On this page: The first person to fill out this form with a name, DOB, and a cell # or email address can steal a person's data-record and lock out the intended person from accessing the data.
I don't think that's how it works. (I just got mine)
When you fill in the info you will get a 24-hour-expiring link at the email/phone number. You provide the PIN to that to get the vaccine record.
Presumably you can activate it multiple times, and the only way an attacker would be able to access it is if they have email/phone access in which case it's moot anyways.
> The first person to fill out this form with a name, DOB, and a cell # or email address can steal a person's data-record and lock out the intended person from accessing the data.
well, no, because all of the information, including the cell phone or email, is matched against information provided at time of vaccination.
Now, if someone knew CDPH was going to do this (or targeted someone vaccinated after it went live) and altered the records submitted at the time of vaccination, they could do that, or if they had taken control of the email address or cell phone number provided at vaccination time. But that’s more than just filling out the form...
How does Digital COVID-19 Vaccine Record portal work?
The Digital COVID-19 Vaccine Record portal draws COVID-19 records from California’s immunization systems. Enter your name, date of birth, and an email or mobile phone number associated with your vaccination record, then create a four-digit PIN. If the information you submitted matches the official record, you will receive a text or email with a link to your digital COVID-19 vaccine record. Enter the PIN you created to view the record."
Keep in mind that the "Health Cards[0] are encoded as Compact Serialization JSON Web Signatures (JWS)". They're cryptographically signed by the state, so it's hard to fake them without having access to the issuer's key.
…that said, it assumes that client-side products will actually verify the health cards, which is not necessary when extracting the data.
11 comments
[ 0.22 ms ] story [ 51.6 ms ] threadWhen you fill in the info you will get a 24-hour-expiring link at the email/phone number. You provide the PIN to that to get the vaccine record.
Presumably you can activate it multiple times, and the only way an attacker would be able to access it is if they have email/phone access in which case it's moot anyways.
well, no, because all of the information, including the cell phone or email, is matched against information provided at time of vaccination.
Now, if someone knew CDPH was going to do this (or targeted someone vaccinated after it went live) and altered the records submitted at the time of vaccination, they could do that, or if they had taken control of the email address or cell phone number provided at vaccination time. But that’s more than just filling out the form...
"Frequently Asked Questions
How does Digital COVID-19 Vaccine Record portal work?
The Digital COVID-19 Vaccine Record portal draws COVID-19 records from California’s immunization systems. Enter your name, date of birth, and an email or mobile phone number associated with your vaccination record, then create a four-digit PIN. If the information you submitted matches the official record, you will receive a text or email with a link to your digital COVID-19 vaccine record. Enter the PIN you created to view the record."
https://myvaccinerecord.cdph.ca.gov/faq
…that said, it assumes that client-side products will actually verify the health cards, which is not necessary when extracting the data.
0: https://smarthealth.cards/