My guess wold be that Infineon notified smartcard *chip makers* but they didn't bother informing their customers in turn. Maybe we can ask @e_estonia when and how they got warned.
-
-
You mean smartcard manufacturers, as in the physical bits of plastic and some gold pads? Infineon makes the ICs.
1 reply 0 retweets 0 likes -
hm really? I thought it's guys like NXP, Gemalto etc.
1 reply 0 retweets 0 likes -
NXP and Infineon make ICs (and software libs). Gemalto makes cards that use those ICs (and more software).
1 reply 0 retweets 1 like -
Replying to @marcan42 @CRoCS_MUNI
Interesting, thanks. However, I wonder why ID cards are affected at all. Aren't the private keys/certificates usually generated centrally on dedicated govt hardware and only the public keys are programmed into the cards? Do the cards still generate some keys on their own?
1 reply 0 retweets 0 likes -
Replying to @IgorSkochinsky @CRoCS_MUNI
The whole point of using smartcards is that you generate the keys internally (and they never leave the card), then the govt signs the public key (presumably with some channel attestation involved so the card can prove it's a real card issued originally by govt).
2 replies 0 retweets 0 likes -
Replying to @marcan42 @CRoCS_MUNI
hm, looks like it. Here's how it works (worked?) for Belgian IDs, which also has (had?) Infineon chip: https://homes.esat.kuleuven.be/~decockd/slides/2006.10.09.belgian.eid.card.technical.overview.presentation.pdf …pic.twitter.com/iqupy8Qgzx
2 replies 0 retweets 0 likes -
@doegox do you know if current eID cards still use Infineon chips?1 reply 0 retweets 1 like -
I heard of SLE66CX360PE
1 reply 0 retweets 0 likes -
Replying to @doegox @IgorSkochinsky and
see https://eid.belgium.be/sites/default/files/page-attachments/rn429.pdf … p23 "world" module
2 replies 0 retweets 0 likes
Note that what matters is the firmware, not the chip, though I expect a correlation between both (depending on how Infineon releases things). It's a firmware bug.
-
-
Indeed typically the semicon provider delivers also a cryptolib. The final customer may use it or not that's another question.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.