Flip side: why are all these countries/users panicking *now*? The vuln was disclosed to Infineon in *February*. This means 6 months of "responsible" disclosure have been utterly worthless. You'd think Infineon would've notified, you know, government clients? WTF? @CRoCS_MUNI
-
-
Interesting, thanks. However, I wonder why ID cards are affected at all. Aren't the private keys/certificates usually generated centrally on dedicated govt hardware and only the public keys are programmed into the cards? Do the cards still generate some keys on their own?
-
The whole point of using smartcards is that you generate the keys internally (and they never leave the card), then the govt signs the public key (presumably with some channel attestation involved so the card can prove it's a real card issued originally by govt).
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.