Seems the Spanish government is finally admitting that new Spanish eIDs ("DNIe 3.0") are vulnerable to ROCA. Everyone gets to renew their certs. Supposedly they're "disabling" the old functionality (revoking the certs, I hope). https://www.dnielectronico.es/PortalDNIe/
-
-
Replying to @marcan42
I wonder, do you know of the card manufacturer? The only reference I cannot find any Infineon connection.
1 reply 0 retweets 0 likes -
Replying to @DanCvrcek
The official specs say the chip is Infineon, but I don't know who actually manufactures the cards. https://www.dnielectronico.es/PortalDNIe/PRF1_Cons02.action?pag=REF_1078 …
2 replies 0 retweets 0 likes -
Replying to @marcan42
Sure, it looks like customised operating system & app as dnie has a common criteria evaluation. Excellent link, thank you!
1 reply 0 retweets 0 likes -
Replying to @DanCvrcek
Common criteria is worthless. The buggy code passed those evaluations. This is why we need *public* review, not shitty certifications that don't certify anything.
2 replies 0 retweets 0 likes
This Infineon fail passed every official certification of the problem chips and libraries. It was only found by researchers working black-box from the keys only.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.