@JamesHenstridge@wabzqem@ServiceNSW@yaakov_h@VTeagueAus I will give some credit on the basis that it attempts to avoid the potential “my server/master private key was leaked” issue, however, given the QR codes currently rotate every 60s it seems rather pointless (ie: just rotate the master key).
@jxeeno@COVID19NearMeAU I’m so glad you did this! I’d been playing with some of the data/struggling to find time to do something similar, so VERY happy to see it exists!
Write up on @ServiceNSW’s Digital Driver Licence QR codes. I go through QR code generation, bypass of cert pinning, jailbreak and tampering mechanisms. There’s private key extraction and AES decryption 🎉. Thanks to @fennb@yaakov_h@VTeagueAus as well.
https://t.co/lMiywW0uEz
@wabzqem Hah, love this. I guess the government can't afford the cost of developing the extra ~90 odd lines of code. It's not like the alternative is so bad, the lockdowns only cost $19M/hour anyway...
Look @GregHuntMP - Richard @wabzqem has already written the code for generating and signing verifiable vaccine certs. All Aus gov needs to do is generate a keypair and sign the data. Please. It's cheap and it's simple and it will let us prove we've been vaccinated.
#Auspol
This is what our vaccination certs should be like - verifiable. This video shows me using the Swiss verification app verifying my EU compat, signed QR code containing my data. I’ve made a tool to generate your own, using your real myGov login:
https://t.co/XxbuooYETN
@wabzqem Absolutely. Even if police can do it, how are retail venue operators supposed to? Also, having an app that could look up IHI numbers (rather than validate digital signatures) is a security risk in and of itself :|
@JennyMikakos Love your work! I'm wondering if DHHS has been considering some of the emerging "2nd generation" contact tracing approaches such as: https://t.co/0z9M5vQcbe
Would something like this perhaps help save some lives in Vic?