<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NPA on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/npa/</link>
    <description>Recent content in NPA on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 22 Nov 2010 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/npa/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Some More Security Research on The nPA AusweisApp</title>
      <link>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</link>
      <pubDate>Mon, 22 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</guid>
      <description>&lt;p&gt;After the initial quick shot (see this &lt;a href=&#34;http://www.insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/&#34;&gt;post&lt;/a&gt;) we decided to have a closer look. And some more stuff turned up.&lt;/p&gt;&#xA;&lt;p&gt;After decompiling the integrated java stuff we stumbled about hard coded server credentials:&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;package Idonttell;&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; &lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; public abstract interface Idonttell&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;{&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean debug = false;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean auth = true;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_SERVER = &amp;quot;Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_USER = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_PASSWORD = &amp;quot;Idonttell&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SEND_FROM = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String[] SEND_TO = { &amp;quot;buergerclient.it-solutions@Idonttell.com&amp;quot; };&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD = &amp;quot;OpenLimitErrorMessage&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD_PROP = &amp;quot;yes&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;}&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our contribution to the public discussion about the German new ID card (nPA)</title>
      <link>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</link>
      <pubDate>Thu, 11 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</guid>
      <description>&lt;p&gt;Currently there’s quite some discussion about the security properties and posture of the German new ID card (“Neuer Personalausweis”, “nPA”, some technically reasonable security discussion can here be found e.g. &lt;a href=&#34;http://blog.cj2s.de/categories/5-German-ID-Cad-nPA&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;While – as of our current knowledge – we do not expect major security flaws on the architecture level, the problems discussed so far (like &lt;a href=&#34;http://www.troopers08.org/content/e6/e461/AMATOFrancisco-evilgrade-ENG-Troopers-fk.pdf&#34;&gt;Evilgrade&lt;/a&gt; style attacks against one of the main applications or keylogging the PIN in scenarios with &lt;a href=&#34;http://www.ccc.de/de/updates/2010/sicherheitsprobleme-bei-suisseid-und-epa&#34;&gt;pinpad-less readers&lt;/a&gt; ) certainly show that security best practices must be followed by all parties involved in the development, deployment and use of the nPA and it’s associated applications. From our perspective this may be expected from the applications’ developers as well.&lt;br&gt;&#xA;Looking at this:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
