Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revoked certificates still shown as valid in CovPassCheck #28

Open
2 of 3 tasks
treysis opened this issue Nov 13, 2021 · 6 comments
Open
2 of 3 tasks

Revoked certificates still shown as valid in CovPassCheck #28

treysis opened this issue Nov 13, 2021 · 6 comments
Labels
bug Something isn't working

Comments

@treysis
Copy link

treysis commented Nov 13, 2021

Avoid duplicates

  • Bug is not mentioned in the FAQ
  • Bug affects both Android and iOS, for specific issues / questions that apply only to one operating system, please raise them in the respective repositories:
  • Bug is not already reported in another issue

Technical details

  • Device name: irrelevant
  • OS version: irrelevant
  • App version: 1.20

Describe the bug

The fraudulent QR codes that leaked 1-2 weeks ago are still validated by CovPassCheck. Other check apps (e.g. the Swiss Covid Certificate Check) correctly mark them as revoked. The database of CovPassCheck says it has been updated today.

Steps to reproduce the issue

Expected behaviour

The QR codes should be reported as invalid.

Possible Fix

Additional context

@treysis treysis added the bug Something isn't working label Nov 13, 2021
@alexcimander
Copy link

Hey Treysis,

sorry for the late response! Is this still an issue? With the Release of 1.13 the certificates should be blocked :-)

Thank you for your feedback!

@treysis
Copy link
Author

treysis commented Dec 6, 2021

Hello @alexcimander
Unfortunately, certificates are still accepted both by CovPass and CovPassCheck.
E.g. this certificate for Adolf Hitler:
https://twitter.com/reversebrain/status/1453095038284615682

The Swiss app correctly shows this certificate as invalid.

@alexcimander
Copy link

Hey Treysis,

the CovPass blocked certificates from entities that we were advised to block. There are still some that will be accepted. The Adolf Hitler certificate is one of the ones that are still scanable. However we are working on a further prevention and we might block more certificates that were issued erroneously. We will keep you updated 👍

@treysis
Copy link
Author

treysis commented Dec 8, 2021

Thx. Why is it so slow, though? Those certificates leaked end of October. Italy and Switzerland are already blocking them since shortly after.

@OlympianRevolution
Copy link

Yes the Mickey mouse certificate at least is still valid in the CoronaWarnApp.

We were told to report it here corona-warn-app/cwa-documentation#751

For more Certs to revoke see here https://github.com/denysvitali/covid-cert-analysis/blob/master/RESULTS.md#samplesmickeymousetxt

@OlympianRevolution
Copy link

Mickey Mouse has also been revoked by Tous Anti COVID (France). What is the rational for delaying revocations already performed by other countries?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants