#validation

carstenraddatz@pluspora.com

Crypto is hard. Certificate validation can be too. GDATA says the German Coronavirus Warning App (CWA), which got added a digital certificate wallet function to recently, lacks any validation.

The researchers were able to add Robert Koch's certificate (*1843) to the app - the only criterion the app checks is that two weeks since the 2nd shot have passed. Oh, a century? Never mind, here you go. >_<

To be fair, the recommended way is using the official CovPass App, which does the self-evident check.

https://www.gdata.de/blog/digitaler-impfnachweis-schwaechen-bei-der-sicherheit

#cwa #gdata #certificates #certificate #validation #fail #covpass #crypto