Skip to content

Comment on sPACE Attack: Spoofing eID’s Password Authenticated Connection Establishment

Comments

The research paper has shown the existence of a vulnerability in the German eID scheme, posing a significant risk to all services relying on the eID, especially those handling sensitive data such as insurances, banks, and government services.

The vulnerability has the CVE-ID CVE-2024–23674 and a CVSS rating of 9.7 (Critical)

A bank account has been successfully opened in the name of a victim at a major German bank.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.