Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[iOS Verifier App] Verifiable Credentials with Matching KID But False Public Key Data Are Accepted #141

Closed
RalicaY opened this issue Apr 28, 2022 · 4 comments
Assignees
Labels
3rd Prio - Low indicated an issue with low priority bug Something isn't working

Comments

@RalicaY
Copy link
Collaborator

RalicaY commented Apr 28, 2022

Describe the bug

We scanned verifiable clredentials with matching KID but manipulated public key data so that the signature was no more valid for the issuer with this KID. The app scanned these without any error.

Expected behaviour

The app should recognize that the credential has an invalid signature.
81d947d2-d79d-40c9-be8c-633b965bfe06(2)
Screenshot from 2022-04-28 09-34-37

Technical details

Verifier App 1.3.1.1(33) Hash & iOS Verifier 1.3.1 (31) Bloom

@RalicaY RalicaY added the bug Something isn't working label Apr 28, 2022
@RalicaY RalicaY added 1st Prio - High Indicates an issue with high priority 2nd Prio - Medium Indicates an issue with medium priority and removed 1st Prio - High Indicates an issue with high priority labels Apr 28, 2022
@PaulBallmann
Copy link
Contributor

@RalicaY
Copy link
Collaborator Author

RalicaY commented May 5, 2022

05.05.2022: Retest with iOS Verifier 1.3.1(34) was not successful. Actual result: "Barcode-Fehler"

@ltranvan
Copy link

tvt, 10.05.2022: Priority reduced from Medium to Low, because the described failed acception of the wrong Credential is not occured anymore. Just only a not expected (consistent to Android) error messaged is now displayed.

@ltranvan ltranvan added 3rd Prio - Low indicated an issue with low priority and removed 2nd Prio - Medium Indicates an issue with medium priority labels May 10, 2022
@ltranvan
Copy link

tvt, 10.05.2022: retested successully by Ralica with IOS-version 1.3.1.1 (42) HL and 1.3.1 (38) BF.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3rd Prio - Low indicated an issue with low priority bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants