Catanal government: "Let's publish a DB of all Catalan citizens! It's fine, it's protected with DIY crypto". http://la3.org/~kilburn/blog/catalan-government-bypass-ipfs/ …
-
Show this thread
-
So basically now you can bruteforce your way into a national ID <-> zipcode <-> birthdate mapping for any Catalan citizen. A+ job there.
1 reply 7 retweets 10 likesShow this thread -
Replying to @marcan42
Am I missing something or could they not just have used a hash of the concatenated values as the DB key to look up the polling station?
1 reply 0 retweets 0 likes -
Replying to @Freerunnering @marcan42
The article makes it sound like the DB exists purely for ‘where is my polling station’ lookups. Why is there DB encryption involved at all?
1 reply 0 retweets 0 likes
Replying to @Freerunnering
The thing is the mere existence of the hash leaks the association of those details for a given citizen.
5:44 PM - 5 Oct 2017
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.