- [2021-10-16] The i-voting in the 2021 local municipality elections took place from October 11th to 16th. A new i-voting record was set with 273,620 votes (46%) being i-votes. Around 24,000 i-votes were revotes. The biggest share of i-votes went to the Reform Party. I-votes cast for the Center Party tripled in Tallinn. Several voting related incidents were observed and are covered below.
https://news.err.ee/1608372258/new-e-voting-record-set-at-2021-local-elections
https://news.err.ee/1608376163/reform-wins-local-elections-e-vote-again
https://www.ohtuleht.ee/1046409/keskerakonna-e-haaled-tallinnas-kolmekordistusid
https://forte.delfi.ee/artikkel/94877729/varske-raport-e-haaletamise-perioodil-motlesid-valijad-oma-otsuse-umber-ligi-24-000-korral - [2021-11-11] The State Electoral Committee (VVK) received an appeal from candidate Andrea Eiche demanding the i-voting results in Lüganuse municipality be annulled due to alleged vote buying activities. The complainant claimed that voters had been “persuaded” to cast an i-vote for a Center Party candidate, both at the Kiviõli Russian School and at a nearby store, with the latter providing gifts in return for doing so. The applicant requested VVK to ascertain how many i-votes had been cast from the store and also from the school’s IP address to specific candidates. The Supreme Court found that processing such data would breach the ballot secrecy. The court found that the allegations lacked sufficient proof, although the court ordered the police to investigate a potential criminal offense.
https://news.err.ee/1608398816/supreme-court-orders-ppa-investigation-into-alleged-luganuse-vote-buying - [2021-11-03] Police detained a politician (Sergei Gorlatš) who is suspected of vote buying. According to preliminary data, almost 40 Narva residents were offered a trip, which included a guided walk in the park, a visit to a SPA, a picnic and transport. The trip took place during the election week and people were instructed to bring their ID card to i-vote. The i-voting took place on the bus. People who could not vote due to the lack of an ID card or PIN codes were asked to do so later at the polling station. Almost half of the people were able to vote on that trip.
https://news.err.ee/1608390995/narva-councilor-suspected-of-vote-buying-suspended-for-at-least-3-months
https://news.err.ee/1608389642/ppa-investigating-narva-e-vote-buying-case
https://news.err.ee/1608390413/eesti-200-calls-for-narva-councilor-resignation-after-police-investigation
https://news.postimees.ee/7376895/member-of-katri-raik-election-coalition-caught-buying-votes
https://www.err.ee/1608389594/keskkriminaalpolitsei-kahtlustab-narva-poliitikut-haalte-ostmises - [2021-10-28] The international i-voting security audit procurement failed five times in a row as the companies that applied did not meet the conditions of the procurement. However, the state signed a contract for a total of 200,000 euro with KPMG Baltics OÜ to conduct a narrower scope procedural audit. The audit is supposed to assess all election-related information systems and has to be completed by April 2022. The audit is supposed to assess at minimum: (1) compliance to the OSCE/ODIHR report; (2) the implementation of the proposals made by the i-voting security working group in 2019; (3) compliance of the Council of Europe e-voting standard; and (4) current legislation and processes related to election information systems.
https://digi.geenius.ee/rubriik/uudis/riik-tellis-auditi-mis-selgitab-valja-kuidas-on-kert-kingo-e-valimiste-tooruhma-ettepanekuid-rakendatud/
https://digi.geenius.ee/rubriik/uudis/suurejooneline-e-valimiste-rahvusvaheline-audit-ebaonnestus-viis-korda-jarjest/
https://digi.geenius.ee/rubriik/uudis/riigihangete-vaidlustuskomisjon-ebaonnestunud-e-valimiste-hankest-ei-saa-valistada-vaidlustuse-esitamist/
https://digi.geenius.ee/rubriik/uudis/riigi-tugiteenuste-keskus-lukkab-umber-vaite-et-riik-oli-valmis-seadusevastaselt-e-valimiste-hanke-tahtaega-pikendama/
https://www.postimees.ee/7349546/e-valimiste-auditit-plaanitud-kujul-ja-ajal-ei-tule-too-tegijaid-lihtsalt-ei-ole
https://forte.delfi.ee/artikkel/95066489/ekre-kunagine-eesmark-saab-siiski-teoks-mkm-alustab-e-valimiste-auditeerimist-tegija-valiti-ilma-hanketa
https://forte.delfi.ee/artikkel/94752045/kas-raul-siemil-on-oigus-eesti-e-valimiste-susteemi-ei-suudagi-keegi-revideerida-ja-see-on-oht-eesti-julgeolekule - [2021-10-28] EKRE submitted a complaint asking for i-voting in the ongoing elections to be declared illegal, as the translation feature of the Google Chrome browser distorted (translated) candidate names listed in the election website kov2021.valimised.ee. On the night of October 13th, the developers of the website added the translate=”no” flag to the candidate list, instructing browsers to not apply translation on that part of the page. National Electoral Committee (NEC) rejected the complaint as the names of the candidates were displayed correctly in the i-voting application. The Supreme Court rejected the appeal assessing the impact of the translation problem as unlikely.
https://www.ohtuleht.ee/1047049/riigikohus-e-haaletamine-oli-seaduslik
https://news.err.ee/1608379718/ekre-goes-to-court-over-e-voting-translation-issue
https://news.err.ee/1608370794/ekre-seeks-annulment-of-e-voting-result - [2021-10-28] Virgo Kruve submitted a complaint asking for i-voting to be canceled for the local elections due to several issues: (1) the source code of the i-voting application was not publicly available; (2) the software was not audited and the i-voting server was not under the supervision of auditors; (3) paper voters and i-voters were not treated equally as i-voting was not possible on election day; (4) the i-voting application was signed after the i-voting trail; (5) VVK confirmed the results of the i-voting trail after the start of the i-voting period. NEC and the Supreme Court dismissed the complaint: (1) legislation does not require publication of the i-voting application source code or audit of the application; (2) the law does not impose an obligation to use the i-voting application provided by VVK; (3) the vote verification application can be used to check if the correct vote has been cast; (4) there are measures to verify the authenticity of the state-provided i-voting application.
https://www.ohtuleht.ee/1047049/riigikohus-e-haaletamine-oli-seaduslik
https://news.err.ee/1608364593/electoral-committee-dismisses-e-voting-organization-complaint - [2021-10-26] Jan Willemson (Cybernetica) used the unofficial proof-of-concept i-voting application to cast an i-vote in the local elections. The vote was accepted by the vote collector server and passed the mobile vote verification successfully. However, in the ballot box processing phase the vote was discarded as invalid. The cause of the bug is being investigated.
https://digi.geenius.ee/eksklusiiv/arvutiteadlane-tegi-kattesaadavaks-e-valimiste-koodi-mida-valimisteenistus-on-seni-kiivalt-varjanud/
https://digi.geenius.ee/rubriik/uudis/uks-valija-loi-endale-isikliku-e-haaletamise-tarkvara/
https://forte.delfi.ee/artikkel/94882233/kahtlus-uks-e-haaletaja-oli-loonud-oma-valimisrakenduse-tema-antud-haal-tunnistati-kehtetuks
https://forte.delfi.ee/artikkel/94898679/valimisteenistus-uksikuritajal-ei-onnestunud-e-valimiste-susteemi-ara-petta - [2021-10-23] Postimees wrote about indications that ID cards of nursing home customers are abused to cast i-votes. As an example, it was mentioned that a relatively unknown candidate, a close relative of the head of a nursing home, received as many votes as a well-known Estonian politician (nearly a hundred votes) and had an unnaturally high proportion of i-votes – four times as many as paper votes. However, so far none of the allegations that ID cards are being misused in nursing homes have been substantiated.
https://leht.postimees.ee/7368389/e-valimispettusi-avastada-aitav-info-havitatakse-enne-haaltelugemist
https://www.postimees.ee/7368573/riigi-valimisteenistus-koik-e-haaletamise-logid-ja-e-haaled-on-alles-ja-turvaliselt-hoiustatud
https://arvamus.postimees.ee/7370931/erkki-koort-e-haaled-ja-logid-on-alles-aga-pettusi-avastada-ei-aita - [2021-10-21] A hacker (Artur Boiko) was able to capture a signed i-vote produced by the voting application. The hacker informed the Estonian media that the i-votes cast in the elections are not valid as the DigiDoc4 client showed that the digital signature attached to his i-vote was not valid. RIA explained that the formed signed BDOC container is not a fully completed digital signature, as the OCSP response and timestamp are added on the server side.
https://ekspress.delfi.ee/artikkel/94929547/kurikuulus-hakker-artur-boiko-pakkus-lahkelt-abi-ka-e-haalte-analuusimisel
https://blog.ria.ee/kuidas-allkirjastatakse-e-haali/ - [2021-10-19] Starting with the local elections this year, it is possible to cancel an i-vote in a polling station also on election day. Before 2021 this was not possible, because the voter lists were on paper. Electronic voter lists were used for the first time and it also enabled voters to vote in any polling station in their district as this information is now maintained in a central database. A total of 1,375 computers and 400 printers were used in polling stations all over Estonia. Most of the equipment was leased from Telia. Almost 2,000 people canceled their i-vote with a paper ballot.
https://news.err.ee/1608359610/e-votes-can-be-canceled-by-voting-at-polling-stations-on-election-day
https://news.err.ee/1608374297/almost-2-000-people-canceled-e-vote-with-paper-ballot
https://forte.delfi.ee/artikkel/94901777/1775-kasutatud-arvutit-ja-printerit-mis-saab-edasi-valimistel-kasutusel-olnud-tehnikast - [2021-10-16] On the sixth day of advance voting, voting in polling stations experienced issues from 12:00 to 12:45. The cause was in RIA’s authentication service TARA that is used by the Election Information System VIS3. For security reasons, the number of queries processed from a single IP address was restricted to prevent DoS attacks. During the inaccessibility of VIS3, voters were able to cast paper votes using double envelopes. The electronic list of voters was updated as soon as VIS3 became available again.
https://digi.geenius.ee/rubriik/uudis/ria-loodud-valimiste-infosusteem-tokestas-valimistel-fuusiliselt-haaletamist/ - [2021-10-13] A designer (Stefan Hiienurm) criticized the design of the i-voting application as the application looks like “old-school pirated software” (has been largely the same for about ten years) and there is no indication that this is a service created by the Estonian state. The designer took 30 minutes and sketched how the i-voting application could look.
https://digi.geenius.ee/rubriik/uudis/disainer-stefan-hiienurm-e-haaletuse-tarkvara-naeb-valja-nagu-vanakooli-piraattarkvara/
https://epl.delfi.ee/artikkel/94879211/riigi-valimisteenistuse-juht-arne-koitmae-valijarakenduse-iganenud-kujundusest-sellel-on-teatud-positiivne-efekt - [2021-10-12] I-voters who had their computer time more than 5 seconds off got an error, although their vote was cast successfully.
https://www.facebook.com/eestivalimised/photos/a.158329754211315/4745406862170225/?type=3 - [2021-10-11] During the first 11 minutes after i-voting started, a false message was shown to voters by the voting application, stating that it was a test vote that would not be counted. Around 900 of the first i-voters received such a message. The votes were actually counted, as this was a configuration error having effect only on the text displayed. The end time of the test vote was wrongly configured to be an hour later.
https://twitter.com/valimisedeestis/status/1447445220271009794
https://news.err.ee/1608366156/e-voting-glitch-which-gave-first-900-voters-inaccurate-information-fixed
https://digi.geenius.ee/rubriik/uudis/e-haaletamine-algas-suure-viperusega-inimesed-ei-tea-kas-nende-haal-laks-arvesse-voi-mitte/
https://blog.ria.ee/ria-analuutikud-e-haaletamise-torked-ei-avalda-kriitilist-moju-valimiste-labiviimisse/
https://digi.geenius.ee/rubriik/uudis/kaimar-karu-tanane-e-valimiste-prohmakas-oli-lubamatu-alusetud-spekulatsioonid-said-kutet-juurde/
https://digi.geenius.ee/rubriik/uudis/miks-oli-e-haaletamisega-sel-korral-nii-palju-probleeme/ - [2021-10-11] Users of the latest version of MacOS were unable to i-vote with an ID card until a new voting application was released in the afternoon of the first day of i-voting. More than 30 complaints were registered by technical support service, but hundreds or more users could have been affected. The error was due to the fact that the application was not tested accordingly. I.e., before initially signing the application, the application was not given the right to communicate with the ID card software. The fault was discovered only after i-voting started as the combination of MacOS and ID card was not tested in the i-voting trial.
https://blog.ria.ee/ria-analuutikud-e-haaletamise-torked-ei-avalda-kriitilist-moju-valimiste-labiviimisse/
https://digi.geenius.ee/rubriik/uudis/e-haaletamist-vaevavad-prohmakad-valijad-ei-saanud-rakenduse-oiguses-veenduda-applei-arvutiga-ei-saanud-e-haalt-anda/
https://digi.geenius.ee/rubriik/uudis/riigi-valimisteenuste-juht-tanased-e-haaletuse-prohmakad-ei-ole-aktsepteeritavad/
https://digi.geenius.ee/rubriik/uudis/ronald-liive-kov-valimiste-e-haaletus-on-kobarkakk-mis-enam-kunagi-korduda-ei-tohi/ - [2021-10-11] The documentation for the MacOS voting application on valimised.ee was inaccurate. The file name of the voting application was different (in the documentation “selection.dmg”, actually “KOV_2021_mac.dmg”), and the cryptographic checksum of the voting application file did not match the checksum in the documentation. The differences arose because the MacOS voting application was updated without it being timely reflected in the documentation.
https://twitter.com/silverk_/status/1447466479918665728
https://blog.ria.ee/ria-analuutikud-e-haaletamise-torked-ei-avalda-kriitilist-moju-valimiste-labiviimisse/
https://digi.geenius.ee/rubriik/uudis/e-haaletamist-vaevavad-prohmakad-valijad-ei-saanud-rakenduse-oiguses-veenduda-applei-arvutiga-ei-saanud-e-haalt-anda/
https://digi.geenius.ee/rubriik/uudis/tanel-tammet-e-haaletuse-eilsed-prohmakad-on-naeruvaarsed/
https://digi.geenius.ee/rubriik/uudis/ronald-liive-kov-valimiste-e-haaletus-on-kobarkakk-mis-enam-kunagi-korduda-ei-tohi/ - [2021-10-10] The source code of the i-voting system was made public in GitHub only 10 hours before i-voting began.
https://twitter.com/silverk_/status/1447119983356567552
https://github.com/vvk-ehk/ivxv/commit/49160800174473502e0bee4c8fa87b7ec75bd6f6
https://blog.ria.ee/ria-analuutikud-e-haaletamise-torked-ei-avalda-kriitilist-moju-valimiste-labiviimisse/ - [2021-10-04] Arne Koitmäe, the head of the State Electoral Service (VVK), discusses the possibility to i-vote using smart devices.
https://news.err.ee/1608358833/arne-koitmae-is-estonia-ready-for-m-voting - [2021-09-21] Postimees received sharp criticism for publishing a cartoon, which puts the Estonian i-voting system and the Russian i-voting system on the same stick. Postimees reacted by taking down the cartoon.
https://arvamus.postimees.ee/7342676/varastatud-valimised
https://arvamus.postimees.ee/7343276/margit-sutrop-eetiku-pilgu-labi-mis-on-postimehe-pilapildil-valesti
https://arvamus.postimees.ee/7342960/peatoimetaja-marti-aavik-postimees-ei-kahtle-e-valimiste-usaldusvaarsuses
https://objektiiv.ee/karikatuur-oravast-ja-karikatuurist/ - [2021-09-09] A research article by Sven Heiberg (SCCEIV), Kristjan Krips (Cybernetica/UT), Jan Willemson (Cybernetica/STACC) and Priit Vinkel (Cybernetica/VVK): “Facial Recognition for Remote Electronic Voting – Missing Piece of the Puzzle or Yet Another Liability?”. The authors studied the applicability of facial recognition for verifying voter identities (not specifically for the Estonian i-voting context). The architectural aspects and the main technical and ethical issues were discussed.
https://eprint.iacr.org/2021/1143
https://twitter.com/krips_k/status/1437413997393874950
https://cyber.ee/resources/stories/facial-recognition-elections-biometrics/ - [2021-09-05] A research article by Bingsheng Zhang (Zhejiang University), Zengpeng Li (Shandong University) and Jan Willemson (Cybernetica): “UC Modelling and Security Analysis of the Estonian IVXV Internet Voting System”. The authors claim that the Estonian i-voting system achieves end-to-end verifiability in practice despite the fact that only 4% (on average) of the i-voters verify their votes.
https://arxiv.org/pdf/2109.01994.pdf - [2021-08-28] A research article by Arne Koitmäe (VVK), Jan Willemson (Cybernetica) and Priit Vinkel (Cybernetica): “Vote Secrecy and Voter Feedback in Remote Voting – Can We Have Both?”. The authors discuss the possibility for introducing a feedback channel that would inform a person if someone (or the person themselves) has cast an i-vote in their name. The Estonian i-voting system is used as an example for discussing the possible feedback channel.
https://research.cyber.ee/~janwil/publ/Vote-Secrecy.pdf
https://link.springer.com/chapter/10.1007/978-3-030-86942-7_10 - [2021-08-25] A Belgian cryptographer (Olivier Pereira) described a variant of the revoting attack for the vote verification feature of the Estonian i-voting. By forcing a voter to revote (e.g., by simulating a voting application crash before the verification QR code is shown), on revote a malicious voting application can display the verification QR code from the previous (non-modified) vote cast by the voter, while the revote is substituted with the attacker’s candidate. The benefit compared to the silent revoting is that malware does not have to interact with the ID card (or compromise the voter’s phone in the case of Mobile-ID). An obvious fix is for the i-voting system to allow the verification of the last vote only. The developers of the i-voting system have implemented such a feature, but this feature was not enabled by VVK for the local elections.
https://nitter.eu/ikubjas/status/1430875590677123072#m
https://eprint.iacr.org/2021/1098
Cyber Security Newsletter 2021-08-24
- [2021-08-13] Starting August 23, the Estonian identity cards will be issued containing the ePassport applet that will contain the cardholder’s photo and fingerprints. The residence permit cards have been issued with the ePassport applet already since 2011. The ePassport applet will not be installed on the digital identity cards, the e-resident’s digital identity cards and the diplomatic identity cards. The introduction of the ePassport applet on identity cards is required by an EU regulation.
https://news.err.ee/1608306396/fingerprint-recognition-to-be-added-to-new-id-cards
https://www.riigiteataja.ee/akt/114082021001 - [2021-08-11] Mauno Pihelgas (TalTech) defended his PhD thesis “Automating Defences against Cyber Operations in Computer Networks”.
https://digikogu.taltech.ee/en/Item/beb3e841-9c6e-4496-a73a-17148bc941ef - [2021-08-09] The procurement for the next-generation SIM-less Mobile-ID solution has taken longer than originally planned. The winner should be announced in September and the new solution should be operational from July 1, 2022. The current Mobile-ID contract with SK has been extended by half a year.
https://news.err.ee/1608301968/state-hoping-to-introduce-new-solution-to-replace-mobile-id
https://digi.geenius.ee/rubriik/uudis/uudse-mobiil-id-riigihange-on-veninud-voitja-peab-lahenduse-saama-valmis-vaid-loetud-kuudega/
https://digi.geenius.ee/rubriik/uudis/uudse-mobiil-id-riigihange-on-veninud-voitja-peab-lahenduse-saama-valmis-vaid-loetud-kuudega/ - [2021-08-08] A group of local cyber security enthusiasts are organizing the BSides Tallinn conference with a program committee consisting of well know Estonian cyber security experts. The conference is planned to take place on October 7 in Tallinn.
https://digi.geenius.ee/eksklusiiv/infoturbe-eksperdid-korraldavad-tallinnas-uritust-kuhu-oodatakse-valdkonna-esindajaid-sudant-puistama/
https://tallinn.bsides.ee/ - [2021-08-07] The Data Protection Inspectorate (AKI) has stated that identification check of a person showing a vaccination certificate is allowed only if there is reasonable doubt. For example, if there are obvious discrepancies – the name of the certificate is of the opposite sex, the person’s appearance does not match the date of birth, and so on. Also, the applications used to verify vaccination certificates should not store or forward the data to third-parties. The Minister of Health and Labor suggested the inspection of vaccination certificate only “visually” as it is assumed that most people who live in Estonia are honest.
https://news.err.ee/1608300642/aki-personal-data-must-be-protected-when-checking-covid-19-certificates
https://news.err.ee/1608293448/kiik-vaccination-certificates-will-usually-not-be-scanned - [2021-08-05] RIA has proposed an idea to enable a vaccination status lookup using the document number of the cardholder’s ID card. This would effectively make a person’s vaccination status public, as the document number of a cardholder’s ID card cannot be considered secret. The Health and Welfare Information System (TEHIK) is looking into the legal side of this solution.
https://news.err.ee/1608298248/id-cards-could-be-used-as-vaccination-certificates - [2021-07-29] The web app kontroll.digilugu.ee created to check COVID certificates provides a misleading status response, as it verifies only the authenticity of the certificate and not whether the COVID certificate satisfies legal requirements (e.g., whether test results are not outdated). Currently, the certificate’s compliance to legal requirements have to be inspected manually.
https://digi.geenius.ee/rubriik/uudis/koroonapassi-apis-on-suur-puudus-riik-ei-tea-millal-see-ara-parandatakse/ - [2021-07-28] Geenius journalist Ronald Liive proposes the introduction of a state-level bug bounty program to motive white hat hackers to report vulnerabilities.
https://digi.geenius.ee/rubriik/uudis/ronald-liive-kui-eesti-tahab-tugeva-e-riigi-mainet-hoida-siis-leitakse-otsejoones-raha-heade-hakkerite-premeerimiseks/ - [2021-07-28] A hacker exploited a vulnerability in RIA’s service that allows people to download their document photos using the DigiDoc client. As a result, facial photos of 286,438 persons have been downloaded. The flaw allowed unauthorized retrieval of document photos by sending queries using a fake ID card certificate containing the document holder’s personal identification code. The queries were made from 9,000 different domestic and foreign IP addresses routed through a malware network. The flawed solution was created several years ago. The police has temporarily detained an Estonian citizen, a resident of Tallinn, whose computer was used to download the photos. The downloaded data has been confiscated and the police believes that the data was not transmitted further. The mass download of photos was detected after SK ID Solutions notified RIA of an abnormal number of (OCSP?) queries. The persons whose document photo was downloaded received a notification to their @eesti.ee email addresses. If the leak caused damage, the person can ask RIA for compensation. In RIA’s opinion no damage could have been caused. The government gave RIA 500,000 euros to improve the security of their legacy services.
https://news.err.ee/1608291072/hacker-downloads-close-to-300-000-personal-id-photos
https://www.ria.ee/en/news/police-and-border-guard-board-and-information-system-authority-stopped-illegal-downloading-data.html
https://www.ria.ee/en/news/further-explanation-information-system-authority-ria-data-theft.html
https://news.err.ee/1608294000/ak-ria-unlikely-to-be-fined-over-mass-photo-hack-victims-not-compensated
https://news.err.ee/1608306519/government-sets-aside-500-000-to-update-state-portal-following-july-hack
https://www.err.ee/1608290994/kuberrundaja-laadis-alla-ligi-300-000-dokumendifotot
http://cybersec.ee/storage/20210729_PPA_dokumendifoto_ebaseadusliku_allalaadimise_kohta.eml
https://digi.geenius.ee/eksklusiiv/e-valimiste-ja-lekkinud-dokumendifotode-infosusteemid-vastavad-samale-turvastandardile/
https://digi.geenius.ee/eksklusiiv/ria-juht-dokumendifotosid-varastanud-isik-uritas-radari-alt-labi-libiseda-see-onnestus-tal-suhteliselt-hasti/
https://digi.geenius.ee/rubriik/uudis/riigiportaalis-on-sadakond-komponenti-mille-turvalisuse-kohta-on-riigil-kusimusi/ - [2021-07-24] The number of banking scams is growing. This year already more than 800,000 euros have been lost. If last summer there were 25-30 such cases in one month, then this year there are already more than 50 in one month.
https://www.err.ee/1608287943/telefonipetturite-ohvrite-arv-on-kasvuteel
https://www.err.ee/1608258774/viie-kuuga-on-petukonedega-kaotatud-ule-kahe-miljoni-euro
https://raha.geenius.ee/rubriik/uudis/kelmuse-ohvrid-saavad-tagasi-ule-34-000-euro/
https://www.err.ee/1608188950/pangakelmid-on-inimestelt-valja-petnud-ule-miljoni-euro
https://news.err.ee/1608158017/people-taken-to-the-cleaners-over-the-phone-and-on-dating-websites - [2021-07-22] Gert Auväärt became RIA’s director of the Cyber Security Branch. Lauri Aasmann, the current director of the Cyber Security Branch, will continue as an advisor to the Director General.
https://www.ria.ee/en/news/july-gert-auvaart-will-become-director-cyber-security-branch-information-system-authority.html - [2021-07-21] AS Morrison Invest (morrison.ee) approached the Data Protection Inspectorate (AKI) questioning the legality of kv.ee showing the name of real estate agents for advertisements posted on behalf of legal entities. AKI found it to be in line with good practice, but in turn found that the website morrison.ee that collects personal data does not use an HTTPS connection, the visitor is not informed about the use of Google Analytics cookies, and thirdly, the site does not have the required data protection conditions. AKI issued a precept requesting that these deficiencies be eliminated.
https://digi.geenius.ee/rubriik/uudis/kurioosne-juhus-portaali-tegevuse-kohta-kusimusi-esitanud-kinnisvarafirmal-terendab-kuni-20-miljoni-euro-suurune-sunniraha/
https://aastaraamat.prokuratuur.ee/prokuratuuri-aastaraamat-2020/kuberkuritegevuse-okosusteem-muutunud-teenusepohiseks - [2021-07-21] Estonian citizen Pavel Tsurkan (33) was extradited to the US where he pled guilty for building a botnet of more than 1000 routers and allowing his criminal clients to use them as proxies routing their malicious internet traffic through the compromised routers. He also pled guilty in a second case for operating the Crypt4U service since 2013 that allowed criminals to obfuscate their malware. The Estonian national faces two 10-year prison sentences.
https://www.justice.gov/usao-ak/pr/estonian-citizen-pleads-guilty-computer-fraud-and-abuse
https://ekspress.delfi.ee/artikkel/92169861/koroonaviirus-ei-paasta-eesti-kodanikku-valjaandmisest-usa-le - [2021-07-15] Cybernetica has completed the analysis of implementing facial recognition in the Estonian i-voting. The analysis points out problems with false negatives, the requirement for high quality video cameras, privacy issues related to the fact that the captured video may contain other persons and a voter’s home interior, and points out a list of legal challenges. The report concludes that facial recognition is still in its infancy and should be first piloted within other public services.
https://www.ria.ee/en/news/implementation-biometrics-e-voting-requires-prolonged-testing.html
https://www.ria.ee/sites/default/files/content-editors/publikatsioonid/biomeetria-aruanne.pdf - [2021-07-15] A Geenius journalist had a look at the mysterious information system SITIKAS created by the State Situation Center. The system is meant to help decision makers and almost 2.8 million euros have been spent on its development. The system uses mostly publicly available information, but the content of the system is classified. Allegedly, the system generates various reports and uses machine learning and neural networks.
https://digi.geenius.ee/eksklusiiv/esimest-korda-avalikkuse-ees-salaparane-infosusteem-sitikas-aitab-peaministril-paremaid-otsuseid-teha/ - [2021-07-13] The Data Protection Inspectorate (AKI) has reprimanded the Health Board for its official contacting TalTech to ask whether one of the Health Board employees studies in TalTech. TalTech disclosed the information over phone without identifying the questioner and without the legal basis.
https://digi.geenius.ee/rubriik/uudis/uus-skandaal-terviseametis-osakonnajuhataja-nuhkis-tootaja-jarel-kes-hiljem-koondati/
https://digi.geenius.ee/rubriik/uudis/terviseametist-koondatud-ametnik-tegu-on-sustemaatilise-tookiusamisega/ - [2021-07-13] For DDOC signatures that have been timestamped after 2018-07-01, the ID software will show a warning “The signature is valid (with a warning)”. Signatures in DDOC format use the outdated SHA-1 hash function whose collision resistance was practically broken in February 2017 and hence any DDOC signatures created since then could be challenged.
https://www.ria.ee/en/news/new-version-id-card-software-will-change-status-ddoc-signatures.html
https://www.ria.ee/et/uudised/id-kaardi-tarkvara-uus-versioon-muudab-ddoc-allkirjade-staatust.html - [2021-07-09] RIA has closed an information leak in the state portal eesti.ee, where personal data of 336,733 people could be accessed. The data contained the first and last names, personal identification codes, places of work and, in some cases, links to previous positions. The leak was in the self-service environment that gave representatives of companies the right to manage the access rights of their employees. The leak was part of the intended functionality that was introduced about ten years ago when the approach to data protection and privacy was different than today. The issue was reported by an attentive user. RIA has no information on whether anyone had saved the data.
https://www.ria.ee/en/news/data-more-300000-people-were-available-state-portal.html
https://digi.geenius.ee/rubriik/uudis/riigiportaalis-olid-kattesaadavad-ule-300-000-inimese-andmed/ - [2021-07-01] Personal data of 96 drone pilots was visible in the website of the Transport Agency for two hours. The personal data contained the pilots’ home addresses, phone numbers, e-mail addresses and personal identification numbers. Due to the leak, the registration numbers issued to the pilots will be replaced. Piksel OÜ developed the flight safety monitoring information system (LOIS). The security of the system was tested, but the flaw was detected only after the information system went into production.
https://digi.geenius.ee/rubriik/uudis/ameti-vea-tottu-paases-iga-huviline-ligi-droonilennutajate-andmetele/
https://digi.geenius.ee/rubriik/uudis/transpordiameti-leke-puudutas-pea-sadat-droonilennutajat-juhtunust-informeeriti-andmekaitse-inspektsiooni/ - [2021-06-29] MKM is using the EU structural funds to produce 60 thematic biographical video interviews to document the history of the Estonian digital state. The plan is to collect the memories and knowledge of the birth and formation of the digital state, including the development of eID, i-voting and cyber security. The work will be completed in the beginning of 2022.
https://mkm.ee/et/uudised/eesti-riik-hakkab-talletama-digiriigi-ajalugu - [2021-06-29] The UT computer science BSc student Peeter Vahe in his BSc research discovered a race condition flaw in the Tartu Smart Bike Share system, which allows a user to unlock 2 bikes at once using a single account.
https://www.youtube.com/watch?v=2tKBlegvGXY
https://comserv.cs.ut.ee/ati_thesis/datasheet.php?id=71618&year=2021&language=en - [2021-06-18] The Supreme Court decided that the procedure for storage and use of communications metadata is in conflict with the law of the EU and therefore the state cannot request this data for criminal investigations. The EU law forbids retaining the communication data of all users without distinction, regardless of whether they have any connection with serious crime (the current practice of the Electronic Communications Act). This decision will affect the proceedings where phone logs are the most substantial evidence. The Ministry of Justice is looking for a solution to agree on some kind of a new metadata keeping obligation.
https://www.isoc.ee/nuhkimishaav-sonavabaduse-sudames/
https://www.riigikohus.ee/et/uudiste-arhiiv/riigikohus-riik-ei-saa-sidefirmade-kogutud-andmeid-kuritegude-uurimiseks-valja-nouda
https://news.err.ee/1608251514/supreme-court-state-cannot-demand-telephone-communication-data
https://forte.delfi.ee/artikkel/93776527/riigikohus-keelas-riigil-sidefirmade-andmeid-kuritegude-uurimiseks-valja-nouda
https://news.err.ee/1608252387/prosecutor-supreme-court-phone-data-decision-may-stop-some-proceedings
https://news.err.ee/1608253017/samost-ja-sildam-supreme-court-communications-call-points-to-problems
https://www.err.ee/1608251964/vaher-sideandmeteta-laheb-kuritegude-uurimine-keerulisemaks
https://news.postimees.ee/7278096/interior-ministry-solving-some-crimes-will-become-impossible
https://news.err.ee/1608266760/justice-ministry-looking-for-ways-to-use-communications-data - [2021-06-16] Kaie Maennel (TalTech) defended her PhD thesis “Advancing Cybersecurity Education through Learning Analytics”.
https://digikogu.taltech.ee/en/Item/d01c0b17-3b4b-41c5-ae24-e75b6128a183 - [2021-06-15] An MSc thesis defended at UT brought to light a security risk concerning signing documents with an ID card via a browser. More specifically, the fact that the signatories are not able to see what exactly the service provider is asking them to sign. The thesis provides the implementation of two solutions. RIA is looking to introduce a solution as well.
https://digi.geenius.ee/eksklusiiv/eesti-id-kaardil-on-kogu-aeg-olnud-allkirjastamisel-turvarisk-mida-selle-aastani-ei-peetud-oluliseks/
https://comserv.cs.ut.ee/ati_thesis/datasheet.php?id=72487&year=2021&language=en - [2021-06-15] A bill has been passed to create a central biometric database ABIS for storing facial images and fingerprints, as currently such data is scattered between several databases. No new data will be collected. The bill has raised concerns regarding cross use of biometric data, as it would allow fingerprints and facial images collected for identification purposes (when applying for an identity document) to be used in criminal proceedings. However, it turns out that since 2012 identity documents database has been used in criminal investigations. While it was possible to compare fingerprints against all fingerprints in the database, ABIS plans to provide the technological capability to match a person’s facial image against facial images stored in the database.
https://news.err.ee/1608162490/estonia-to-create-database-for-biometric-identification-system
https://news.postimees.ee/7272664/abis-holds-uncertainty-for-the-future
https://news.err.ee/1608241671/ekre-stalls-riigikogu-s-work-over-personal-identification-database-bill
https://news.err.ee/1608250773/interior-minister-right-to-decide-over-use-of-data-can-be-discussed
https://news.err.ee/1608260931/kaljulaid-promulgates-abis-cross-use-of-data-law
https://www.err.ee/1608247482/oiguseksperdid-naevad-probleemi-abis-e-info-ristkasutuses
https://www.err.ee/1608250389/uno-lohmus-abis-kui-pohiseaduslik-probleem
https://www.err.ee/1608262158/oiguskantsler-naeb-abis-es-mitut-tosist-probleemi
https://www.err.ee/1608261951/helme-inimesed-voiksid-kohtus-nouda-oma-andmete-kustutamist-abis-est
https://www.err.ee/1608240822/jaani-abis-e-eelnou-kooskolastas-siseminister-mart-helme - [2021-06-14] Cyber Security Summer School 2021 took place during June 14-16 in virtual format. The focus of this year’s summer school was on real-world internet voting systems.
https://www.cs.ut.ee/en/news/international-cyber-security-summer-school-focuses-online-voting-technologies-around-world
https://studyitin.ee/c3s2021 - [2021-06-11] The Transport Administration is developing a database in which private parking lots from Helsinki and Riga can obtain personal data of car owners registered in Estonia. The Estonian vehicle owner database has now been opened to Estonia’s private parking lots for imposing fines.
https://news.err.ee/1608243435/parking-tickets-from-nearby-countries-will-soon-find-their-estonian-owners - [2021-06-04] The President of Estonia, Kersti Kaljulaid awarded ENISA’s Executive Director, Juhan Lepassaar, the Order of the White Star, 3rd Class state decoration for advancing EU cybersecurity.
https://news.err.ee/1608120073/president-awards-152-state-decorations
https://nitter.eu/enisa_eu/status/1400819371409297411 - [2021-06-03] MSc thesis by Taavi Turu (TalTech): “The Role of Co-production in National Cyber Security and Cyber Resilience of Critical Infrastructures: the Case of Estonian Defence League’s Cyber Unit”
https://digikogu.taltech.ee/en/Item/b32ff254-b558-4571-8fc9-7127b1c5f408 - [2021-06-02] A new Estonian information security standard (E-ITS) has been compiled to replace the voluminous information security standard ISKE. The standard contains data on security threats and provides measures for public sector authorities.
https://www.ria.ee/en/news/ria-has-compiled-information-security-guidebook-public-sector.html
https://eits.ria.ee/ - [2021-06-02] RIA organized a seminar “Cyber Security in Estonia 2021” in English. Presentations by Gert Auväärt, Tõnu Tammer, Perit Kirkmann, Mark Erlich, Lauri Tankler and Märt Hiietamm are available in RIA’s youtube channel.
https://www.youtube.com/playlist?list=PLNPWRftK1TNr0A3WrxK05IOVCaDlsf6nh - [2021-05-31] Due to a database error, the health information system was not available for more than two and a half hours in the middle of the working day.
https://www.err.ee/1608230814/tervise-infosusteem-oli-esmaspaeval-tehnilise-vea-tottu-paar-tundi-maas
https://www.ria.ee/et/uudised/olukord-kuberruumis-mai-2021.html - [2021-05-28] Arnis Parsovs (UT) has published “Security Analysis of RIA’s Authentication Service TARA”. The analysis finds that the TARA protocol might be susceptible to man-in-the-middle and phishing attacks.
https://cybersec.ee/storage/20210528_tara_analysis.pdf
https://digi.geenius.ee/rubriik/uudis/loputoos-leiti-mitu-kohta-kuidas-riiklikku-autentimisteenust-veel-turvalisemaks-muuta/ - [2021-05-26] The TV investigative program Pealtnägija has published materials and insights from the “passport mafia Marika” criminal case of running an illegal document business with insiders from PPA. A trap was set up with the help of a secret agent who was interested in a document. Video footage and other materials from covert police surveillance activities are demonstrated.
https://www.err.ee/1608225496/salajased-kaadrid-pealtnagijas-ulatuslik-passiari-toimis-kui-kellavark - [2021-05-21] Following a scheduled maintenance at SK ID Solutions, the issuance of Mobile-ID and Smart-ID certificates were disrupted.
https://news.err.ee/1608220819/issuing-of-digital-id-verification-services-encounters-glitches-friday
https://news.err.ee/1608221635/smart-id-and-mobile-id-new-registrations-back-online
https://digi.geenius.ee/rubriik/uudis/mobiil-idd-vaevavad-teist-paeva-jarjest-probleemid/
https://digi.geenius.ee/rubriik/uudis/ria-soovib-hiljutiste-mobiil-id-ja-id-kaardi-katkestuste-kohta-lisainfot/
https://www.skidsolutions.eu/en/News/mobile-id-and-smart-id-services-were-interrupted/ - [2021-05-15] An Estonian accounting software company fell victim to a ransom attack and through it the attackers gained access to the systems of one of the Lääne County rural municipality governments. The attack was discovered by CERT-EE before the attackers were able to cause damage.
https://www.ria.ee/et/uudised/olukord-kuberruumis-mai-2021.html
https://www.ria.ee/et/uudised/mais-runnati-it-teenusepakkujat-ning-jouti-seelabi-tema-kliendini.html
https://forte.delfi.ee/artikkel/93831843/juhtub-ka-eestis-runnak-digiteenusepakkujale-joudis-selle-kliendini-valja - [2021-05-13] RIA refuses to disclose how many sessions at once the authentication service TARA can handle, as this would reveal too much of the e-Estonia capability to potential attackers. TARA has been used up to 150,000 times a day.
https://digi.geenius.ee/eksklusiiv/kui-palju-paaseb-korraga-e-valima-riigiportaali-voi-patsiendiportaali-amet-salatseb-ja-ei-tee-infot-avalikuks/ - [2021-05-13] A court in the US convicted 3 IT specialists that were residing in Estonia for providing bulletproof hosting services to cyber criminals from 2009 to 2015.
https://news.postimees.ee/7247575/estonia-s-it-talents-sold-international-services-to-cybercriminals
https://www.justice.gov/opa/pr/four-individuals-plead-guilty-rico-conspiracy-involving-bulletproof-hosting-cybercriminals
https://therecord.media/botnet-operator-who-proxied-traffic-for-other-cybercrime-groups-pleads-guilty/
https://news.err.ee/1608213967/daily-estonia-based-cyber-criminals-active-for-years-to-face-us-trial
https://news.postimees.ee/7247575/estonia-s-it-talents-sold-international-services-to-cybercriminals - [2021-05-12] There is a plan to amend the Public Information Act that would allow for the classification of documents to last indefinitely. Currently, the access restriction limit for classified documents “information intended for internal use” (AK) is five years. This limit can be extended by another five years to a total maximum of 10 years.
https://news.err.ee/1608210079/defense-minister-documents-should-not-be-classified-for-over-10-years - [2021-05-11] The Data Protection Inspectorate (AKI) has released the 2020 yearbook.
https://aastaraamat.aki.ee/sites/default/files/aastaraamatud/aastaraamat_2020.pdf - [2021-05-05] The Estonian Digital Society Development Plan 2030 has been released. One of the areas is national cyber security. Among the plans is to: improve the personal data tracker service; develop the possibility to get all the data stored in the country from the state portal; create a national eID that is free of physical media; update the national cyber security governance model to clarify roles, responsibilities and tasks of organizations; increase the capacity of academic institutions and development centers to implement nationally important cyber security R&D projects.
https://news.err.ee/1608202027/it-minister-requesting-feedback-on-future-of-digital-society
https://mkm.ee/et/uudised/it-minister-saatis-konsultatsioonile-digiuhiskonna-tulevikuvisiooni-eesti-tais-digivage - [2021-05-03] Liisa Past (former employee of Cybernetica and RIA) has started working as an information security manager (CISO) at the Information Security Department of the Information Technology and Development Center (SMIT) of the Ministry of the Interior.
https://www.smit.ee/et/uudised/smiti-infoturbejuhina-alustas-toeoed-liisa-past-97 - [2021-04-27] Over the last couple of years, most of the security testing procurements have been won by the company Clarified Security OÜ. Last year, procurements for up to 2 million and 3.5 million euros were won. Paevaleht looked at the similarities of the procurement specifications and discussed the need to introduce mandatory rotation of security testers.
https://epl.delfi.ee/artikkel/93253019/koik-munad-uhes-korvis-suure-osa-e-riigi-turvatestimise-hankeid-voidab-uksainus-ettevote
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisuse_aastaraamat_2021_eng_final.pdf - [2021-04-22] Äripäev has published a special issue “Cyber security 2021” covering a variety of cyber security related topics: cyber hygiene, i-voting, cybercrime, training of cyber experts and other topics.
https://www.aripaev.ee/lisa/2021/04/22/kuberturvalisus-22042021 - [2021-04-22] Due to a hardware failure, the state authentication service TARA was not available for 45 minutes, as a result of which it was not possible to log into any service that uses TARA.
https://www.ria.ee/et/uudised/olukord-kuberruumis-aprill-2021.html - [2021-04-15] The government introduced a draft legislation to strengthen rules for assessing eID system trustworthiness and delimiting institutional responsibilities. In addition, RIA will be able to check whether providers of public e-services fulfill the obligation of recognizing international eID solutions arising from the eIDAS regulation.
https://news.err.ee/1608178582/government-endorses-regulation-updates-to-e-identification - [2021-04-13] Due to a software error, the digital prescription service was not available for almost 7 hours.
https://www.ria.ee/et/uudised/olukord-kuberruumis-aprill-2021.html - [2021-04-09] Arnis Parsovs (UT) defended his PhD thesis “Estonian Electronic Identity Card and its Security Challenges”.
https://dspace.ut.ee/handle/10062/71481
https://www.uttv.ee/naita?id=31267
https://blog.cs.ut.ee/2021/04/07/phd-thesis-shows-that-id-card-issues-reoccur-because-they-are-not-learned-from/
https://digi.geenius.ee/rubriik/uudis/riik-valjastas-uheksa-aasta-jooksul-ule-miljoni-vigase-id-kaardi/ - [2021-04-07] The Mobile-ID and Smart-ID phishing attackers who were detained in Romania last September, sent emails to 100,000 Estonians and managed to steal money from the accounts of nearly 40 people in the total amount to more than 100,000 euros.
https://digi.geenius.ee/rubriik/uudis/rumeenias-tabatud-kuberpattide-ohvriks-langes-ligi-40-eestlast-kahju-ule-100-000-euro/
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisuse_aastaraamat_2021_eng_final.pdf - [2021-04-07] RIA released the yearbook “Cyber Security in Estonia 2021”. Some of the covered topics: DDoS ransom attacks, ransomware attacks, phishing attacks, E-ITS security standard, DigiTest cyber hygine training platform, cyber diplomacy, 5G security.
https://news.err.ee/1608168793/ria-yearbook-cyber-criminals-took-advantage-of-covid-19-fears
https://www.ria.ee/en/news/new-yearbook-information-system-authority-ria-cyber-security-summarises-most-influential.html
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisuse_aastaraamat_2021_eng_final.pdf - [2021-04-05] Based on a precept issued by the Technical Supervision Authority (TTJA), Zone Media OÜ blocked access to the websites koroonavabaeesti.ee and kloordiioxidiinfokeskus.ee, which were used to spread misinformation about the anti-COVID drug. The websites were registered by a private person and used the web hosting service of Zone Media OÜ.
https://digi.geenius.ee/eksklusiiv/terviseamet-tahab-blokeerida-ligipaasu-eesti-veebilehtedele-mis-jagavad-koroonaviiruse-kohta-valeinfot/
https://digi.geenius.ee/rubriik/uudis/tarbijakaitseameti-mahitusel-peatati-ligipaas-lehele-mis-vaitis-et-koroonat-saab-ravida-mmsiga/
https://digi.geenius.ee/rubriik/uudis/veebimajutaja-zone-uurib-kuidas-piirata-ligipaasu-teiselegi-vaarinfot-levitavatele-veebilehele/
https://digi.geenius.ee/rubriik/uudis/zone-sulges-ttja-ettekirjutusel-mmsi-koroonaravimina-reklaaminud-veebilehe/ - [2021-04-04] Personal data of 533 million Facebook users leaked online. The leak contains personal data of 87,533 users from Estonia. The data includes their phone numbers, Facebook IDs, full names, locations, birthdates, bios, and (in some cases) email addresses. The dataset was collected by crawling the data made public by users themselves.
https://www.theverge.com/2021/4/4/22366822/facebook-personal-data-533-million-leaks-online-email-phone-numbers
https://tehnika.postimees.ee/7220357/facebook-suudistab-kasutajaid-selles-et-nende-andmed-hakkerite-katte-sattusid
https://www.ria.ee/et/uudised/olukord-kuberruumis-aprill-2021.html - [2021-03-31] The government approved an amendment enabling automatic forwarding of a person’s @eesti.ee mailbox to their contact information in the population register. The population register has almost every person’s contact information (email address and phone number) as it is collected, for instance, when applying for an identity document. Before this change, around 413,000 people of 1.3 million had manually enabled forwarding for their @eesti.ee address. The opt-out in @eesti.ee forwarding was introduced after many elderly people missed invitations to be vaccinated.
https://www.ria.ee/en/news/state-will-link-persons-eestiee-mailbox-their-contact-information-population-register.html
https://www.ria.ee/en/news/information-system-authority-forwarded-state-portal-mailboxes.html
https://news.err.ee/1608146752/people-s-contact-information-to-be-used-to-send-eesti-ee-notifications
https://digi.geenius.ee/rubriik/uudis/karm-kusimus-mis-on-eesti-ee-meiliaadressi-mote-ja-kas-seda-on-uldse-vaja/
https://digi.geenius.ee/rubriik/uudis/eesti-ee-meiliaadressi-on-sel-kuul-ara-suunanud-ligi-16-000-inimest/ - [2021-03-31] E-residency background checks will become more thorough. New data sought from applicants includes information about misdemeanor proceedings initiated against the applicant, prohibition on business as well as bank accounts owned by the applicant or their businesses. To improve user friendliness, PPA has created a new self-service environment for e-residents at https://eresident.politsei.ee.
https://news.err.ee/1608161419/e-residency-background-checks-to-become-more-thorough - [2021-03-26] The Latvian Data Protection Inspectorate did not apply sanctions to the company responsible for the e-shop charlot.ee database leak in which personal data of 14,000 Estonians was made publicly available. According to the Latvian inspectorate, they learned about the personal data of only 168 Latvians being compromised. The Estonian Data Protection Inspectorate (AKI) now regrets not initiating proceedings, as Charlot OÜ had appointed Estonia as the data controller and hence the server’s location in Latvia should not have played a role.
https://digi.geenius.ee/rubriik/uudis/aki-todeb-et-nad-eksisid-eesti-uhe-suurima-andmelekke-menetlemisel/
https://digi.geenius.ee/rubriik/uudis/latlased-ei-algatanud-eesti-ajaloo-suurima-andmelekke-osas-jarelevalvemenetlust/ - [2021-03-19] The attackers who downloaded 350GB of data from government servers last November used the security testing tool Acunetix to discover the .git catalogue which had remained public by accident. By using information in the .git catalogue, the attackers were able to upload malicious code and gain access to the servers. The same scanning pattern has been observed lately against companies in the private sector. RIA has purchased a license to the Acunetix tool and is offering it to the public sector.
https://digi.geenius.ee/rubriik/uudis/hakkerid-leidsid-uue-sihtmargi-eesti-ettevotted-mis-teevad-riigiga-koostood/
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisuse_aastaraamat_2021_eng_final.pdf - [2021-03-17] A former employee of the newspaper Raplamaa Sõnumid was convicted in court of illegally disrupting the operation of the newspaper’s computer system. The employee left the newspaper in 2015 and committed the crime four years later by using Google’s Search Console tool to hide the website https://sõnumid.ee in the Google search engine. The conviction of the county court and the circuit court has been appealed to the Supreme Court.
https://digi.geenius.ee/rubriik/uudis/googlei-otsingus-endise-tooandja-veebilehe-varjamine-toi-kaasa-kriminaalasja/ - [2021-03-17] The Prosecutor’s Office has released a yearbook about 2020. In 2020, various covert surveillance operations were carried out on 729 people. There have been cases where criminals have compromised state systems to mine cryptocurrencies. One of the biggest achievements last year was the detention of three Romanian cyber criminals last September, which was possible thanks to direct contacts with foreign partners. In one criminal case, it was possible to seize 1 million worth of cryptocurrency by transferring it to a wallet held by police. It is not uncommon to see criminal cases being closed without gathering additional evidence if the identified IP address is located abroad.
https://aastaraamat.prokuratuur.ee/prokuratuuri-aastaraamat-2020/jalituse-jarelevalvest
https://aastaraamat.prokuratuur.ee/prokuratuuri-aastaraamat-2020/kuberkuritegevuse-okosusteem-muutunud-teenusepohiseks
https://digi.geenius.ee/rubriik/uudis/prokuror-meil-on-viiteid-et-kurjategijad-kaevandasid-riigi-vahenditega-kruptoraha/ - [2021-03-17] Due to an error on the SK ID Solutions side, 6000 Smart-ID users received a false SMS alert as if someone had just created a Smart-ID account on their behalf. Turns out the alert was not false, but was sent with a delay. Smart-ID users who created an account on 2021-02-27 or later received the alert on 2021-03-17.
https://forte.delfi.ee/artikkel/92868487/6000-inimest-said-tana-eksliku-hoiatusteate-smart-id-loomise-kohta
https://www.skidsolutions.eu/en/News/sms-notifications-for-smart-id-account-creation-were-sent-with-delay/ - [2021-03-08] RIA has published a technical report produced by Cybernetica: “Cryptographic algorithms and their support in libraries and information systems”. The report looks at cryptographic primitives and protocols, federated authentication protocols (OAuth, OpenID), cryptographic libraries and crypto file containers. The use of PGP is not recommended anymore.
https://www.ria.ee/sites/default/files/content-editors/publikatsioonid/cryptoreport2021.pdf
https://www.ria.ee/et/kalender/kruptoalgoritmid-ning-nende-tugi-teekides-ja-infosusteemides.html - [2021-03-04] The birth registration service in the self-service portal of the population register (rahvastikuregister.ee) allows the lookup of a mother’s name and personal identification code by entering a newborn’s personal identification code. A Geenius journalist tried 50 random personal code combinations and in 9 cases was able to see the child’s mother’s name and personal identification code and was able to apply to be registered as the father of the child. A rate limit for number of queries is not present. The officials do not consider this a risk as it only reveals the fact that someone has given birth. The queries leave a trace that can be seen in the data tracker, but to see who exactly viewed the data the child’s mother must contact the Ministry of Interior. The Data Protection Inspectorate (AKI) sees no problem.
https://digi.geenius.ee/eksklusiiv/iga-huviline-saab-e-rahvastikuregistris-naha-vastsundinud-laste-emade-nimesid-ja-isikukoode/ - [2021-03-02] The European Court of Justice ruled that the Prosecutor’s Office in Estonia should not grant access to communications metadata as it is not a fully independent party in the conduct of criminal investigations. A good deal of evidence in thousands of criminal cases may prove inadmissible.
https://curia.europa.eu/jcms/upload/docs/application/pdf/2021-03/cp210029en.pdf
https://news.err.ee/1608130099/thousands-of-pieces-of-evidence-could-disappear-from-criminal-cases
https://ekspress.delfi.ee/artikkel/92783317/advokaat-kas-moosivarguse-uurimine-oigustab-inimese-lausjalitamist
https://news.err.ee/1608191572/lawyers-prosecutor-s-office-riding-roughshod-over-ecj-data-stance
https://news.err.ee/1608209794/bill-initiated-to-use-communications-data-in-court-cases
https://www.err.ee/1608200386/ministeerium-ei-kavatse-piirata-mobiiliandmete-kasutamist
https://news.err.ee/1608231447/bill-aligning-prosecutor-data-collection-with-eu-law-passes-first-reading - [2021-03-02] MKM has submitted a draft regulation on the security of communications networks. The change mostly affects the radio equipment on the mobile operator masts. The transition away from Huawei equipment would cost Elisa up to 54 million euros over the next five years, for Telia up to 5 million euros, but for Tele2 there would be no additional costs. The government will vote on the draft bill in the autumn.
https://mkm.ee/et/uudised/minister-sutt-esitas-valitsusele-sidevorkude-turvalisuse-eelnou
https://www.err.ee/1608127927/huawei-seadmete-keelamine-voib-tuua-vorkudele-kumneid-miljoneid-kahju
https://www.err.ee/1608250608/huawei-seadus-lukkub-sugisesse-5g-sagedusalade-konkurssi-pole-seni-oodata - [2021-03-02] The National Audit Office (Riigikontroll) has raised several issues related to X-Road. The audit has found that in many cases X-Road data service providers did not enter into service agreements and the public authorities have not audited whether private operators were implementing adequate security risk mitigation measures. The regulation should clarify which security measures should be implemented at what level. The audit has found that there has been one significant disruption in X-Road services during the last three years due to the failure of key components.
https://news.err.ee/1608127567/audit-office-it-security-of-firms-using-x-road-not-sufficiently-checked
https://digi.geenius.ee/rubriik/uudis/riigikontroll-manitseb-keegi-ei-kontrolli-x-teed-kasutavate-eraettevotete-turvalisust/
https://www.ria.ee/et/uudised/riigikontroll-riigi-infosusteemi-amet-taganud-x-tee-tookindluse-kuid-x-teed-kasutavate.html
https://blog.ria.ee/x-tee-liikmete-ule-tuleb-tohustada-kontrolli/ - [2021-03-01] A research article by Sven Heiberg, Kristjan Krips and Jan Willemson (Cybernetica): “Mobile Voting – Still Too Risky?”. The article is mainly based on the report “Mobile voting feasibility study and risk analysis” that was released by Cybernetica in April 2020.
https://research.cyber.ee/~janwil/publ/mvoting-design.pdf - [2021-02-01] Denial-of-service extortion attack took place against one of the banks in Estonia. As a result, online banking, card payments and internal bank services were disrupted.
https://www.ria.ee/et/uudised/olukord-kuberruumis-veebruar-2021.html - [2021-01-22] Thousands of .ee domains were unavailable for a few hours due to an administrative error made by the Zone Media in their name server solution.
https://www.ria.ee/et/uudised/olukord-kuberruumis-jaanuar-2021.html - [2021-01-18] For a few hours hundreds of websites hosted at Zone Media were not available due to a network switch failure.
https://www.ria.ee/et/uudised/olukord-kuberruumis-jaanuar-2021.html
https://blog.zone.ee/2021/01/20/katkestuse-post-mortem/ - [2021-01-15] Denial-of-service attacks took place against Estonian financial institutions and technology companies, accompanied by blackmail letters. The ransom demands were between 0.5 to 10 bitcoins. The longest interruption lasted for about six hours. According to RIA, the attackers did not receive any ransom money from Estonia.
https://www.ria.ee/et/uudised/olukord-kuberruumis-jaanuar-2021.html
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisuse_aastaraamat_2021_eng_final.pdf
Cyber Security master’s theses defense in TalTech/UT (August 2021)
Defence of master theses of Cyber Security curriculum on August 10th 2021 online
Time: 09:00
Student: Ilker Furkan Kahyalar
Title: A Comparative Study of Virtualization Solutions for Cybersecurity Labs
Supervisor: Risto Vaarandi
Reviewer: Toomas LepikTime: 09:40
Student: Martin Välbe
Title: Benchmarking of Android Applications’ System Calls Behavior: Implications for Malware Detection
Supervisor: Alejandro Manzanares, Tarmo Oja
Reviewer: Risto VaarandiTime: 10:20
Student: Mohamed Nasef Ibrahim Mohamed
Title: Towards a new method for teaching malware analysis for Cyber Security students
Supervisor: Toomas Lepik
Reviewer: Pavel TšikulTime: 11:30
Student: Thilina Nenathunga
Title: Identity and Access Management, and Audit trails for Continuous Delivery infrastructure on Amazon Web Services platform
Supervisor: Toomas Lepik
Reviewer: Risto VaarandiTime: 12:10
Student: Bisrat Woldeyes Ambaye
Title: Adversarial Machine Learning Poisoning Attacks on Mobile Check Deposits
Supervisor: Alejandro Manzanares
Reviewer: Matthew SorellTime: 12:50
Student: Md Forhad Hossain
Title: Adapting Active Learning for Intrusion Detection Within Security Operation Center Context
Supervisor: Hayretdin Bahsi
Reviewer: Alejandro ManzanaresTime: 14:00
Student: Muhammad Junaid Farrukh
Title: Evaluation of Agile Threat Modeling Methods to Identify Threats to Privacy in Robotic Systems
Supervisor: Andrew Roberts
Reviewer: Shaymaa KhalilTime: 14:40
Student: Raigo Vilur
Title: Evaluation of Secure Channel Communication for Cloud-Based Autonomous Vehicle Telematics
Supervisor: Andrew Roberts, Nikita Snetkov
Reviewer: Olaf Maennel
Defence of master theses of Cyber Security curriculum on August 11th 2021 online
Time: 12:00 (closed defence)
Student: Wellington Oscar Alves De Souza
Title: Cybercrime knowledge of identity theft investigators in Estonian FinTech
Supervisor: Maria Claudia Solarte Vasquez, Sten Mäses
Reviewer: Toomas VaksTime: 12:40
Student: Abhisek Ojha
Title: Cybersecurity Awareness among Engineering students of West Bengal , India
Supervisor: Sten Mäses
Reviewer: Kaido KikkasTime: 13:40
Student: Alex Bindevald
Title: Cyber Security at schools – challenges, opportunities and needs for CTF-solution
Supervisor: Birgy Lorenz
Reviewer: Sten MäsesTime: 14:20
Student: Orkhan Rustamli
Title: Analysis of Cyber Security Awareness Level of Secondary High-school Students: The Case of Azerbaijan
Supervisor: Kaie Maennel
Reviewer: Sten Mäses
Defence of master theses of Cyber Security curriculum on August 12th 2021 online
Time: (withdrawn)
Student: Anupam Rakshit
Title: Pragmatic Comparison of Machine Learning Models to Detect The Type Of Attacks In An IoT Network Traffic
Supervisor: Pelle Jakovits
Reviewer: Alejandro ManzanaresTime: 10:00
Student: Vasile Tarlev
Title: Compatibility of the European Blockchain Service Infrastructure with the European Union General Data Protection Regulation
Supervisor: Anna-Maria Osula, Andres Ojamaa, Vladimir Rogojin
Reviewer: Eneken TikkTime: 10:40
Student: Henry Ochieng’ Dola
Title: Cyber Threat Modeling of A Water Quality Monitoring System
Supervisor: Hayretdin Bahsi, Jeffrey Andrew Tuhtan
Reviewer: Andrew RobertsTime: 11:20
Student: Andris Männik
Title: Cyber Awareness Verification Using Phishing Assessments
Supervisor: Kaido Kikkas
Reviewer: Kaie MaennelTime: 12:30
Student: Oluwatosin Soremekun
Title: Method for cyber threat modelling and validation of public transportation systems
Supervisor: Hayretdin Bahsi, Andrew Roberts
Reviewer: Liivar LutsTime: 13:10
Student: Tino Apostolovski
Title: Design of a system for secure communication between ATC and Drone Pilot
Supervisor: Olaf Maennel, Dariana Khisteva
Reviewer: Andrew Roberts, Nikita SnetkovTime: 13:50
Student: Gulkhara Babayeva
Title: Domain Ontology for Cyber Defense Exercises
Supervisor: Olaf Maennel, Kaie Maennel
Reviewer: Rain Ottis
August 12, 2021 online:
Time: 09:00
Student: Olorunshe Temilola Esther (Cyber Security MSc)
Title: Recognition of Phishing Attacks and its Impact: A Case Study
Supervisor: Raimundas Matulevicius
Reviewer: Abasi-Amefon Affia
Cybersecurity related bachelor’s and master’s theses in University of Tartu 2021 (June)
The defences are taking place on the first and second week of June.
June 2, 2021:
Time: 09:45
Student: Toomas Aleksander Veromann (Software Engineering MSc)
Title: WYSIWYS Extensions to the Estonian ID Card Browser Signing Architecture
Supervisor: Arnis Paršovs
Reviewer: Mart SõmermaaTime: 10:30
Student: Sébastien René Baptistin Boire (Computer Science MSc)
Title: Credential Provisioning and Peer Configuration with Extensible Authentication Protocol
Supervisor: Tuomas Aura, Dominique Unruh
Reviewer: Arnis ParšovsTime: 10:30
Student: Mariia Bakhtina (Innovation & Technology Management MA)
Title: Securing Passenger’s Data in Autonomous Vehicles
Supervisor: Raimundas Matulevičius, Mari Seeba
Reviewer: Abasi-Amefon Obot AffiaTime: 11:30
Student: Burak Can Kus (Cyber Security MSc)
Title: Use of Electronic Identity Documents for MultiFactor Authentication
Supervisor: Arnis Paršovs
Reviewer: Inguss TreigutsTime: 12:15
Student: Priit Põdra (Cyber Security MSc)
Title: Web tracking in the most popular Estonian websites
Supervisor: Arnis Paršovs
Reviewer: Raimundas MatulevičiusTime: 13:00
Student: Mikus Teivens (Cyber Security MSc)
Title: Analysis of Security and Privacy Issues in Common Smart Home Products
Supervisor: Arnis Paršovs
Reviewer: Alo Peets
June 4, 2021:
Time: 11:30
Student: Magnus Valgre (Computer Science BSc)
Title: Tracking And Privacy: The Case of News Site Delfi
Supervisor: Arnis Paršovs
Reviewer: Mari Seeba
June 7, 2021:
Time: 09:00
Student: Hain Luud (Computer Science BSc)
Title: An Analysis of the HID® Indala and Seos™ Protocols
Supervisor: Danielle Morgan
Reviewer: Kristjan KripsTime: 09:30
Student: Geio Illus (Computer Science BSc)
Title: Wi-Fi Positioning System
Supervisor: Danielle Morgan
Reviewer: Jakob MassTime: 11:00
Student: Peeter Vahe (Computer Science BSc)
Title: Tartu Smart Bike Share Access Cards Authentication Analysis
Supervisor: Danielle Morgan
Reviewer: Alo Peets
June 11, 2021:
Time: 09:30
Student: Jan Erik Kriisk (Computer Science BSc)
Title: Security Analysis of RIA’s Authentication Service TARA
Supervisor: Arnis Paršovs
Reviewer: Kristjan KripsTime: 11:00
Student: Siim Markus Marvet (Computer Science BSc)
Title: Collecting Statistics and Security Data on Estonian Domains
Supervisor: Alo Peets
Reviewer: Kristjan Krips
Links:
https://www.cs.ut.ee/sites/default/files/cs/defence_schedule_01-11.06.2021.pdf
https://comserv.cs.ut.ee/ati_thesis/index.php?year=2021&language=en
Cyber Security master’s theses defense in TalTech (May 2021)
Cyber Security curriculum MSc theses defences on May 27th 2021 (online):
Time: 10:00
Student: Tarvo Arikas
Title: Streaming event correlation and complex event processing using open-source solutions
Supervisor: Risto Vaarandi
Reviewer: Mauno PihelgasTime: 10:40
Student: Janno Arnek
Title: Improving cybersecurity level of Estonian small and medium sized enterprises through coordination with national level
Supervisor: Sille Laks
Reviewer: Anna-Maria OsulaTime: 11:50
Student: Tedel Baca
Title: Critical infrastructure protection in the Republic of Kosovo: A policy-analysis on the protection of electric-energy and water-supply sectors
Supervisor: Mika Kerttunen, Kristine Hovhannisyan
Reviewer: Adrian VenablesTime: 12:30
Student: Risto Kasepuu
Title: Designing an artifact to support cybersecurity policy development in small and medium enterprises
Supervisor: Mika Kerttunen, Andro Kull
Reviewer: Adrian VenablesTime: 13:20
Student: Dariana Khisteva
Title: A proposal of integrating open-source IDS into vessel’s bridge network
Supervisor: Olaf Maennel, Gabor Visky
Reviewer: Risto VaarandiTime: 14:00
Student: Stanislav Mekinulashvili
Title: Sniffing encrypted BLE traffic after changing connection parameters, using low-cost hardware that captures only one channel at a time
Supervisor: Olaf Maennel
Reviewer: Toomas LepikTime: 14:40
Student: Yazeed Basim Aeadah Alhaddad
Title: Ghost Injection Attack on Automatic Dependent Surveillance-Broadcast Equipped Drones Impact on Human Behavior
Supervisor: Erwin Orye
Reviewer: Jaan Priisalu
Cyber Security curriculum MSc theses defences on May 28th 2021 (online):
Time: 10:00
Student: Juan Manuel Delgado Garcia
Title: Forensic Analysis of Privacy-Oriented Cryptocurrency Wallets
Supervisor: Hayretdin Bahsi
Reviewer: Pavel TsikulTime: 10:40
Student: Faisal Sumaila
Title: Extraction and Analysis of Forensic Artifacts from Automotive Maintenance Applications
Supervisor: Hayretdin Bahsi
Reviewer: Matthew SorellTime: 11:50
Student: Yoshihisa Furushita
Title: Sources of artifacts in video
Supervisor: Matthew Sorell, Pavel Tšikul
Reviewer: Richard MatthewsTime: 12:30
Student: Kärte Pärend
Title: Forensic Traces of Messaging Applications on Android and iOS Mobile Phones
Supervisor: Sten Mäses, Priit Lahesoo
Reviewer: Matthew SorellTime: 13:20
Student: Karoliina Koppel
Title: Securing Software Supply-Chain Using OWASP Application Security Verification Standard: A SimplBooks Case Study
Supervisor: Toomas Lepik
Reviewer: Andrew RobertsTime: 14:00
Student: Rooya Karimnia
Title: Culturally-Sensitive Instructional Design Of A Cybersecurity Awareness Program For High School Students In Iran, Hormozgan
Supervisor: Kaie Maennel, Mahtab Shahin
Reviewer: Stefan Sütterlin
Cyber Security curriculum MSc theses defences on May 31th 2021 (online):
Time: 10:00
Student: Jelizaveta Vakarjuk
Title: Converting a post-quantum signature scheme to a two-party signature scheme
Supervisor: Ahto Buldas, Jan Willemson
Reviewer: Ahto TruuTime: 10:40
Student: Esteban Josue Ramirez Rojas
Title: Preserving Information’s Integrity and Confidentiality with Blockchain in the Service Supply Chain
Supervisor: Jaan Priisalu, Alex Norta
Reviewer: Nikita SnetkovTime: 11:50
Student: Ali Ghasempour
Title: HTTP based Network Intrusion Detection System by Using Machine Learning-Based Classifier
Supervisor: Risto Vaarandi, Alejandro Manzanares
Reviewer: Hayretdin BahsiTime: 12:30
Student: Mauricio Antonio Duarte Lara
Title: Prototyping A Serious Game On Information Manipulation
Supervisor: Maria Claudia Solarte Vasquez, Adrian Venables
Reviewer: Rain OttisTime: 13:20
Student: Madis Männik
Title: Smart meter threat detection based on log analysis
Supervisor: Gabor Visky
Reviewer: Risto VaarandiTime: 14:00
Student: Alex Bindevald
Title: Cyber security at schools – challenges, oppurtunities and needs for CTF-solution
Supervisor: Birgy Lorenz
Reviewer: Tiia Sõmer
Cyber Security Newsletter 2021-02-22
- [2021-02-18] The Ministry of Economic Affairs and Communications (MKM) will establish a new state cyber security department joining the current state information systems department (RISO) and the information society services development department.
https://digi.geenius.ee/rubriik/uudis/valitsus-korrastab-digiriiki-luuakse-uus-riiklik-kuberturvalisuse-osakond/ - [2021-02-18] The LokiBot malware is being distributed using a spoofed e-mail address of the TalTech rector. The phishing email is written in good Estonian and as a pretext invites recipients to participate in a procurement. As a response, TalTech has enabled DMARC so that recipients could detect emails from spoofed @taltech.ee addresses.
https://www.taltech.ee/uudised/tahelepanu-tallinna-tehnikaulikooli-rektori-nime-alt-tulnud-hinnaparingud-petukirjad-ja
https://taltech.ee/en/news/attention-price-inquiries-sent-under-name-rector-taltech-are-e-mail-scam-and-university-asks
https://forte.delfi.ee/artikkel/92598139/kustuta-kohe-petukiri-korgel-tasemel-tehnikaulikooli-rektori-tiit-landi-nime-alt-laks-tana-teele-massiliselt-libaparinguid - [2021-02-17] An information security specialist of Viljandi Hospital raised a privacy issue of PDF and DDOC signature files being sent for validation to RIA validation service SiVa. According to RIA, data is not permanently stored on RIA servers and the DigiDoc4 client explicitly asks for permission before the file is sent to RIA. The DDOC file validation logic has been moved server side to simplify the DigiDoc4 client-side software. On a side note, people have forgotten that a few years ago, all documents signed using Mobile-ID were sent to the SK DigiDocService.
https://www.ohtuleht.ee/1026090/paranoia-voi-suure-venna-sund-digiallkirja-kehtivuse-kontrollimiseks-laheb-dokument-kogu-taiega-riigi-katte-miks - [2020-02-16] At the end of 2020, an ID card authentication bypass flaw was found in the Coop Pank’s internetbank environment. Since Coop Pank also provides a bank link authentication service, the eesti.ee e-service and other e-services supporting the bank link option were also affected. A similar flaw was also found in elisa.ee, printincity.ee and arved.ee.
https://www.youtube.com/watch?v=cObPmkK7zaY
https://www.youtube.com/watch?v=IQ5UK2VwN4w
https://digi.geenius.ee/rubriik/uudis/coopi-internetipangas-oli-turvaauk-mis-voimaldas-ligipaasu-voora-inimese-kontole/
https://digi.geenius.ee/rubriik/uudis/coop-pank-turvaviga-sai-operatiivselt-parandatud-interneti-ja-mobiilipanga-kasutamine-on-taiesti-turvaline/
https://digi.geenius.ee/rubriik/uudis/turvaauk-elisa-iseteeninduses-ning-arved-ee-keskkonnas-voimaldas-paaseda-voorale-kontole/ - [2021-02-12] In January 2021, Estonian banks lost more than 200 thousand euros in Smart-ID and Mobile-ID phishing attacks.
https://majandus24.postimees.ee/7178741/pangakelmustega-peteti-eesti-inimestelt-jaanuaris-valja-ule-200-000-euro - [2021-02-10] The personal data of 5000 persons was leaked from the Mineral Garden (mineralgarden.org – Living Minerals OÜ) online store. The names, email addresses, phone numbers, home addresses, and shopping cart information of thousands of Mineral Garden customers were searchable on Google. The Data Protection Inspectorate initiated a supervisory procedure. The shop is controversial as it distributes a harmful substance advertised as a miracle cure. Postimees published the name of a parliament member, who was found in the leak to have purchased the substance.
https://digi.geenius.ee/rubriik/uudis/hiiglaslik-andmeleke-mmsi-tellinud-klientide-andmed-rippusid-avalikult-internetis/
https://leht.postimees.ee/7176185/nimed-telefoninumbrid-aadressid-tuhandete-eesti-veebipoe-klientide-andmed-rippusid-avalikult-internetis - [2021-02-10] From March 2021, RIA will stop supporting bank link in the state authentication service TARA, because the security of bank link authentication mechanisms has not been assessed according to eIDAS regulation. The change will affect approximately 7000 people, which accounts for about 1% of all authentications in TARA. This move has been long awaited as the use of banks as authentication providers has never had legal basis and security flaws in banking systems have put personal data, that is accessible through the bank link, at risk.
https://www.ria.ee/et/uudised/1-martsist-ei-saa-teatud-riiklikesse-e-teenustesse-pangalingi-kaudu-siseneda.html
https://www.ria.ee/en/news/1-march-it-will-no-longer-be-possible-access-certain-public-e-services-bank-link.html
https://www.ria.ee/et/uudised/osasse-riiklikesse-e-teenustesse-ei-saa-alates-martsist-pangalingi-kaudu-siseneda.html
https://forte.delfi.ee/artikkel/92520083/alates-1-martsist-ei-paase-pangalingiga-enam-38-e-teenusesse-sh-riigiportaali
https://digi.geenius.ee/rubriik/uudis/riigiteenustesse-ei-saa-pangalingiga-martsist-enam-siseneda-pohjuseks-euroopa-liidu-seadus/
https://news.err.ee/1608104449/some-public-e-services-cannot-be-accessed-via-a-bank-link-from-march - [2021-02-05] The litigation between PPA and the Estonia ID card manufacturer Gemalto has reached a compromise with Gemalto paying the state 2.2 million EUR in compensation. While the press release only mentions the ID card security incident in 2017, the compromise also covers the claim against Gemalto regarding private key generation outside the ID card.
https://www.politsei.ee/en/news/a-settlement-agreement-has-been-signed-between-the-police-and-border-guard-board-and-gemalto-ag-tallinn-2021
https://forte.delfi.ee/artikkel/92482559/politsei-loobus-hiigelhagist-gemalto-vastu
https://forte.delfi.ee/artikkel/92191151/see-pole-enam-isegi-naljakas-moodunud-on-kaks-aastat-ja-kohus-pole-joudnud-politsei-ja-gemalto-kohtuasjas-mitte-kuskile
https://digi.geenius.ee/rubriik/uudis/vigaste-id-kaartide-tootja-gemalto-maksab-eesti-riigile-22-miljonit-eurot-huvitist/
https://www.err.ee/1608099706/ppa-ja-gemalto-joudsid-kokkuleppele-ettevote-maksab-2-2-miljonit-eurot
https://news.err.ee/1608100102/gemalto-ppa-reach-compromise-over-id-card-security-weakness - [2021-02-03] RIA fixed an authentication man-in-the-middle flaw in the ID card browser signing extension. The flaw (a feature to sign raw values using the authentication key) was quietly introduced in 2017 without a proper security analysis. Swedbank began using the feature to authenticate their clients at the end of 2020, because it was considered to be more reliable than TLS client certificate authentication.
https://www.youtube.com/watch?v=Qr638sbaZ_M
https://www.ria.ee/en/news/information-system-authority-ria-and-its-partners-fixed-critical-bug-id-card-browser-extension.html
https://digi.geenius.ee/eksklusiiv/swedbank-kasutas-turvanorkusega-id-kaardi-laiendust-kaks-aastat-pank-pidas-seda-tookindlamaks/ - [2021-02-03] Geenius wrote an article about the recent repeated failures of revoking ID cards of deceased persons. RIA in 2019 initiated a supervisory procedure which still has not been completed.
https://digi.geenius.ee/eksklusiiv/teist-korda-jaid-hulga-surnud-inimeste-id-kaartide-sertifikaadid-kehtetuks-tunnistamata/ - [2021-01-25] CERT-EE reported that in December 2020, an ID card authentication bypass flaw was found in the website of quick loan provider (credit24.ee), which would have provided the opportunity to take a quick loan on behalf of a stranger.
https://www.ria.ee/et/uudised/detsembris-lahendati-oluline-turvanorkus-kiirlaenu-pakkuja-veebilehel.html
https://forte.delfi.ee/artikkel/92359667/kiirlaenu-pakkuja-veebilehel-avastati-ohtlik-turvanorkus - [2021-01-26] Liisa Past and Jan Willemson from Cybernetica, in the Digital Government podcast (30min), talk about the historical and cognitive aspects of i-voting and explain how technology and math ensure a secure and trustworthy solution.
https://www.buzzsprout.com/1191800/7491415-what-makes-online-voting-secure - [2021-01-25] Estonian server hosting company Zone.ee experienced a DDoS attack. The attack lasted a total of five hours and affected the company’s operations.
https://digi.geenius.ee/rubriik/uudis/eesti-serverimajutusettevote-on-aktiivse-ddos-runnaku-all/ - [2021-01-25] The Ministry of Economic Affairs and Communications (MKM), the State Information System Authority (RIA) and the State Electoral Service (RVT) signed a cooperation agreement to define the division of tasks between the agencies for organizing i-voting security. MKM will organize a security audit. RVT undertakes the development of the i-voting system and organization of security testing and risk analysis. RIA will provide hosting services and perform security testing and logging. RVT and RIA will undertake the procurement of a technical and legal analysis of the possibility of voter identification by facial biometrics. The analysis should be conducted by 1 June 2021.
https://www.ria.ee/et/uudised/mkm-ria-ja-rvt-solmisid-koostoolepingu-e-valimiste-kuberturvalisuse-korraldamiseks.html - [2021-01-24] The Estonian government recently fell and a new one was formed with a new Minister of Foreign Trade and IT: Andres Sutt (Reform). The political position on i-voting has now significantly changed as the coalition agreement seeks to develop a mobile app for i-voting.
https://news.err.ee/1608084379/who-s-who-estonia-s-new-government
https://news.err.ee/1608086476/coalition-agreement-center-reform-government-2021-2023
https://twitter.com/ikubjas/status/1353315211571294213 - [2021-01-14] The Ministry of Economic Affairs and Communications (MKM) announced a public procurement tender for the audit of the i-voting system. The purpose of the audit is to get a reasoned assessment of the security of the election information systems and proposals for improvements that can raise the level of security. The audit shall be performed by internationally renowned auditors and information security specialists. The deadline for presenting the project’s final report is October 1, 2021.
https://news.err.ee/1608073477/ministry-seeking-international-auditor-to-check-security-of-e-elections - [2021-01-05] On 2021-01-05, Smart-ID, Mobile-ID and ID-card authentication and signing services were disrupted for a few hours. The state does not know the reason behind the failures and did not answer whether the question of whether a supervisory procedure will be initiated against SK ID Solutions AS.
https://majandus24.postimees.ee/7147961/riiklikud-autentimisteenused-olid-hairitud
https://news.err.ee/1228642/disruptions-in-use-of-mobile-id-still-possible
https://digi.geenius.ee/rubriik/uudis/riik-ei-tea-pohjust-miks-oli-mobiil-id-ja-id-kaardi-too-korraga-hairitud/ - [2021-01-04] On 2021-01-04, SK ID Solutions AS failed to rotate the OCSP signer’s certificate, as a result, for 10 hours OCSP responses were signed with an expired certificate.
https://www.skidsolutions.eu/en/News/certifier-esteid2018-validity-information-responses-were-signed-with-an-expired-certificate/ - [2020-12-22] A research article by Valeh Farzaliyev, Kristjan Krips and Jan Willemson (Cybernetica): “Developing a Personal Voting Machine for the Estonian Internet Voting System”. The article describes a proof-of-concept i-voting client implemented on a microcontroller. The client only supports Mobile-ID for casting an i-vote. The source code of the client and build instructions have been published in GitHub.
https://research.cyber.ee/~janwil/publ/votingclient-final.pdf
https://github.com/Valeh2012/PersonalVotingMachine - [2020-12-18] RIA has published a technical report produced by Cybernetica: “Analysis of planned architectural changes in Open-eID”. The work analyzes the proposed alternative to TLS certificate authentication – authentication using a new web browser extension that RIA is currently developing.
https://web-eid.gitlab.io/analysis/webextensions-main.pdf - [2020-12-04] The Data Protection Inspectorate (AKI) initiated a supervisory procedure against the Health Board (TA) in connection with the COVID-19 data leak of 9158 persons. However, the Health Board will not be fined, because AKI does not have the power to fine another state agency.
https://digi.geenius.ee/rubriik/uudis/suur-isikuandmete-leke-ei-too-terviseametile-trahvi-kaela/
Cybersecurity related master’s theses in University of Tartu 2021 (January)
Student: Jayavarshini Thirumalai (Cyber Security MSc)
Title: An integrated approach for certification and re-certificationbased on the case study
Supervisor: Liina Kamm, Mari Seeba
Reviewer: Raimundas MatulevičiusStudent: Valeh Farzaliyev (Computer Science MSc)
Title: Towards Practical Post-Quantum Voting Protocol: Shorter Exact Lattice-Based Proof of a Shuffle
Supervisor: Dominique Unruh, Jan Villemson
Reviewer: Janno SiimStudent: Jamil Gurbanzade (Computer Science MSc)
Title: Malicious Android app for security testing
Supervisor: Alo Peets
Reviewer: Denizalp Kapisiz
Cyber Security master’s theses defense in TalTech (January 2021)
Cybersecurity curriculum MSc theses defences on January 11th 2021 (online):
Time: 9:30
Student: Electra Zoe Karamargin
Title: Going dark: a Forensic Analysis of Biometric Asset Management within Smart Eyewear, toward the Rising Conflict Between Security Through Privacy by Design and Forensic Investigation
Supervisor: Hayretdin Bahsi
Reviewer: Matthew SorellTime: 10:10
Student: Siim Sarv
Title: Using Event Correlation to Detect Security Incidents from Windows Workstations
Supervisor: Risto Vaarandi
Reviewer: Toomas LepikTime: 10:50
Student: Alvaro-Wim Schuller Fernandez
Title: Developing a Scada Testbed from a Design Science Approach
Supervisor: Hayretdin Bahsi
Reviewer: Andrew RobertsTime: 12:00
Student: Jaanus Kääp
Title: Hyper-V VMBus Based Traffic Interception and Fuzzing
Supervisor: Sille Laks
Reviewer: Bernhards BlumbergsTime: 12:40
Student: Kapil Yadav
Title: Information Security Management for Teleworking in Small and Medium Enterprises during the COVID-19 Crisis
Supervisor: Kaie Maennel
Reviewer: Adrian VenablesTime: 13:20
Student: Ivo Malve
Title: Dark Triad in Central Route to Persuasion: a Personality-based Phishing Susceptibility Study
Supervisor: Kieren Lovell
Reviewer: Stefan SütterlinTime: 14:15
Student: Anastasiya Kornitska
Title: Exploring How to Establish Cross-functional Teams for Cybersecurity of Industrial Control Systems
Supervisor: Hayretdin Bahsi
Reviewer: Rain OttisTime: 14:55
Student: Arefeh Fathollahi Kalkhoran
Title: A Systematic Process to Improve Data Loss Prevention in a Large Organization
Supervisor: Hayretdin Bahsi
Reviewer: Tiia SõmerTime: 15:35 (withdrawn)
Student: Furkan Atlas
Title: A Comparative Study: Evaluating the Efficiency of Looking Glasses in Helping Monitor BGP Attacks
Supervisor: Olaf Maennel
Reviewer: Toomas Lepik
Cyber Security Newsletter 2021-01-04
- [2020-12-30] A new version of the Election Information System (VIS) is being developed which will introduce an electronic list of voters making it possible to cancel an already given i-vote on election day with a paper vote. News portal Geenius tried to establish whether the authorities are performing background checks on the employees of private companies, Nortal and Cybernetica, involved in the development of the information systems for elections. Not clear whether such checks are needed as the security of the elections should not depend on the integrity of the developers.
https://digi.geenius.ee/rubriik/uudis/kas-valimiste-infosusteemide-arendajate-taust-on-riigile-teada-riigiasutused-keerutavad/ - [2020-12-29] Äripäev’s Russian-language website dv.ee experienced a large-scale DDoS attack. Äripäev’s editor-in-chief believes that the attacks are related to the published story about cryptocurrency millionares in Ida-Viru.
https://digi.geenius.ee/rubriik/uudis/aripaev-sattus-parast-ida-viru-kruptomiljonaride-uurimise-kajastamist-kuberrunnaku-ohvriks/ - [2020-12-28] Arnis Parsovs (UT) has published the draft of his PhD dissertation “Estonian Electronic ID card and its Security Challenges”.
https://cybersec.ee/storage/phd_idcard.pdf - [2020-12-22] An anonymous interview was given for the Kanal 2 television channel where the coronavirus vaccine plan was criticized. The Health Board used a freeware program downloaded from the Internet to remove the voice distortion added to anonymize the source. As a result, the whistle blower was identified and asked to resign from the Health Board.
https://leht.postimees.ee/7139982/terviseametist-vallandatud-simmo-saar-naitab-napuga-sotsiaalministeeriumi-suunas
https://news.err.ee/1215910/health-board-comms-chief-asked-to-resign-after-criticizing-vaccine-plan - [2020-12-18] The Minister of Finance Martin Helme (EKRE) said that Estonian e-elections are not verifiable. The head of the state electoral service refuted the statements of the minister.
https://digi.geenius.ee/rubriik/uudis/martin-helme-eesti-e-valimised-ei-ole-kontrollitavad-ning-neil-puudub-vaatlemise-voimalus/ - [2020-12-16] Sten Mäses (TalTech) defended his PhD thesis “Evaluating Cybersecurity-Related Competences through Simulation Exercises”.
https://digikogu.taltech.ee/et/Item/b4c33d3b-e7ce-48ad-98ad-a0add5e571a3 - [2020-12-16] For years, an IT employee with a state secret permit mined cryptocurrency at the Ämari air base, bought expensive equipment with the Estonian defense budget and smuggled computer components out of the base to sell them in online forums. The purchased goods were not accounted for in the air monitoring division. From 2015 until his arrest in January 2019, the man illegally used devices belonging to the Defense Forces to extract cryptocurrencies worth 30,404 euros and misappropriated at least 190 devices with the total value of 48,935 euros.
https://ekspress.delfi.ee/artikkel/91976323/it-mees-armaani-tegi-eesti-kaitserahaga-osturallit-ja-avas-amaris-salajase-kruptorahakaevanduse - [2020-12-08] The Ministry of Interior sells the residence addresses entered in the population register to commercial enterprises for the purpose of sending advertisements or invitations to participate in surveys. Names, e-mail addresses, dates of birth and personal identification codes are not disclosed to the companies, but the addresses can be purchased by specifying the characteristics such as age, gender and mother tongue. People can opt-out by restricting access to their data in the e-service at rahvastikuregister.ee. In 2019, the data was sold to five customers and the state earned 8,205 EUR.
https://forte.delfi.ee/news/digi/riik-muutis-inimeste-aadressid-ariks-siseministeerium-muub-rahvastikuregistri-andmeid-otsepostitusfirmadele?id=91904305 - [2020-12-07] The Estonian Foreign Intelligence Service (EFIS) allowed an active intelligence officer to give an interview to Postimees. The interview followed strict secrecy rules and Postimees did not learn the agent’s identity. This activity is likely related to the job ads recently put out by the Estonian Foreign Intelligence Service.
https://news.postimees.ee/7127281/estonian-intelligence-operative-our-special-tool-is-our-brain - [2020-12-07] The 6th Interdisciplinary Cyber Research conference took place in a semi-online format. The video recordings and proceedings are available.
https://www.taltech.ee/en/icr2020 - [2020-12-02] By exploiting a flaw in the content management software Drupal, attackers compromised servers of the Ministry of Economic Affairs and Communications, the Ministry of Social Affairs and the Ministry of Foreign Affairs. The attackers downloaded 350GB of data from a total of 11 servers. The data mostly consisted of the data in the document management system. However, the attackers were also able to download a database containing data about 9158 corona-positive persons and their close contacts, that was stored as a LimeSurvey database in the Drupal instance of the Health and Welfare Information Systems Center (TEHIK). RIA initiated supervision proceedings, the Data Protection Inspectorate initiated its own proceedings and the Central Criminal Police initiated criminal proceedings of obtaining illegal access to the systems. Members of Parliament suspected that data from the national car registry had also been leaked, but this information was not confirmed.
https://news.err.ee/1192411/three-government-ministries-came-under-cyber-attack-in-november
https://news.postimees.ee/7123666/cybercriminals-attack-three-ministries
https://news.err.ee/1193476/november-s-cyber-attack-left-foreign-ministry-intranet-unmolested
https://www.err.ee/1192309/riigi-vastu-toimusid-kuberrunded-katte-saadi-9158-koroonapatsiendi-andmed
https://digi.geenius.ee/rubriik/uudis/ria-mkm-ei-kasutanud-infoturbe-osas-parimaid-praktikaid-algatasime-jarelevalvemenetluse/
https://digi.geenius.ee/eksklusiiv/koroonapositiivsete-andmed-lekkisid-limesurvey-teenusest-terviseamet-lopetas-selle-kasutamise/
https://digi.geenius.ee/rubriik/uudis/ministeerium-lukkab-riigikogulase-kahtlustuse-umber/
https://digi.geenius.ee/rubriik/uudis/riigikogulaseni-joudis-info-et-kuberrunnaku-kaigus-saadi-katte-rohkem-infot-kui-seni-on-oeldud/ - [2020-12-01] RIA is developing an environment which will provide the possibility of installing additional smart card applications on the ID card. There are about four companies working on the creation of apps. The proof of concept will be completed by March 2021. RIA will not charge for apps, but it is possible that the use of the app will require a certain fee to be paid to the companies providing the apps.
https://digi.geenius.ee/rubriik/uudis/tulevast-aastast-saab-id-kaardile-appe-installida/ - [2020-12-01] Internet shops of pharmacies Apotheka, Südameapteek and Azeta.ee allowed anyone to query another person’s prescriptions by entering their personal ID code. The Data Protection Inspectorate issued a precept-warning with a one-day compliance deadline and a penalty payment of 100,000 euros to these three pharmacy chains. The chains complied with the precept by the deadline and suspended the possibility for buying a prescription drug for another person from the e-pharmacy.
https://www.aki.ee/et/uudised/andmekaitse-inspektsioon-kohustas-e-apteeke-lopetama-koheselt-ligipaas-teise-inimese
https://www.err.ee/1196452/e-apteekidest-enam-teistele-inimestele-retseptiravimeid-osta-ei-saa
https://arileht.delfi.ee/news/uudised/vooraste-inimeste-retseptiinfot-avaldavad-apteegid-said-riigilt-hoiatuse?id=91845429 - [2020-12-01] Citizen Lab reported that the Estonian Education and Research Network (EENet) hosts Circles surveillance technology that exploits weaknesses in the global mobile phone system SS7 to track people’s phone calls, text messages and location, from anywhere. The technology is sold only to governments, therefore the best guess is that it has been purchased by the Estonian Foreign Intelligence Service to spy on targets abroad. RIA, who are the end-users of the IP addresses, acknowledged that they were used by RIA’s “contract partners”, but refused to name them. Since RIA refused to clarify whether the use of these IPs complied with the EENet’s network policy, EENet blocked traffic to these IPs.
https://citizenlab.ca/2020/12/running-in-circles-uncovering-the-clients-of-cyberespionage-firm-circles/
https://epl.delfi.ee/artikkel/91851591/suur-vend-jalgib-aga-keda-uurijad-paljastasid-hamarat-nuhkimissusteemi-kasutavad-valitsused-nimekirjas-on-ka-eesti
https://www.delfi.ee/news/paevauudised/eesti/voimalikule-eesti-nuhkimissusteemile-tombasid-kriipsu-peale-haridusametnikud?id=91877113
https://twitter.com/ikubjas/status/1333861285725921292
https://digi.geenius.ee/rubriik/uudis/ekspert-nuhkvarast-circles-riigil-on-tagauksed-niigi-olemas-tuvastamisel-piiraksid-telekomid-selle-kasutamist/
https://digi.geenius.ee/eksklusiiv/ria-keeldus-teisele-riigiametile-utlemast-miks-nad-jooksutavad-nende-susteemides-salajast-nuhkvara/ - [2020-11-27] EveryPay AS, which offers payment solutions for Estonian e-shops (used by mTasku), made a mistake which resulted in the bank accounts for a few hundred people being emptied. According to the company, it was a human error in the development which the automatic tests did not catch. All affected customers have received a refund.
https://raha.geenius.ee/rubriik/uudis/eesti-maksevahendaja-eksitus-tuhjendas-monesaja-inimese-pangakonto/ - [2020-11-21] Õhtuleht journalists tailed a ministerial car to reveal its misuse. The Minister of Justice asked the Prosecutor General to have the journalists’ activities investigated on the basis of section 137 of the Penal Code – the section on unauthorized surveillance. The Minister of Justice later claimed that this was a misunderstanding.
https://news.err.ee/1161772/journalists-association-justice-minister-reps-probe-a-press-freedom-threat
https://news.err.ee/1162648/prosecutor-s-office-will-not-open-proceedings-against-ohtuleht-journalists - [2020-11-21] A book chapter by Kärt Salumaa-Lepik (TalTech), Tanel Kerikmäe (TalTech) and Nele Nisu (Ministry of Social Affairs): “Data Protection in Estonia”.
https://link.springer.com/chapter/10.1007/978-94-6265-407-5_3 - [2020-11-20] IT minister Raul Siem (EKRE) proposed using face recognition in i-voting to cut out voter fraud. The Electoral committee responded that the idea is not bad, but may be expensive. RIA supports the idea of using biometrics to identify a person, but acknowledged that this requires in-depth analysis.
https://www.err.ee/1161445/raul-siem-tahab-e-valimistel-hakata-inimesi-kaameraga-tuvastama
https://news.err.ee/1161488/it-minister-smartphone-camera-verification-would-cut-out-voter-fraud
https://news.err.ee/1162239/electoral-committee-face-verification-idea-not-bad-but-expensive
https://news.err.ee/1164544/kaimar-karu-face-recognition-could-be-added-to-e-voting-but-should-it
https://news.err.ee/1196515/it-entrepreneur-doubts-over-e-voting-reliability-is-political-issue
https://twitter.com/ikubjas/status/1329733968099299328
https://digi.geenius.ee/rubriik/uudis/ria-toetab-biomeetria-kasutamise-motet-isiku-tuvastamisel/
https://digi.geenius.ee/rubriik/uudis/itli-president-krull-naotuvastusega-e-valimised-ei-ole-rahvahaaletuse-ajaks-realistik-soov/
https://digi.geenius.ee/rubriik/uudis/it-minister-siem-e-haaletamine-peab-koigile-kattesaadav-olema/
https://digi.geenius.ee/rubriik/uudis/kaimar-karu-naotuvastusega-e-valimiste-teema-tostatus-juba-sel-ajal-kui-mina-olin-minister/ - [2020-11-17] RIA held an online information day. Among the topics covered: new ID card browser extension; new CDOC 2.0 encryption format; new Mobile-ID solution; remote ID card certificate update and remote applet loading; the states authentication service TARA; the new information security standard. The video recordings and the transcribed Q&A are available.
https://blog.ria.ee/kusimused-ja-vastused-ria-infopaeva-esimene-paev-17-11-2020/
https://blog.ria.ee/kusimused-ja-vastused-ria-infopaeva-teine-paev-18-11-2020/ - [2020-11-16] The Ministry of Economic Affairs and Communications (MKM) is planning an independent audit and security analysis on i-voting, however, the details of the audit are still unclear. The ministry plans to propose a model where the security management of i-voting will be two-stage – RIA organizes cyber security and MKM checks the whole process and gives the National Electoral Committee an opinion on whether cyber security is organized at a sufficient level to use electronic systems for conducting elections.
https://news.err.ee/1159591/economics-affairs-ministry-looking-to-tighten-up-e-voting-security
https://mkm.ee/et/uudised/siem-e-valimiste-turvalisus-riikliku-julgeoleku-kusimus
https://digi.geenius.ee/rubriik/uudis/e-valimistele-tehakse-it-ministri-juhtimisel-esimene-rahvusvaheline-audit/
https://digi.geenius.ee/rubriik/uudis/e-valimiste-auditi-osas-valitseb-veel-teadmatus/ - [2020-11-12] SK ID Solutions AS annual conference was replaced with a video presentation. Among the topics covered: SK team has grown; Smart-ID solution is to be implemented in Iceland; SK has teamed up with TalTech to pre-emptively identify and counter phishing scams.
https://www.youtube.com/watch?v=2BBgScfRy0k - [2020-11-08] Minister of the Interior Mart Helme (EKRE) made a statement (without providing any evidence) that election results are falsified in favor of a particular political party by those with access to i-votes. The head of the state electoral service refuted all statements of the minister. The Minister of the Interior later resigned due to other unfounded claims in the context of the U.S. presidential elections.
https://digi.geenius.ee/rubriik/uudis/siseminister-mart-helme-seadis-eesti-e-valimiste-susteemi-ilma-toendeid-esitamata-kahtluse-alla/
https://news.err.ee/1157305/koppel-electoral-committee-does-not-falsify-election-results-in-estonia
https://forte.delfi.ee/news/varia/riigi-valimisteenistuse-juht-lukkab-umber-koik-mart-helme-vaited?id=91621201
https://digi.geenius.ee/rubriik/uudis/riigi-valimisteenistus-lukkab-kategooriliselt-umber-eksminister-helme-e-valimiste-teemalised-vaited/ - [2020-11-01] A cyber defense exercise “Cyber Battle of Tartu” for pupils and students was held at the Delta Center in Tartu. The competition was organized by CybExer Technologies. The participants had to find vulnerabilities in the school’s information system, stop the attack on the hospital’s vital systems and prevent a cyber attack aimed at opening the museum’s treasury.
https://tartu.postimees.ee/7100809/kuberkaitsespetsialist-hans-lougas-internetis-peab-motlema-nagu-hakker
https://tartu.postimees.ee/7099309/tartu-ja-poltsamaa-gumnasistid-esindavad-eestit-rahvusvahelisel-kuberkaitsevoistlusel - [2020-10-29] In the second half of July this year, a new way of banking fraud began to spread – telephone phishing calls. As of the beginning of October, the police has reported 90 cases in which fraudsters have been able to cause damage totaling 200,000 euros. Criminals spoof a bank’s Caller ID, use waiting music, read out the customer’s personal identification code or other personal data, and use all means to create the illusion that the victim is indeed talking to a bank employee. The criminals create fear and state that an action is urgently needed. The victim’s phone receives Mobile-ID or Smart-ID authentication requests and the victim thinks that he is being identified by a bank employee. Scammers are speaking Russian and the victims are mainly the Russian-speaking customers. From the audio recording of the fraudulent call to Swedbank, it is possible to hear that the scammers operate a call center – in the background similar calls can be heard being made to other potential victims. Also the phishing e-mails sent on behalf of banks are once again spreading.
https://tarbija24.postimees.ee/7063755/pank-hoiatab-petukonede-ja-petusonumite-eest
https://www.ria.ee/et/uudised/sagenenud-venekeelsed-telefonikoned-raha-valja-petmiseks.html
https://www.err.ee/1153036/pangapettuste-ohvriks-langevad-enamasti-venekeelsed-kliendid
https://news.err.ee/1153654/ppa-ria-warn-against-phishing-letters-spread-on-behalf-of-banks - [2020-10-28] Draft regulation specifies requirements for handling interruptions in vital services. The telecommunications operator must ensure that the service is restored within 24 hours if 1000 to 30 000 end users are affected and within 8 hours if more than 200,000 users are affected by the failure.
https://digi.geenius.ee/rubriik/uudis/riik-paneb-paika-kui-pikad-voivad-olla-elutahtsate-teenuste-katkestused/ - [2020-10-26] Cybercriminals stole patient data from a Finnish psychotherapy center. Worries are that the same could happen in Estonia.
https://www.err.ee/1151658/ria-hinnangul-kasutavad-turvalisi-kuberteenuseid-umbes-pooled-perearstid - [2020-10-25] The Ministry of Finance plans to register the loans of residents in a central database.
https://www.err.ee/1151293/riik-kogub-inimeste-kohta-aina-enam-infot - [2020-10-22] A 20-year old man in Tartu had repeatedly ridden a bicycle from the Tartu Bike Share System without authorization by using a friend of a friend’s password. It was only discovered after the bike was ridden for more than an hour in one session resulting in the 1 EUR fee being sent to the account holder. The man was identified using security camera footage. He pleaded guilty and promised to compensate for the damage caused. The police imposed a financial penalty on the man in misdemeanor proceedings.
https://tartu.postimees.ee/7076171/sartsuratas-tegi-supilinlase-nime-all-annelinnas-fantoomsoite
https://tartu.postimees.ee/7091433/politsei-tabas-voora-kontoga-sartsurattaid-laenanud-noormehe - [2020-10-21] The Ministry of Economic Affairs and Communications and the Ministry of Interior have made amendments to ban the use of anonymous SIM cards, requiring identification verification for using pre-paid SIM cards. The amendments are needed to help solve drug offenses as well as other organized crime, where anonymous calling cards are often used. The amendments would also affect messaging app services like Skype, WhatsApp and Viber, requiring them to register as communications service providers and require the same degree of ID verification for their users.
https://news.err.ee/1149511/ministry-wants-to-tighten-identification-regulations-on-pre-paid-sim-cards
https://www.err.ee/1149441/mkm-tahaks-turvakaalutlustel-keelata-isikustamata-konekaardid
https://news.err.ee/1149796/legal-expert-anonymous-pre-paid-sim-card-ban-could-violate-privacy-rights
https://news.postimees.ee/7100007/bill-to-obligate-data-collection-and-personalize-prepaid-sim-cards
https://forte.delfi.ee/news/digi/valitsus-toukab-eesti-mitme-pika-sammu-vorra-kontrollimisuhiskonna-poole-likvideeritakse-isikustamata-konekaardid-ja-suhtlusprogrammid-lahevad-voimu-k?id=91396045
https://forte.delfi.ee/news/varia/eksperdid-valitsus-plaanib-olulist-sekkumist-eestlaste-internetivabadusse?id=91408841 - [2020-10-16] Estonia holds the second place in the world in terms of internet freedom after Iceland. Estonia did not receive all the points because, among other things, the Tax and Customs Board can oblige Estonian service providers to block illegal gambling sites.
https://novaator.err.ee/1147918/raport-koroonapandeemia-kiirendab-internetivabaduse-vahenemist
https://news.err.ee/1147145/estonia-ranks-second-in-global-internet-freedom-index
https://mkm.ee/et/uudised/eesti-internetivabaduse-poolest-maailmas-esirinnas - [2020-10-16] A recent audit conducted by the Data Protection Inspectorate (AKI) finds that local municipality governments often unjustifiably mark documents as “information intended for internal use”. Most commonly the wage of employees and their vacation information is hidden. There are rumors that when signing an agreement, some personal information is included on purpose so that access restrictions could be applied. At the same time, there are plenty documents available to the public, containing the full names and contacts of private persons. Sometimes personal data leaks by including personal data in the public title of a non-public document.
https://news.err.ee/1147941/data-protection-inspectorate-local-governments-cover-for-officials - [2020-10-09] The Mobile-ID service was disrupted from 11:20 to 14:30.
https://news.err.ee/1145136/mobile-id-experiencing-disruptions-friday - [2020-10-06] The Ministry of Justice has made amendments to prevent mass-download of personal data from the public databases of court decisions and court calendars. Already on 2020-05-08, before the amendments were passed, a robot trap unexpectedly appeared on the website of Rigi Teataja without a legal basis. Previously, journalists had mass-processed the data to inform the public about the candidates of Riigikogu and municipality elections that have been criminally sentenced.
https://news.err.ee/1143685/law-change-to-stop-personal-legal-information-remaining-open-data
https://news.err.ee/1116586/reduced-accessibility-of-open-data-would-complicate-courts-work
https://news.err.ee/1115164/ministry-of-justice-wants-to-reduce-accessibility-of-court-data - [2020-10-01] CERT.LV organized the online conference “Cybershock 2020”. Among the participants were Estonians Jaanus Kääp (Clarified Security) and Hans Lõugas (CybExer Technologies).
https://cert.lv/lv/2020/09/technical-online-conference-cybershock-2020
https://www.youtube.com/watch?v=JuzAsFakHec - [2020-09-30] The Ministry of Economic Affairs and Communications has finished a regulation bill which will restrict the use of non-EU telecoms tech in Estonia, including those from Huawei. Initially, these requirements will affect the providers of vital services such as the communication companies, which have at least 10,000 clients – Telia, Elisa, Tele2, Levikom and STV. Huawei says it will challenge the bill. Elisa CEO claims that there is no real risk from Chinese tech and that the ban on Huawei’s equipment will cost Elisa tens of millions of euros.
https://news.err.ee/1117620/elisa-ceo-hits-out-at-ministry-huawei-tech-ban-draft
https://www.mkm.ee/et/uudised/mkm-alustas-sidevorkude-turvalisuse-maaruse-eelnou-avalikku-konsultatsiooni
https://www.err.ee/1142482/uus-sidevorkude-turvakontroll-hakkab-hindama-tootjaid
https://news.err.ee/1143507/huawei-plans-to-challenge-estonia-5g-ban-in-court
https://news.err.ee/1147922/huawei-asks-government-to-review-communications-networks-regulation
https://news.err.ee/1146282/estonia-to-limit-officials-choice-of-network-devices-and-software
https://www.err.ee/1161191/elisa-juht-riigi-analuusi-jargi-maarab-vorguseadmete-valjavahetamise-kulud-kohus - [2020-09-29] Three Romanian nationals were arrested in Romania for being suspected of organizing the Mobile-ID and Smart-ID phishing attacks that started in 2019. The aggregate sum stolen from close to 40 victims totals over €100,000. Estonian police detectives took part in the operation that was carried out in Bucharest. The prosecutor’s office is applying for the suspects to be extradited to Estonia for court proceedings.
https://news.err.ee/1140977/police-apprehend-suspects-in-cyberattacks-against-estonia
https://tehnika.postimees.ee/7073958/rumeenias-peeti-kinni-eesti-vastastes-kuberrunnakutes-kahtlustatavad - [2020-09-29] The procurement of a new Mobile ID solution is in process. An offer was received from two companies: the first applicant is the current partner SK ID Solutions that wants to continue providing the service, but the second applicant is the Belgian company Belgian Mobile ID, which was set up in 2016 by seven mobile operators and banks. The procurement doesn’t constrain technology too much and assesses the proposals individually. The solution must allow the change of crypto algorithms without going to a service office (i.e., remotely). For the enrollment it can support face-to-face identification, digital identification and biometric identification. Suspension of the certificates must not be supported.
https://riigihanked.riik.ee/rhr-web/#/procurement/2063672/general-info
https://riigihanked.riik.ee/rhr-web/#/procurement/2063672/applications
https://twitter.com/ikubjas/status/1297196116358897665
https://forte.delfi.ee/news/digi/belgia-ettevote-tahab-eestile-pakkuda-uut-mobiil-idd?id=91411201
https://forte.delfi.ee/news/digi/id-kaart-ja-mobiil-id-vajavad-uuenduskuuri?id=89736991 - [2020-09-25] A research article by Mihkel Solvak (UT): “Does vote verification work: usage and impact of confidence building technology in Internet voting”. The study finds that: i-vote verifiers are younger males and Linux users with the verification rate especially high in the 18 to 40 age group; voting from abroad clearly leads to more verification; the cast-as-intended verification leads to higher confidence that ones vote was taken into account.
https://link.springer.com/chapter/10.1007/978-3-030-60347-2_14 - [2020-09-18] From August, RIA started monitoring procedures for the implementation of information security measures for all critical databases in Estonia. A total of ten critical databases have been defined: e-file (e-toimik), land register, commercial register, Riigi Teataja information system, land cadastre, state treasury information system, taxpayer register, population register, register of identity documents and state pension insurance register.
https://www.ria.ee/et/uudised/olukord-kuberruumis-august-2020.html - [2020-09-17] The investigative journalism show “Pealtnägija” investigated a scam of fictitious real estate ads targeted at foreign students. While the victims believed that they were transferring money as a deposit for an apartment, they effectively paid an Estonian Bitcoin trader for the scammer’s purchase of bitcoins.
https://news.err.ee/1136558/pealtnagija-foreign-students-falling-victim-to-fictitious-real-estate-ads - [2020-09-17] Government will revoke 10 citizenships acquired illegally as the result of a widespread fraud that was committed during the years of 2013-2015 by a criminal group involving PPA employees. Previously, Estonian citizenship has only been revoked once by a government decision in 2016.
https://news.err.ee/1136097/government-to-revoke-10-citizenships-acquired-illegally - [2020-09-16] A research article by Sven Heiberg (SCCEIV), Kristjan Krips (Cybernetica/UT) and Jan Willemson (Cybernetica/STACC): “Planning the next steps for Estonian Internet voting”. The authors mostly reiterate the discussion points in the report of feasibility of i-voting on smart devices.
https://research.cyber.ee/~janwil/publ/planning.pdf
https://digikogu.taltech.ee/en/Download/38e36fd7-1428-42a1-ac6b-30d561bf849c
https://twitter.com/ikubjas/status/1306178995747250179 - [2020-09-06] A research article by Valentyna Tsap (TalTech), Silvia Lips (TalTech) and Dirk Draheim (TalTech): “Analyzing eID Public Acceptance and User Preferences for Current Authentication Options in Estonia”. The study finds that the ID card is used the most to access e-services; Smart ID holds the second position; username/password and Mobile-ID shares the third choice.
https://link.springer.com/chapter/10.1007/978-3-030-58957-8_12 - [2020-09-01] Kaija Kirch, previously a document expert at the Estonian Police and Border Guard Board (PPA), now works for Cybernetica.
- [2020-08-28] After two years, the court has not yet started to resolve the case of PPA vs Gemalto. In August 2019, a preliminary hearing was held where the possibility of finding a compromise was discussed. However, as of 2020-08-28 no compromise has been reached and both parties have submitted a number of different requests that the court has to resolve.
https://forte.delfi.ee/news/tehnika/politsei-vs-gemalto-kaks-aastat-kohtuveskeid-ja-ei-tuhjagi?id=90871257 - [2020-08-25] CERT-EE identified almost twenty websites that did not check the certificate revocation information when authenticating users with an ID card. In two cases, there was also no check on whether the certificate was signed by SK ID Solutions. This effectively allowed ID card authentication bypass in these services.
https://www.ria.ee/et/uudised/olukord-kuberruumis-juuli-2020.html
https://jarvateataja.postimees.ee/7046443/mitmed-eesti-veebilehed-ei-kontrollinud-autentimisel-sertifikaatide-kehtivust - [2020-08-25] BSc thesis by Sander-Karl Kivivare (UT): “Secure Channel Establishment for the NFC Interface of the New Generation Estonian ID Cards”. The thesis describes the cryptographic protocol that is used to communicate with the Estonian ID card over the contactless interface and provides detailed instructions with code examples in Python, to help software developers create applications that can make use of the new NFC interface introduced in the ID cards issued since December 2018.
https://comserv.cs.ut.ee/ati_thesis/datasheet.php?id=70557&year=2020&language=en
https://github.com/Kivivares/estid-nfc - [2020-08-25] BSc thesis by Jekaterina Gorohhova (UT): “Malicious Android app for security testing”. In the context of this thesis, an Android app was developed to demonstrate how a malicious app with a given set of Android permissions can abuse them to collect personal data stored on a user’s device and then send it out.
https://comserv.cs.ut.ee/ati_thesis/datasheet.php?id=70525&year=2020&language=en - [2020-08-21] RIA has banned the social media app TikTok on all phones belonging to RIA employees and has also recommended the ban to other state institutions. The app is considered a security threat as it is collecting far more information about its users than necessary.
https://news.err.ee/1126180/information-system-authority-in-essence-tiktok-a-security-threat - [2020-08-20] July statistics from the state authentication service TARA show that Smart-ID became the most popular identification tool outperforming the ID card. The number of government agencies using TARA in their e-services is currently between 30-40, but RIA expects it to grow to over a hundred. RIA plans to remove the banklink authentication option from TARA at the end of 2020, as the banks are accessed by the same ID card, Mobile-ID and Smart-ID that are directly supported by TARA as well.
https://forte.delfi.ee/news/digi/smart-id-tousis-koige-populaarsemaks-tuvastusvahendiks-eesti-riigi-e-teenustes?id=90789775 - [2020-08-20] Estonia launched the coronavirus exposure notification app “HOIA” (Keep). The app was created in cooperation with 12 Estonian companies – Cybernetica, Fujitsu Estonia, Guardtime, Icefire, Iglu, Mobi Lab, Mooncascade, Velvet, FOB Solutions, Heisi IT OÜ, Bytelogics and ASA Quality Services OÜ. The development was done at the companies’ own expense. The state only paid for an independent security audit that cost 30,000 EUR. The Data Protection Inspectorate and Chancellor of Justice deems the app suitable as the privacy of its users is protected. RIA also recommends using the app, but notes that the requirement for bluetooth to be constantly on creates additional risks.
https://digi.geenius.ee/rubriik/uudis/aki-peab-eestlaste-koroonaappi-sobilikuks-oiguskantsleri-buroo-jagab-tunnustust/
https://news.err.ee/1125119/feature-estonia-launches-coronavirus-exposure-notification-app-hoia
https://forte.delfi.ee/news/digi/eesti-koroonaapp-maksis-30-000-eurot?id=90849441
https://www.ria.ee/et/uudised/trendid-ja-tahelepanekud-kuberruumis-iii-kvartal-2020.html - [2020-08-14] Research article by Arnis Parsovs (UT): “Estonian Electronic Identity Card: Security Flaws in Key Management”. The article, among other things, provides details about the malpractice of the Estonian ID card manufacturer Gemalto in generating private keys outside the ID card.
https://www.usenix.org/conference/usenixsecurity20/presentation/parsovs - [2020-08-13] Tartu County Court convicted Dennis Einasto of computer fraud that caused nearly €28,500 in damages, of illegally obtaining access to computer systems and of large-scale money laundering. Overall, he was sentenced to 4.5 years in jail. Einasto’s computer contained cryptocurrency and web hosting databases hosting large numbers of usernames and passwords, but which did not belong to him. The cyber crimes were committed on an international scale.
https://news.err.ee/1123315/tartu-county-court-convicts-man-of-cyber-crime-money-laundering - [2020-08-05] The passwords and e-mail addresses of 27,000 users of an unnamed Estonian advertising portal was leaked. The data was accessible for almost a year without the portal being aware of it. The portal has informed users about the leak and the same account data can no longer be used to enter the environment. Although the portal did not inform the Personal Data Inspectorate (AKI) in time, AKI has not yet made a decision on whether supervision proceedings should be initiated.
https://digi.geenius.ee/rubriik/uudis/27-000-eestlase-paroolid-lekkisid-portaal-kuulis-lekkest-aasta-parast-selle-toimumist/ - [2020-07-28] Due to a human error, the Ministry of Justice made a report in their document register public that contaied personal data of approximately 1000 people who sought legal advice. The information listed names and the reason the person had obtained legal aid. The Ministry of Justice has not informed the affected persons about the leak as this would have meant further processing of the data, which was intended to be avoided. According to the ministry, the article published by the media is enough.
https://www.err.ee/1117570/justiitsministeerium-jattis-avalikuks-oigusabi-saanud-inimeste-andmed
https://news.err.ee/1117589/justice-ministry-glitch-leaks-legal-aid-personal-data-online
https://news.err.ee/1129734/ministry-of-justice-has-not-informed-people-of-data-breach - [2020-07-27] BSc thesis by Silver Maala (UT): “A Proof of Concept Malware for Interacting with the Smart-ID Android Application”. The thesis presents a proof-of-concept Android malware that can take over the Smart-ID app running on a rooted Android device.
https://comserv.cs.ut.ee/ati_thesis/datasheet.php?id=69678&year=2020
https://digi.geenius.ee/rubriik/uudis/loputoo-pahavaraga-saab-varastada-smart-id-pin-koode-ja-neid-automaatselt-sisestada/ - [2020-07-23] The National Audit Office has published the audit report “Effectiveness of the e-Residency programme”. The report finds that foreigners with a criminal background and/or business ban have become e-Residents, as PPA does not have the capability to perform sufficient background checking for foreigners. Another noteworthy finding is that only 10% of e-Residents have renewed their digital IDs after expiration.
https://news.err.ee/1117934/audit-criminals-have-become-e-residents-better-background-checks-needed
https://www.err.ee/1117824/riigikontroll-kriminaalid-saavad-liialt-lihtsalt-eesti-e-residendiks
https://www.err.ee/1118255/ott-vatter-kahtlase-paritoluga-e-residentide-suhtarv-on-vaga-vaike
https://mkm.ee/et/uudised/valiskaubandus-ja-it-minister-varske-audit-selge-kinnitus-e-residentsuse-programmi
https://www.err.ee/1118243/ministeerium-eesti-teeb-koik-et-e-residentsust-ei-saaks-ohtu-kujutavad-valismaalased - [2020-07-23] The Ministry of the Interior proposed a bill that would give law enforcement organizations backdoor access to encrypted messaging applications. The idea faced sharp criticism and later the Ministry of Justice rejected the proposal due to the lack of a thorough analysis of the consequences.
https://news.err.ee/1116325/interior-ministry-looking-for-backdoor-into-encrypted-messaging-apps
https://www.err.ee/1115645/siseministeerium-soovib-krupteeritud-sonumirakendustesse-tagaust
https://www.err.ee/1116295/kuberoiguse-ekspert-tagauste-lubamine-muudaks-eesti-digiriigi-aluseid
https://digi.geenius.ee/rubriik/uudis/vandeadvokaat-turk-tagaust-toetavad-inimesed-ei-saa-tegelikult-aru-mida-nad-soovivad/
https://digi.geenius.ee/rubriik/uudis/eesti-e-riigi-endine-peaarhitekt-tehniliselt-ei-ole-voimalik-tagada-et-tagauksest-tulevad-sisse-ainult-oilsad/
https://www.err.ee/1116665/peeter-p-motskula-tagauksega-kruptoside-rumal-ja-oigusvastane-idee
https://www.err.ee/1116669/rainer-ratnik-neli-pohjust-miks-tagaukse-lubamine-pole-moistlik
https://www.err.ee/1127157/kaimar-karu-kuberturbeteatri-kordusetendus
https://www.err.ee/1149441/mkm-tahaks-turvakaalutlustel-keelata-isikustamata-konekaardid
https://twitter.com/ikubjas/status/1295653952554438656
https://twitter.com/ikubjas/status/1329455387683250179 - [2020-07-21] The government has made amendments to the “Statutes of the Health Information System” allowing the authentication of subjects using “ID card, Mobile-ID, Smart-ID or other equivalent device”. Historically, access to the Health Information System has only been granted based on authentication using the ID card. The security requirements have likely been relaxed due to the pressing coronavirus situation.
https://www.riigiteataja.ee/akt/118072020004 - [2020-07-21] Kert Kingo (EKRE), a member of the Riigikogu’s Legal Affairs Committee, explained why EKRE is so worried about i-voting. According to her, the distrust is created by the fact that it is possible to give an i-vote using another person’s ID card and that i-voting data is destroyed immediately after the elections.
https://uueduudised.ee/uudis/eesti/miks-erke-e-valimiste-parast-nii-palju-muretseb-kert-kingo-sest-need-tekitavad-usaldamatust/ - [2020-07-10] Research article by Kaido Kikkas (TalTech) and Birgy Lorenz (TalTech): “Training Young Cybersecurity Talents – The Case of Estonia”. The paper describes the Estonian experience with the CyberOlympics/CyberSpike program from 2017–2019 and reflects on the lessons learned about talent building in cybersecurity.
https://link.springer.com/chapter/10.1007/978-3-030-50729-9_36 - [2020-07-07] Research article by Laura Kask (UT/Proud Engineers) and Kristiina Laanest (RIA): “Determining the Time of Electronic Signing: Legal Requirements and Technological Possibilities”. The authors suggest establishing the time from the timestamp as the time of signing, but fail to address the issues raised in the original article “Time of signing in the Estonian digital signature scheme” by T.Mets and A.Parsovs.
https://www.juridica.ee/article.php?uri=2020_4_elektroonilise_allkirjastamise_aja_tuvastamine_iguslikud_n_uded_ja_tehnilised_v_imalused
https://www.id.ee/wp-content/uploads/2020/10/j_20_4_294.pdf
https://cybersec.ee/timesign/ - [2019-12-19] A research paper by Abasi-amefon Affia (UT): “Assessing the NFC Unlock Mechanism of the Tartu Smart Bike Share System”. The paper describes a flaw in the Tartu Smart Bike Share System that can be exploited to create a clone of a victim’s Tartu bus card, which can then be used to unlock the bikes. To create the clone, only the card number printed on the victim’s Tartu bus card is needed (valid numbers can be guessed). The flaw has now been partially mitigated as cloning is still possible, but the task is not that trivial.
https://kodu.ut.ee/~arnis/bikeshare_nfc.pdf
Cyber Security master’s theses defense in TalTech/UT (August 2020)
Defences of master theses of Cyber Security curriculum on August 17th 2020. The defences will take place online.
Time: 9:30
Student: Tarmo Oja
Title: X-ROAD TRUST MODEL AND TECHNOLOGY THREAT ANALYSIS
Supervisor: Ahto Buldas, Mari Seeba
Reviewer: Aleksandr LeninTime: 10:10
Student: Nikita Snetkov
Title: PRACTICAL IMPLEMENTABILITY OF TWO-PARTY ECDSA SIGNATURE SCHEMES
Supervisor: Ahto Buldas
Reviewer: Aleksandr LeninTime: 10:50
Student: Liubomyr Kushnir
Title: BENCHMARKING OF POST-HOC LOCAL INTERPRETABILITY METHODS FOR CLASSIFYING MALICIOUS TRAFFIC
Supervisor: Hayretdin Bahsi, Sven Nõmm
Reviewer: Pavel TšikulTime: 12:00
Student: Timm Jeff E Luyten
Title: RAISING CYBER AWARENESS WITH NON-IT PROFESSIONALS WORKING IN A HOME OFFICE ENVIRONMENT USING A PILOT VIDEO GAME CONCEPT
Supervisor: Birgy Lorenz
Reviewer: Sten MäsesTime: 12:40
Student: Andrew J Roberts
Title: Development of a cybersecurity evaluation test bed for autonomous self-driving vehicles
Supervisor: Olaf Maennel
Reviewer: Tobias EggendorferTime: 13:20
Student: Ilkin Huseynov
Title: THE ANALYSIS OF THE CURRENT CYBER SECURITY ACTIONS TAKEN IN THE E-GOVERNMENT OF AZERBAIJAN AND PROPOSAL OF THE IMPROVEMENT PLAN
Supervisor: Mika Kerttunen
Reviewer: Adrian VenablesTime: 14:15
Student: Andres Pihlak
Title: CONTINUOUS DOCKER IMAGE ANALYSIS AND INTRUSION DETECTION BASED ON OPEN-SOURCE TOOLS
Supervisor: Mauno Pihelgas
Reviewer: Kristian KivimägiTime: 14:55
Student: Eduard Iltšuk
Title: Two-Party ECDSA Protocol for Smart-ID
Supervisor: Arnis Paršovs
Reviewer: Jan VillemsonTime: 15:35
Student: Aivo Toots
Title: Zero-Knowledge Proofs for Business Processes
Supervisor: Peeter Laud
Reviewer: Marlon Dumas, Janno Siim