Flip side: why are all these countries/users panicking *now*? The vuln was disclosed to Infineon in *February*. This means 6 months of "responsible" disclosure have been utterly worthless. You'd think Infineon would've notified, you know, government clients? WTF? @CRoCS_MUNI
There is; public keys can be trivially checked for the ROCA fingerprint in microseconds. If you mean in a more general case, usually what happens is cards are provisioned with a private key at manufacture time that signs things to prove they're card-generated.
-
-
I've got a .NET card with national Post-issued certificate that doesn't test positive for ROCA, which is why I'm curious about how it was generated.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.