FB pixel

White hat hacker reveals vulnerability in Germany’s digital ID

White hat hacker reveals vulnerability in Germany’s digital ID
 

Germany’s digital ID may come under threat from malicious attackers, according to an analysis from a digital security expert.

A white hat hacker recently demonstrated how a cybercriminal could perform a Man-in-the-Middle attack on the online version of the German National Identity Card, known as eID. The vulnerability could potentially pose a danger to the approximately 10 million people currently using the system.

“I was surprised at how easy it was to compromise the system,” the hacker told news outlet Der Spiegel.

The anonymous digital researcher, who goes under the name CtrlAlt, built an application that could record the six-digit PIN users type in to log in to the eID on their smartphones. To aid the process, he used the official eID app code, which is available online as open-source software.

The malware could potentially be installed on the user’s smartphone through sophisticated Trojan software that gives access to the entire smartphone, similar to the ones used by certain governments to target dissidents and journalists. Alternatively, cybercriminals could also place the malware by tricking a user into downloading a fraudulent app from an app store.

Once they gain access to the digital ID, malicious actors could log the user into a fake eID app account as well as intercept data used to log into other eID services, including government services, eHealth platforms and banking systems, according to the hacker who published an analysis of the attack last Friday.

CtrlAlt says he informed Germany’s Federal Office for Information Security (BSI) in December last year and that the agency has acknowledged the vulnerability. In a response to Der Spiegel, BSI said there is no evidence of specific attacks carried out and that it sees no reason for a change in risk assessment for using the eID.

“From the BSI’s point of view, this is not an attack on the eID system, but on the users’ end devices,” it says.

CtrlAlt, however, says that this places undue responsibility on users for maintaining client device security. And with plans for expanding Germany’s digital ID system, the problem could linger on. Since 2017, the country has been automatically enrolling citizens into the eID program while issuing new ID cards. Fifty-six million people in Germany now have the eID.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Adoption of biometric payment cards plateaus with niche applications

Biometric payment cards, once seen to be the belle of the biometric ball, are mired in a rut of stagnated…

 

South Korea’s age assurance policies built on years of systemic, political change

A new paper from two scholars examines South Korea’s approach to age assurance. Published in TechPolicy.press, the paper contrasts global…

 

Zambia obtains World Bank funding support to advance DPI implementation

Zambia has secured funding to the tune of $120 million from the World Bank’s Digital Development Partnership to carry on…

 

Aadhaar enables an ‘epidemic’ of IDs in India

The Aadhaar ecosystem continues to grow, but it’s not all good news. The proliferation of IDs like the “One Nation,…

 

EU AI Act’s impact on businesses inspires simplification efforts

The European Union’s AI Act is already having a wide-reaching impact on business both inside and outside the economic bloc….

 

Chinese biometrics firms settle in Hong Kong for international market access

Chinese biometric recognition companies are eyeing Hong Kong as a springboard for expanding to foreign markets, according to company executives….

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events