Of course, they aren't admitting to it publicly. The question is how many countries, companies, and other users of Infineon chips are quietly sweeping ROCA under the rug and ignoring the fact that their security is now *utterly broken* until updated?https://twitter.com/marcan42/status/928171103607865345 …
There is a CRL. There is a way of getting every on-line system to stop accepting these certs. But they aren't using it. Why aren't these certs in the CRL already?
-
-
As for e-signing, yes. Basically Spanish eID can be used by *anyone* to validate the identity of Spanish citizens and for accepting signatures with legal validity. It's an open x.509 based system. Companies are encouraged to use it.
-
For example, I can set up my bank account to allow logging in via DNIe.
End of conversation
New conversation -
-
-
If they’re not revoked yet, then that’s negligence. And not “working hard” as I expected earlier. I assume nothing would break on revoke.
-
Online cert checks would break on revoke (i.e. no more logging in with the broken certs). Which is what you *want*.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.