Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well the government does not generate the keys, or access the signed data. The smartcard does, inside the chip. The spec is here: http://www.id.ee/public/TB-SPEC-EstEID-Chip-App-v3.4.pdf

Forgotten who the chip manufacturer is, but basically what you'd describe would be an attach against the chip manufacturer and their key generation algorithms and randomness.

Estonian ID cards are made by TrĂ¼b AG, which does id cards also for Switzerland, Germany, Dubai and countless other countries. And the Estonian card personalization if I remember correctly is also outsourced to a private party.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: