Seems the Spanish government is finally admitting that new Spanish eIDs ("DNIe 3.0") are vulnerable to ROCA. Everyone gets to renew their certs. Supposedly they're "disabling" the old functionality (revoking the certs, I hope). https://www.dnielectronico.es/PortalDNIe/
-
-
:) what strikes me though ... Infineon was notified and a number of its customers supported by
@CRoCS_MUNI since March 2017 -
Clearly Infineon has utterly neglected their responsibilities in this "responsible" disclosure process. Government customers should all have been informed, (if not all customers period). This is why we can't have nice things. RD doesn't work if companies don't care.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.