HomeSecurityGerman vaccination certificates: Security gaps found

German vaccination certificates: Security gaps found

The EU promises that with digital vaccination certificates for smartphones we will have greater freedom of movement both within Germany and beyond its borders this summer.

Around 30 million digital vaccination certificates have been issued in Germany so far by vaccination centers, pharmacies and doctors' offices. But German experts warn of security gaps that leave room for counterfeiters and others.

German vaccination certificates: Security gaps found

See also: Israel COVID-19: Reduced effectiveness of the Pfizer vaccine?

The company GData Cyber ​​Defense examined the digital vaccination certificate a few days ago and identified serious weaknesses.

One of the weak points of the certificate is, according to Tim Berghoff, GData's head of security, that the digital certificate does not transfer important data from the printed vaccination certificate (it includes all the vaccinations the holder has had), such as the vaccine code, the place of vaccination, and the name of the health care provider.

In addition, there are errors in the vaccination dates. For example, one certificate listed the same vaccination date for the first and second doses.

A certificate for… Robert Koch who died in 1910

According to the head of GData, another weak point is that the digital signature of the vaccinated person is not checked. Thus, experts managed to fool the system by obtaining confirmation from the Robert Koch Institute that its founder, who died in 1910, was fully vaccinated.

The inclusion of the digital certificate in the German anti-coronavirus mobile application (Corona App) is also considered problematic, as it accepted the certificate even for someone like Robert Koch, who was born in 1843.

German vaccination certificates: Security gaps found

See also: Novavax vaccine: Over 90% effective for various mutations of COVID-19

Fraudsters face 2 years in prison

The fact that the vaccination certificate is displayed correctly in the app is ultimately no indication of the authenticity of the certificate, even if the RKI is officially listed as the issuer. A quality standard, said Thomas Zibert, is not related to the issuer. This is because the RKI receives almost no data, but simply issues cryptographic keys for signing the vaccination certificates. In short: if a pharmacy asks for a vaccination certificate for Donald Duck, it is likely to receive such a certificate.

In principle, scammers only need a fake vaccination certificate. And the supposed signature of a doctor from another city or even another country can hardly be verified in practice.

“A fake vaccination certificate almost always leads to a properly signed digital proof of vaccination,” said Zibert.

Falsifying documents related to COVID-19 is punishable under the German Infection Protection Act, which came into effect on June 1. Anyone caught could face up to two years in prison.

vaccination certificates
German vaccination certificates: Security gaps found

Invitation for criminals

Bochum IT security experts also warned about malware that specializes in hacking access data. This type of software has been part of the standard repertoire of cybercriminals for years.

For example, fraudsters who have illegally obtained a pharmacy's login details can use this portal to create vaccination records at will. Berghoff said a further problem is that vaccination certificates cannot be revoked later. This is due to the way passports are certified electronically.

Berghoff says it is clear that the German Ministry of Health has come under great pressure amid a tight deadline for issuing the certificate.

“They wanted to present a suitable solution to enable citizens to regain some normality for the summer holidays. That in itself is not a bad thing. However, in this case, it was clearly at the expense of security.”

See also: COVID-19: Pfizer vaccine approved for use in adolescents aged 12-15

The Ministry of Digital Governance of Greece, with the application that is about to be released for the entry into the focus, should be particularly careful so that there are no similar cases of illegal or irregular use of the said application as has been observed in other countries. Continuous security checks together with the security analysis of the source code can push towards strengthening the security of the application.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS