Regarding section 5.1, 5.2 in the Guidelines on Technical Specifications for DGCs, Volume 4, European DGC Applications, v1.3
I am unsure, if I understand the DGC installation process in the Wallet App correctly, especially the planned use of a TAN via SMS (or on paper) to move a test result from an e-mail (or paper) into the app.
I assume the following:
- the QR code shown in the Wallet is the same as on the printed version (its just the DGC)
- it is always necessary to check if the ID of the person presenting the DGC matches the DGC, and of course the signature
- there is maybe some protection against just presenting a screenshot, like a moving counter or so on the wallet screen
- on the other hand, localized versions of the wallet may have different appearances
- it is possible to build an app not doing the TAN/DGCI check on DGC installation, that still looks like the wallet and presents DGCs
- it is even possible (but probably illegal) to use a rogue verifier app at an venue that just records DGC, with or without actually verifying the signature
So, the protection offered by the TAN requirement is somewhat limited, as the data to display is already transmitted to the user and only the installation in the app is a bit more difficult.
I think it is useful to only allow one installation of the DGC in the official wallet app by registering the installation's public key with the backend and only allow registration for a limited time after issuing the certificate as planned. The wallet app should inform the user that the DGC can only be installed in one wallet before registering the DGCI with the backend.
This would help against the "normal" DGC reuse attempts, like forwarding a test result email to a friend, or trying to scan the QR code from the wallet of another person.
But I don't understand the benefit of a second factor in this situation. Maybe I have missed something important?
Regarding section 5.1, 5.2 in the Guidelines on Technical Specifications for DGCs, Volume 4, European DGC Applications, v1.3
I am unsure, if I understand the DGC installation process in the Wallet App correctly, especially the planned use of a TAN via SMS (or on paper) to move a test result from an e-mail (or paper) into the app.
I assume the following:
So, the protection offered by the TAN requirement is somewhat limited, as the data to display is already transmitted to the user and only the installation in the app is a bit more difficult.
I think it is useful to only allow one installation of the DGC in the official wallet app by registering the installation's public key with the backend and only allow registration for a limited time after issuing the certificate as planned. The wallet app should inform the user that the DGC can only be installed in one wallet before registering the DGCI with the backend.
This would help against the "normal" DGC reuse attempts, like forwarding a test result email to a friend, or trying to scan the QR code from the wallet of another person.
But I don't understand the benefit of a second factor in this situation. Maybe I have missed something important?