is actually a new way to make physical things - like printed Covid vaccination cards - provably unique and authentic.
Much more powerful than holograms and also much more secure, unclonable and authenticatable.
Take a look at Blocktag (blocktag dot com) - Next gen QR codes that anyone can print, yet cannot be counterfeited. And of course linked to blockchain and ready for physical NFTs too.
meanwhile ime most places with vaccine requirement accept a photo on my cell phone - not exactly cryptographically signed stuff over here.
For places that are 3G you have the option in the app to not disclose your vaccination status in the code. So the scanning entity will know ow if you have one of the 3 possible requirements. Vaccinated, recovered or tested.