TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Estonia blocks electronic ID cards over identity-theft risk

55 pointsby tempover 7 years ago

9 comments

tauntzover 7 years ago
The vulnerability in question: *The Return of Coppersmith’s A‚ttack: Practical Factorization of Widely Used RSA Moduli∗ <a href="https:&#x2F;&#x2F;crocs.fi.muni.cz&#x2F;_media&#x2F;public&#x2F;papers&#x2F;nemec_roca_ccs17_preprint.pdf" rel="nofollow">https:&#x2F;&#x2F;crocs.fi.muni.cz&#x2F;_media&#x2F;public&#x2F;papers&#x2F;nemec_roca_ccs...</a><p>Estonian ID card uses 2048 byte keys which means generating a private key from a public key takes 140.8 CPU years which is quite fast&#x2F;trivial&#x2F;cheap using a distributed approach (botnet, your already existing HW that you use for mining etc).. considering the implications.<p><a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2017&#x2F;09&#x2F;security_flaw_i.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2017&#x2F;09&#x2F;security_flaw...</a>
评论 #15618774 未加载
emerongiover 7 years ago
Official announcement: <a href="https:&#x2F;&#x2F;www.valitsus.ee&#x2F;en&#x2F;news&#x2F;estonia-will-block-certificates-760-000-id-cards-evening-3-november" rel="nofollow">https:&#x2F;&#x2F;www.valitsus.ee&#x2F;en&#x2F;news&#x2F;estonia-will-block-certifica...</a><p>It was claimed that software for cracking the private keys has entered the black market, so they had to block the sertificates earlier than expected.
评论 #15618853 未加载
jackvalentineover 7 years ago
&gt; As of October 31, all users of faulty ID cards can update their security certificates remotely and at Estonian police and border guard service points.<p>I have been trying every day to do so but constantly getting “server is overloaded” errors.
paulajohnsonover 7 years ago
Other governments take note: this is what good electronic security looks like.
评论 #15618023 未加载
评论 #15620248 未加载
评论 #15620768 未加载
评论 #15618002 未加载
DocGover 7 years ago
&gt;ID Card is compulsory<p>&gt;760,000 ID cards will be blocked<p>&gt;in country of 1.3 million<p>&gt;I have no idea how I can declare monthly VAT numbers<p>It is bad but could be worse. People are signing up for MobileID and there is still possible to update ID cards via going to the office.<p>But poor people abroad. Basically they will be cut off from all the services.
评论 #15618146 未加载
评论 #15618241 未加载
baccreditedover 7 years ago
estonia id card question: can ANYONE create a website that uses the card to authenticate? Or is it a estonia whitelist of services only?
评论 #15618629 未加载
smclover 7 years ago
Been trying with little luck to arrange my appointment to pick up my card from the local embassy - I guess this is why
askzover 7 years ago
And then, we&#x27;ll discover that ecdsa is also vulnerable on these chips?
pjc50over 7 years ago
This is fallout from the Infineon private key weakness, isn&#x27;t it?
评论 #15617971 未加载
评论 #15619110 未加载