Seems the Spanish government is finally admitting that new Spanish eIDs ("DNIe 3.0") are vulnerable to ROCA. Everyone gets to renew their certs. Supposedly they're "disabling" the old functionality (revoking the certs, I hope). https://www.dnielectronico.es/PortalDNIe/
-
-
Replying to @marcan42
I wonder, do you know of the card manufacturer? The only reference I cannot find any Infineon connection.
1 reply 0 retweets 0 likes -
Replying to @DanCvrcek
The official specs say the chip is Infineon, but I don't know who actually manufactures the cards. https://www.dnielectronico.es/PortalDNIe/PRF1_Cons02.action?pag=REF_1078 …
2 replies 0 retweets 0 likes -
-
Replying to @DanCvrcek
Oh, sorry, misunderstood :-) (and thanks for running that!)
1 reply 0 retweets 0 likes -
Replying to @marcan42
:) what strikes me though ... Infineon was notified and a number of its customers supported by
@CRoCS_MUNI since March 20171 reply 1 retweet 0 likes
Clearly Infineon has utterly neglected their responsibilities in this "responsible" disclosure process. Government customers should all have been informed, (if not all customers period). This is why we can't have nice things. RD doesn't work if companies don't care.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.