- [2020-03-10] The company Unicount has developed an e-service which allows companies to be registered in Estonia using Smart-ID. Companies in the Estonian Business Register can only be directly registered using an ID card or Mobile-ID. The Smart-ID company registration service provided by Unicount is using the company registration API that has been offered since 2017 by the Estonian Business Register.
https://www.ituudised.ee/uudised/2020/03/10/tanasest-saab-ettevotteid-asutada-smart-idga
https://news.err.ee/1061645/estonian-companies-can-now-be-established-using-only-smart-id
https://www.baltictimes.com/estonia__1st_company_founded_with_use_of_smart-id_registered_on_tuesday/ - [2020-03-06] A large-scale cyber attack simulation exercise developed by CybExer Technologies was conducted bringing together 12 Estonian companies and institutions.
https://news.err.ee/1060615/cyber-exercise-brings-together-defense-league-public-and-private-sector - [2020-03-03] Yet another cybersecurity index has placed Estonia in the 58th position. According to the study, 1.59% of mobiles and 13.2% of computers in Estonia are infected with malware.
https://www.comparitech.com/blog/vpn-privacy/cybersecurity-by-country/ - [2020-02-26] For several years, the Estonian ID card software recognized digital signatures created with revoked certificates as valid signatures. Software libraries used by Estonian e-service providers are likely still affected. The EU-developed eSignature DSS library and libraries used in other EU countries are also affected.
https://www.delfi.ee/news/paevauudised/eesti/tartu-ulikooli-turvaspetsi-jarjekordne-avastus-id-kaardi-tarkvaras-oli-aastaid-kriitiline-auk?id=89080065
https://www.youtube.com/watch?v=eYG17IGOCi0 - [2020-02-26] A Smart-ID account can now be created using biometrics. In the enrollment process the Smart-ID app over NFC retrieves person’s photo from their biometrical passport and uses phone’s camera to perform face recognition. For biometrical passport reading Smart-ID uses Dutch company’s InnoValor NFC-based ReadID software, but for face recognision a cloud service provided by UK company iProov. Contrary to the claims, the security guarantees provided by this technology are quite weak, since the facial verification technology at best can verify only the presence of the person and not their intent to create a Smart-ID account. Fortunately, the person is required to confirm their intent either using previous Smart-ID account (including non-qualified) or a security code sent over email or SMS.
https://digi.geenius.ee/rubriik/uudis/riik-vottis-biomeetriliste-passide-toega-smart-id-labivaatamiseks-ajapikendust/
https://tehnika.postimees.ee/6884293/smart-id-kasutajad-peavad-olema-valmis-uuenduseks
https://digi.geenius.ee/rubriik/uudis/smart-id-kasutajaks-saab-nuud-biomeetriaga-kuidas-see-kaib/
https://news.err.ee/1056955/biometric-registration-made-available-to-users-of-smart-id
https://www.iproov.com/newsroom/blog/estonian-digital-identity-with-iproov - [2020-02-26] Self-censorship at UT. The university decided not to publish an article in the University of Tartu magazine, Universitas Tartuensis, about a cooperation agreement between the university and Huawei. Since the Chinese company Huawei is perceived as a potential threat to national security, the Huawei topic has become sensitive.
https://ekspress.delfi.ee/kuum/tartu-ulikool-keelas-ajakirjanikul-huawei-teemalise-artikli-avaldamise?id=89042773
https://www.err.ee/1058339/tartu-ulikool-lubab-huaweiga-koostood-tehes-jargida-eesti-julgeolekuhuve
https://news.err.ee/1056839/paper-university-of-tartu-refused-to-publish-article-on-huawei - [2020-02-25] Teachers and system owners of e-school environments are discussing the acceptable duration of an authenticated session after which the user is automatically logged out. According to RIA, session length is not specified in the ISKE implementation guide and it is up to the system owner.
https://digi.geenius.ee/rubriik/uudis/opetajate-protest-e-opilaspaevikiku-kasutusmugavuse-osas-toi-kaasa-turvariski/ - [2020-02-20] The e-shop reset.ee closed its doors leaving at least 275 customers without money. The police do not consider it a scam but a a civil offense, inviting victims to file a claim in the bankruptcy proceedings.
https://digi.geenius.ee/rubriik/uudis/tarbijakaitse-saatis-politseisse-reseti-asjus-kuriteoteate-aga-politsei-ei-alusta-uurimist/ - [2020-02-12] The state pays for Smart-ID on a per use basis – the more users use Smart-ID, the more the state will have to pay (SK offers volume discounts). Smart-ID users outnumber Mobile-ID users two-to-one today. At the end of 2019, there were 230,000 Mobile-ID users and 430,000 Smart-ID users.
https://news.postimees.ee/6898254/estonia-to-create-new-digital-identification-tool - [2020-02-12] The state’s Mobile-ID contract will expire in 2022. RIA and PPA will announce the procurement for a new eID solution this year. The state does not want to copy Smart-ID, but instead use something else possibly based on biometrics.
https://news.postimees.ee/6898254/estonia-to-create-new-digital-identification-tool
https://tehnika.postimees.ee/6897706/eesti-asub-looma-uut-inimeste-tuvastamise-vahendit - [2020-02-12] The Estonian Foreign Intelligence Service has published their 2020 report. It contains a section on Russian cyber operations in 2019 and mentions potential Chinese threats including Huawei.
https://www.valisluureamet.ee/pdf/raport-2020-en.pdf - [2020-02-12] A ridiculous incident was reported which highlighted the core weakness in Mobile-ID (and Smart-ID). A customer of Luminor Bank unexpectedly logged into a stranger’s bank account. The customer accidentally entered the wrong username and the correct owner of the username confirmed the login with his Mobile-ID. The bank acknowledged that similar incidents have happened before. SEB bank also confirmed similar incidents.
https://epl.delfi.ee/uudised/kogemata-voorale-kontole-turvarisk-toob-netipanka-uue-lahtri?id=88906895 - [2020-02-12] RIA is analyzing the risks of enabling i-voting on iOS and Android mobile devices. It will also have to be decided whether to allow voting using Smart-ID in the next elections. The final decision will rest with the National Electoral Committee.
https://news.postimees.ee/6898254/estonia-to-create-new-digital-identification-tool
https://digi.geenius.ee/rubriik/uudis/riik-otsustab-juba-jargmisel-kuul-kas-valimistel-saab-e-haalt-anda-smart-id-ga/ - [2020-02-11] RIA and PPA launched a cybercrime information website (cyber.politsei.ee) where people are asked to report suspicious emails, account hijacking, money stolen from accounts, etc. The data will be used to inform the public about new crime schemes and to help investigate cases.
https://news.err.ee/1033928/police-launch-cybercrime-information-website - [2020-02-10] After the Tartu Smart Bike Share website had a security flaw which gave access to personal data of registered users, the Data Protection Inspectorate conducted a proceeding on the activities of the Tartu City Government over a longer period of time and concluded that the data leak did not pose a risk to users.
https://digi.geenius.ee/rubriik/uudis/tartu-rattaringluse-andmeleke-ei-kujutanud-kasutajatele-ohtu/ - [2020-02-05] The Estonian ID software introduced an option to sign documents with Smart-ID. Smart-ID signing in DigiDoc4 client uses the additional security measure of the Smart-ID app – the users have to choose the right verification code out of three (similar to LHV bank). Smart-ID support is also planned for Android and iOS DigiDoc apps.
https://digi.geenius.ee/rubriik/uudis/riik-lisab-digiallkirjastamise-tarkvarale-smart-id-toe-soov-on-see-lisada-ka-mobiiliappidele/
https://www.id.ee/index.php?id=39777
https://www.ria.ee/et/uudised/ria-id-tarkvara-voimaldab-nuudsest-smart-idga-digiallkirjastada.html - [2020-02-04] Remote verification will be launched in the e-Notary self-service portal enabling notarial acts to be carried out at Estonia’s foreign representations without physically visiting a notary’s office. In order to perform remote verification, the customer will need an Estonian ID-card, digital ID, Mobile-ID or an e-resident’s digital ID. The personal identification system of the participants will use Veriff’s biometric face recognition technology.
https://news.err.ee/1031373/notary-acts-can-be-carried-out-in-foreign-embassies-from-february
https://www.err.ee/1034421/eesti-notarite-koda-loi-voimaluse-sooritada-toiminguid-interneti-kaudu
https://news.err.ee/1063131/estonian-embassies-join-e-notar-distant-authentication-pilot-project - [2020-01-30] RIA introduced a state signing service (SiGa) to replace DigiDocService. The service allows the creation of documents digitally signed with ID card and Mobile-ID and the validation of signatures. The service is provided to all persons performing public tasks. The software used by the service is public and allows anyone to run a similar service themselves.
https://www.ria.ee/et/uudised/ria-vastvalminud-riigi-allkirjastamisteenus-hoiab-asutuse-kulusid-kokku.html - [2020-01-17] UT, CybExer Technologies, NATO CCDCOE, Thinnect and Elisa Eesti will create a cyber defense environment in the simulation of critical information infrastructure protection on a cyber training ground (whatever it is).
https://news.err.ee/1025354/project-started-to-make-cyberdefense-for-public-and-private-infrastructure - [2020-01-16] A draft bill initiated by MKM would require telecoms to seek state permission when introducing new hardware and software. The security of any new tech will additionally be monitored by RIA, the Internal Security Service (ISS) and the state’s foreign intelligence agency. The restrictions are likely motivated to keep 5G networks away from the Chinese company Huawei, which is suspected of being controlled by the communist Chinese government.
https://tehnika.postimees.ee/6826879/eesti-sidetehnika-hakkab-labima-julgeolekukontrolli
https://tehnika.postimees.ee/6859100/it-minister-karu-esimene-tagasilook-oluline-eelnou-tunnistati-pohiseaduse-vastaseks
https://www.ituudised.ee/uudised/2020/01/28/valitsus-tahab-oigust-lubada-ning-keelata-eesti-sidevorkudes-kasutatavat-tehnoloogiat
https://tehnika.postimees.ee/6873351/minister-karu-noudis-huaweilt-aru
https://tehnika.postimees.ee/6871738/eesti-hakkab-tehnikat-politiseerima
https://www.ituudised.ee/uudised/2020/03/16/sidevorkude-turvalisust-puudutav-eelnou-sai-taiendust-ja-saadeti-teisele-lugemisele
https://news.err.ee/1020859/telecoms-security-bill-may-exclude-huawei-from-estonian-market-firm-says - [2020-01-15] Estonian-based web security company WebARX found a critical vulnerability in the popular WordPress plugin InfiniteWP Client and WP Time Capsule.
https://digi.geenius.ee/rubriik/uudis/eesti-veebiturbe-ettevote-leidis-kriitilise-haavatavuse-mis-mojutab-poolt-miljonit-veebilehte/ - [2020-01-14] Cybernetica will create an automated threat information system between the US Air Force and the Estonian Defense Forces. The US-Estonian cyber-security alert information exchange system will cost €3.54 million. The contract was granted to Cybernetica without competition.
https://tehnika.postimees.ee/6873957/cybernetica-sai-riigilt-magusa-miljonilepingu-ilma-konkurentsita
https://www.err.ee/1023814/eesti-ja-usa-alustasid-kuberkaitsealast-koostood-ohuteabe-vahetamiseks
https://news.err.ee/1023833/estonia-and-the-us-to-build-joint-cyber-threat-intelligence-platform - [2020-01-14] In 2019, PPA instituted 12 disciplinary proceedings due to police officers making non-work related inquiries to the police information system. The police officer who made 35 queries was fired.
https://digi.geenius.ee/rubriik/uudis/politsei-karistas-uheksat-ametnikku-andmebaaside-vaarkasutamise-eest-uks-kaotas-too/ - [2020-01-10] Due to technical issues at RIA, the notification service using @eesti.ee email address was disrupted between December 19 and January 7. In total 85,000 emails were not delivered in this period.
https://tehnika.postimees.ee/6869462/rikke-tottu-ei-joudnud-85-000-riigi-ametlikku-teadet-inimesteni - [2020-01-10] Geenius has contacted the biggest banks in Estonia, asking whether they have enabled security features to prevent criminals using their domain names in e-mail spoofing attacks. Danske Bank, Svenska Handelsbanken, Citadele, SEB and Bigbank has introduced DMARC to prevent e-mail spoofing attacks. Swedbank is still (already for a half a year) considering implementing DMARC. In LHV’s opinion, DMARC implementation is too complicated.
https://digi.geenius.ee/rubriik/uudis/eesti-pangad-on-hakanud-agaramalt-kasutama-tehnoloogiat-millega-e-kirja-pettuseid-valtida/ - [2020-01-08] A family doctor helpline service has been opened offering personalized advice. The hotline staff will have access to a patient’s medical records if the caller grants consent authenticating with Mobile-ID or Smart-ID.
https://news.err.ee/1021433/family-doctors-advice-helpline-cannot-issue-repeat-prescriptions - [2020-01-07] The court denied the early release of Aleksei Vasilev, a 20-year-old student from Kingisepp convicted for finding flaws in the computer networks of Estonian state agencies on the orders of FSB. His 4-year sentence will end on November 4, 2021.
https://news.err.ee/1021428/court-denies-early-release-to-russian-man-convicted-of-working-for-fsb
https://news.err.ee/1010629/court-to-discuss-releasing-juvenile-convicted-of-spying-for-fsb-early - [2020-01-04] The Minister of the Interior was asked how many cases of illegal surveillance have been investigated by authorities. According to the response, 17 cases of private surveillance were registered in 2016, 71 cases in 2017, 22 cases in 2018 and 24 cases in 2019. There was one confirmed case of illegal surveillance and covert listening in 2017.
https://news.err.ee/1020497/authorities-not-interested-in-former-minister-s-bugged-office-claims - [2020-01-03] The database leakage of e-shop charlot.ee will be investigated by Latvian Data Protection Inspectorate, as the leaked database contained more data about clients in Latvia.
https://digi.geenius.ee/rubriik/uudis/eesti-ajaloo-suurimat-e-poe-andmeleket-uurivad-edasi-latlased/ - [2020-01-03] SK ID Solutions has paid a contractual penalty to AS LHV Pank for disruptions in the functioning of the Mobile-ID service, as the maximum permitted downtime of 45 minutes was exceeded in 2019. SEB, Swedbank and Luminor refused to disclose whether they have sought contractual penalties from SK ID Solutions.
https://news.err.ee/1020240/sk-id-solutions-pays-penalty-to-lhv-for-disruptions-in-mobile-id-service - [2020-01-01] Personnel rotation in RIA. In December, Andrus Kaarelson, Deputy Director General of the State Information System Branch at the RIA has left RIA returning to work in the private sector. Margus Arm, previously the head of the Electronic Identity Department has been appointed Deputy Director General of the State Information System Branch. The new head of RIA’s Electronic Identification Department is now Mark Erlich. In December, Lauri Aasmann took over as the new RIA Deputy Director General for Cybersecurity. Aasmann came to RIA from the NATO CCD COE, where he led a team of lawyers. Previously, he worked as a lawyer at Swedbank AS and as a prosecutor at the Northern District Prosecutor’s Office and Tallinn Prosecutor’s Office, where he dealt with white-collar crime and cybercrime.
https://www.err.ee/1010537/ria-kuberturvalisuse-teenistuse-juhiks-sai-lauri-aasmann
https://news.err.ee/1020294/margus-arm-appointed-state-information-system-chief-at-ria
https://www.ria.ee/et/uudised/ria-peadirektori-asetaitjaks-sai-margus-arm.html
https://digi.geenius.ee/rubriik/uudis/riigi-infosusteemi-ameti-uks-tippjuhte-suundub-toole-erasektorisse/
https://www.ria.ee/et/uudised/olukord-kuberruumis-detsember-2019.html - [2019-12-31] A software engineer found a flaw in the Elisa home router which gives access to the management password and access to the router over SSH. Elisa claims that this flaw can only be used by clients themselves, but cannot be used to access other client’s devices.
https://digi.geenius.ee/rubriik/uudis/elisa-koduinterneti-ruuterist-avastati-turvaauk-mis-voimaldab-saada-ligipaasu-tehnilise-kasutaja-paroolile/ - [2019-12-28] Märt Põder gave the presentation “DEBRIEF ON E-VOTING IN ESTONIA” at the 36th Chaos Communication Congress (36C3), explaining his view on the i-voting in Estonia.
https://events.ccc.de/congress/2019/wiki/index.php/Projects:Netizen_index_of_e-voting_requirements
https://docs.google.com/presentation/d/1ON01Fej5w7cnBmTsTIxnaoWFIh_LhuuaoAGkKFAZ0EE/edit?folder=0AKv1cHIDbJwmUk9PVA
https://twitter.com/trtram/status/1211007098194219009 - [2019-12-23] A fraud case involving fake tara deposit checks caused €12,925 in damages. The fake checks were printed with a cashier printer on the same paper as the real checks. The criminals understood the composition of the bar code and configured the printer so that the printout would deceive the Maxima checkout system that prevents the use of a copy of a check receipt. It turned out that the checks were printed by IT specialist from the company that serviced tara vending machines at Maxima stores. The criminals were tracked down using CCTV footage that is stored by the store for 30 days.
https://ekspress.delfi.ee/kuum/aasta-krimiullatus-voltsitud-taaratsekkidega-raha-kokku-ajanud-kelmid-tootasid-nagu-mafioosod?id=88435809 - [2019-12-23] The Supreme Court expressed its position in the case where a woman gave her ID card and PIN codes voluntarily to a man who ordered some merchandise in her name from Telia e-shop using ID card authentication. The case has been sent back to district court. According to the Supreme Court, in case the owner voluntarily gives his ID card with PIN codes to another person who uses the ID card to enter into a transaction, the transaction (or digital signature) may be valid based on the provisions of “entry into transaction through representative” (General Part of the Civil Code Act – GPoCCA – Chapter 8). As the court referenced GPoCCA § 131, this construction can still be attacked and the signed contract later annulled.
https://ekspress.delfi.ee/sisuturundus/e-identimise-vahendite-turvalisest-hoidmisest-ja-tehingutest?id=88465617
https://www.riigikohus.ee/et/lahendid?asjaNr=2-16-124450/77 - [2019-12-21] MyHits radio uploaded, on Google Docs, a publicly available document containing names, phone numbers and email addresses of all participants in their prize game. The link was embedded in the source code of the prize game website. The subjects and Data Protection Inspectorate have been informed.
https://digi.geenius.ee/rubriik/uudis/myhitsi-auhinnamangu-osalejate-andmed-olid-koigile-huvilistele-kattesaadavad/ - [2019-12-20] A group of Estonians used blank chip and PIN cards containing stolen credit card data to empty bank accounts of Indian, Bangladeshi and Pakistani victims. The criminals also attempted to order 17 phones in total from Klick using a Japanese credit card, but were reported to the police.
https://news.postimees.ee/6855114/estonian-gang-emptied-indian-bank-accounts - [2019-12-19] The Supreme Court of Estonia ruled that the bill expanding EDF surveillance rights is unconstitutional. The court said that the covert collection and processing of personal data may be necessary for the effective defense of domestic and external peace, however, legislation should establish efficient procedural guarantees similar to those set out in the Code of Criminal Procedure, in order to eliminate the possibility of the person against whom surveillance is conducted not being informed of the EDF having processed their data.
https://news.err.ee/1015626/top-court-bill-seeking-to-expand-edf-surveillance-rights-unconstitutional - [2019-12-18] A secret camera was found at a metal company AKG Loots. The high-tech camera was installed under the ceiling of the production workshop and was in constant communication. Industrial espionage is suspected, as the company has several international clients with classified contracts.
https://ekspress.delfi.ee/teateid-elust/metallifirmas-leiti-salajane-jalgimisseade?id=88407489 - [2019-12-17] From 2020 PPA will introduce a 5 EUR fee for obtaining a new ID card PIN envelope.
https://raha.geenius.ee/rubriik/uudis/uuest-aastast-saab-id-kaardi-ja-passi-soodsamalt-tellida/ - [2019-12-16] Mobile-ID was down for two hours.
https://digi.geenius.ee/rubriik/uudis/selgus-eilse-mobiil-id-kahetunnise-katkestuse-pohjus/
https://news.err.ee/1014529/mobile-id-service-in-estonia-disrupted-now-back-online - [2019-12-14] A Viljandi hospital patient learned that a hospital nurse had viewed her health information and shared it in Facebook messages with her friend. The nurse has been fined for data breach.
https://leht.postimees.ee/6849818/medode-nuhkis-sobranna-mahitusel-voora-inimese-terviseinfo-jarele - [2019-12-12] The i-voting workgroup published the full report with 25 proposals to improve the i-voting system enhancing credibility and managing risks. In the IT Minister’s opinion, several important directions have been outlined and following working groups should be set up to go deeper into the more specific topics. In Märt Põder’s opinion, the report is a failure as the verifiability(?) issue has not been addressed.
https://www.mkm.ee/sites/default/files/content-editors/e-valimiste_tooruhma_koondaruanne_12.12.2019_0.pdf
https://digi.geenius.ee/rubriik/uudis/e-valimiste-tooruhma-liige-loppraport-on-minu-jaoks-labikukkumine/
https://digi.geenius.ee/rubriik/uudis/it-minister-karu-moodustab-e-valimiste-tooruhma-osas-uued-toogrupid/
https://digi.geenius.ee/rubriik/uudis/e-valimiste-tooruhm-ei-soovi-e-valimisi-ara-lopetada-hoopis-voimalusi-juurde-lisada/
https://tehnika.postimees.ee/6844891/kingo-tooruhm-annab-aru-kas-e-valimised-on-eesti-habiplekk
https://news.postimees.ee/6849632/e-voting-task-force-finishes-report-including-25-proposals-for-improving-system
https://news.err.ee/1013585/e-election-taskforce-report-complete-includes-25-improvement-proposals
https://www.err.ee/1013627/tooruhm-tegi-25-ettepanekut-e-valimiste-parendamiseks
https://news.err.ee/1015470/ria-does-not-have-funds-to-implement-e-election-workgroup-s-proposal - [2019-12-12] Florian Hartleb wrote an article “e-Estonia. Europe´s Silicon Valley or a new 1984?”. The article mentions X-Road, personal ID code, DDoS attacks in 2007, Infineon ID card crisis in 2017 and data embassy project. Contrary to the title, the privacy aspects are not discussed in depth.
https://link.springer.com/chapter/10.1007/978-3-030-27957-8_16 - [2019-12-06] Former Minister of Rural Affairs Mart Järvik claimed that he had detected “bugs” in his office in one section of the ceiling. He tried two eavesdropping detection devices borrowed from his friends. Later, according to an unnamed source, the detected device turned out to be a device for amplifying Wi-Fi signals.
https://news.err.ee/1010579/prosecution-we-do-not-know-what-jarvik-is-talking-about
https://news.err.ee/1011075/mart-jarvik-s-letter-to-helme-about-alleged-eavesdropping
https://news.err.ee/1010506/former-minister-says-he-found-listening-device-in-ministry-of-rural-affairs
https://news.err.ee/1011048/rural-affairs-ministry-no-bugging-device-found-in-former-minister-s-office
https://news.err.ee/1012483/reform-mp-asks-mart-helme-about-alleged-illegal-surveillance-of-jarvik
https://news.err.ee/1011441/jarvik-i-haven-t-seen-a-bug-but-the-equipment-detected-it
https://news.err.ee/1011608/paper-jarvik-bugging-device-a-simple-wifi-signal-amplifier - [2019-12-05] A cryptographer from the Republic of Senegal published a subtle attack against the Smart-ID clone detection mechanism described in the original Smart-ID paper. The flaw allows an attacker who has cloned a victim’s Smart-ID app instance to forge signatures before the victim has used his instance, such that when the victim uses his Smart-ID instance, the attacker’s clone which was used to forge signatures is not detected by the server. The flaw lies in the fact that according to the protocol description, the next expected request ID is set by the client and not the server, which means that after the attack the attacker can reset the next request ID to match the request ID stored in the victims Smart-ID instance, thereby leading to the victim’s next request to be accepted by the Smart-ID server. SK has responded that the actual Smart-ID implementation uses an updated clone detection mechanism which is not affected by this flaw.
https://eprint.iacr.org/2019/1412
https://twitter.com/doomsdaysoup/status/1204399972231331846
https://www.skidsolutions.eu/en/News/iacr-published-smart-ids-cryptanalysis/ - [2019-12-03] Toomas Vaks, former RIA Deputy Director General for Cybersecurity, wrote an opinion piece about cyber risks.
https://leht.postimees.ee/6840530/toomas-vaks-kas-ja-kes-peaks-kartma-kuberohtu - [2019-12-02] Agu Kivimägi wrote his thoughts about the recently highlighted issue that the time of signing of a digitally signed file can be changed.
https://digi.geenius.ee/rubriik/uudis/agu-kivimagi-kas-digiallkirja-aega-saab-usaldada/ - [2019-12-02] SEB has made an update to its Android mobile app, which now allows SEB customers to make payments by touching a payment terminal with their mobile phone. The app can be used to pay for mobile purchases up to €150 if NFC has been enabled on the phone.
https://tehnika.postimees.ee/6839851/seb-apiga-saab-ka-nuud-poes-maksta - [2019-11-29] Phishing attacks against Smart-ID users have advanced. Now attackers are performing active attacks and displaying to victims the correct Smart-ID verification code. The usual defense of comparing verification codes does not work anymore. Now the only defense is to verify that the authentication is performed in the expected web site.
https://www.ria.ee/et/uudised/petturite-ongitsuslehed-muutumas-inimeste-jaoks-usutavamaks.html - [2019-11-29] CERT-EE warned about scam emails sent in the name of SEB bank. A victim from Tartu lost €4,777 in the scam. Security specialists have pointed out that SEB is endangering their clients by not configuring SPF+DMARC to prevent email spoofing using seb.ee domain.
https://kasulik.delfi.ee/news/uudised/hoiatus-tartlane-langes-ohtliku-seb-nimel-leviva-kelmuse-ohvriks-ja-kaotas-pangakontolt-ligi-5000-eurot?id=88072693
https://twitter.com/SadEstonianIT/status/1200422642639130625
https://twitter.com/SadEstonianIT/status/1195009181826404358 - [2019-11-27] Registration of marriage is one of the few things that cannot be concluded digitally. The state is now analyzing the possibility of making marriage registration easier and partly accessible through the state portal eesti.ee.
https://news.err.ee/1007521/state-analyzing-online-marriage-registration - [2019-11-26] People sent letters to the Ministry of Justice and the Chancellor of Justice expressing their dissatisfaction with the fact that the real estate owned by them can be searched in the electronic land register by anyone. The land register has now been modified such that only an authenticated user would be able to search for real estate by name or personal identification code leaving an audit trail.
https://tehnika.postimees.ee/6835333/riik-asus-piirama-kinnistusraamatus-tuhnimist - [2019-11-20] A communication channel has been set up between the police and Facebook, allowing police officers to access Facebook account holders’ information in minutes if police the estimates that there is a real risk to human life. If there is no immediate threat, the request will take longer, sometimes a couple of days. In 2019, PPA asked Facebook about 88 accounts, requiring quick response nine times. Account freezes have been requested for 14 accounts.
https://digi.geenius.ee/rubriik/uudis/kuidas-ja-kui-kiiresti-saab-politsei-facebookist-katte-kaja-kallase-ahvardajate-ja-teiste-kahtlusaluste-andmed/ - [2019-11-20] Using a fake Facebook account, death threats were made towards Reform Party leader Kaja Kallas. According to PPA, the perpetrators are based in Sweden and therefore Kallas’ life was in no immediate danger.
https://news.err.ee/1006702/paper-estonian-and-swedish-police-to-cooperate-over-kaja-kallas-threat
https://news.err.ee/1005823/police-not-opening-criminal-proceedings-into-kaja-kallas-online-threats
https://news.err.ee/1004931/paper-death-threats-against-reform-party-leader-made-in-sweden - [2019-11-20] Rats seriously damaged RIA’s underground optical cable affecting the operation of eesti.ee and the services of the Health Insurance Fund. Although physical network connections are duplicated, these e-services failed to automatically move to another channel.
https://www.ria.ee/et/uudised/olukord-kuberruumis-november-2019.html
https://www.ria.ee/et/uudised/rotid-pohjustasid-riigivorgu-osalise-katkestuse.html
https://www.ria.ee/et/uudised/riigivorgu-oine-kaablivahetus-sujus-torgeteta.html
https://m.arileht.delfi.ee/article.php?id=88126529
https://news.err.ee/1005397/ria-hopes-to-remedy-cable-disruptions-with-automatic-devices-in-future
https://news.err.ee/1005241/e-services-inaccessible-after-rats-chew-through-wires - [2019-10-30] The Estonian Research Council has financed the creation of a programmable USB device with a RGB LED and button, which can be programmed, for example, to emulate a keyboard and send key strokes after it is plugged into the computer. The device was given out to high school students in the Robotex event.
https://hackest.org/usb/ - [2019-09-25] The requirement for an age check when ordering alcohol online is not enforced by all e-shops. Some parcel terminals require the ID card of an adult to be inserted, but the terminal does not ask for a PIN code (which means that the process does not involve any cryptography).
https://epl.delfi.ee/uudised/e-poest-alkoholi-tellides-piisab-taisealise-id-kaardist?id=87524573 - [2019-04-26] TalTech in cooperation with others have created a High School Cyber Security Selection Course Digital Textbook. The textbook contains material on various topics and includes a lot of unseen video materials.
https://web.htk.tlu.ee/digitaru/kyberkaitse/ - [2017-01-27] In Tallinn Circuit Court, defendants contested the integrity of an electronic evidence (a virtual machine image containing Skype logs), based on the fact that the integrity of the disk image was provided by calculating the hash using the outdated MD5 hash function. The defendants demonstrated a practical MD5 collision attack by showing that when opening two visually different image files the calculated MD5 hash value of the files was the same. The court correctly noted that while the MD5 function is not collision resistant, it is still second pre-image resistant guaranteeing the integrity of the collected evidence.
https://journals.sas.ac.uk/deeslr/article/view/5081
Defence of Cyber Security Engineering Diploma Theses at TalTech IT College (January 2020)
January 22nd at 15-17, TalTech IT College, Raja 4C, Tallinn at room 217:
Chairman of the Defence Committee: Priidu Paomets
The Defence Committee: Mohammad Tariq Meeran, Kaido Kikkas, Aleksei Talisainen, Toomas Lepikult
- Title: Countermeasures to Deepfakes
Student: Gabriel Apeh Adoyi- Title: Implementing Authentication and Authorization in Dynamic Web Applications
Student: Christian Cataldo- Title: Windows User Simulation for Scalable Cybersecurity Training Platform
Student: Kustas Kurval
Grades (in random order): 5, 2, 1
Links:
Cyber Security master’s theses defense in TalTech (January 2020)

January 9th, 2020, Akadeemia Tee 15a, room ICT-411.
Time: 10:00
Student: Deniz Basar
Title: Uniqueness Criteria for Blockchain Type Distributed Ledgers
Supervisor: Ahto Buldas
Reviewer: Aleksandr LeninTime: 10:40
Student: Kristian Kivimägi
Title: Predicting students’ success using technical labs as part of university admission to a cyber security program
Supervisor: Kaie Maennel, Olaf Maennel
Reviewer: Stefan SütterlinTime: 11:20
Student: Alessandro Mirani
Title: User Behavior Analysis for Predictive Virtual Reality Applications: An Ethical and Data Security Perspective
Supervisor: Aleksei Tepljakov, Hayretdin Bahsi
Reviewer: Eduard Petlenkov
Cyber Security Newsletter 2019-11-14
- [2019-11-12] RIA organized information day. The topics covered: new Mobile-ID procurement, closure of DigiDocService, authentication gateway, developments in eID field, signature service, X-Road and others. Full video recording available online (in Estonian).
https://www.ria.ee/et/uudised/tana-toimub-ria-koostoopartnerite-infopaev.html
https://riainfopaev2019.publicon.ee/paevakava/ - [2019-11-11] RIA decided to support with EUR 5,550 grant the association for the visually impaired as a compromise for RIA’s failure to support screen readers in DigiDoc4 client.
https://www.ria.ee/et/uudised/ria-solmis-nagemispuudega-inimestega-hea-tahte-margiks-kompromissi.html
https://digi.geenius.ee/rubriik/uudis/kohus-hakkab-vaagima-kas-riik-peab-nagemispuudega-inimestele-vigase-tarkvara-parast-maksma-10-000-eurot/ - [2019-11-11] Supreme Court is discussing EDF law expanding surveillance rights. Chancellor of Justice Ülle Madise has found that the amendments are constitutional, because they do not allow for the restriction of individuals’ fundamental rights any more than the legislation currently in force.
https://news.err.ee/1001642/supreme-court-discussing-edf-law-expanding-surveillance-rights
https://news.err.ee/982963/justice-chancellor-law-expanding-edf-surveillance-rights-constitutional - [2019-11-11] Telia offers NFC-enabled SIM card that can be used in the phone to validate ride on public transport in Tallinn.
https://digi.geenius.ee/rubriik/uudis/tallinna-bussis-saad-nuud-oma-soidu-valideerida-ka-nutitelefoniga-viibates/
https://digi.geenius.ee/rubriik/uudis/juhend-kuidas-kaib-labi-nutitelefoni-uhiskaardiga-valideerimine-ja-palju-see-teenus-maksab/
https://news.err.ee/1001643/what-the-papers-say-accessible-tartu-baby-boom-in-paide - [2019-11-07] SK ID Solutions annual conference was held second time in English. Presentation slides available.
https://www.skidsolutions.eu/en/about/sk-annual-conference/sk-annual-conference-2019 - [2019-11-04] Estonia is planning a system that would collect data from hotels to alert the authorities when somebody on a watchlist checks in. Dan Bogdanov discussed how to build a totally anonymous electronic accommodation card.
https://twitter.com/danbogdanov/status/1189805333146935296
https://digi.geenius.ee/rubriik/uudis/andmeteadlane-kuidas-ehitada-taiesti-anonuumset-elektroonset-majutuskaarti/
https://digi.geenius.ee/rubriik/uudis/testimisse-jouab-riiklik-e-majutuskaart-mis-informeerib-politseid-tagaotsitavatest/ - [2019-11-04] UT researchers performed interdisciplinary research studying Estonian digital signature compliance to national and EU legal requirements. The finding is that the “Signed on” time displayed by DigiDoc software cannot be trusted to establish the actual time of signing. Other finding is that due to the certificate validity suspension option, vast majority of digital signatures created as of now cannot be verified according to legal requirements.
https://cybersec.ee/timesign/ - [2019-10-31] From next year, the Consumer Protection and Technical Surveillance Authority (TTJA) will have the rights to restrict access to e-shops and mobile apps, and will have the right to find out who are the customers of the telecom operators.
https://digi.geenius.ee/rubriik/uudis/ttja-hakkab-e-poodide-ja-appide-kasutust-piirama-kui-muud-meetmed-ei-aita/
https://digi.geenius.ee/rubriik/uudis/riik-saab-hakata-piirama-ligipaasu-e-poodidele-ja-appidele-ning-naeb-operaatorite-klientide-andmeid/ - [2019-10-28] Storm caused extensive power outage that disrupted internet connection in south of the country. Border crossing was disrupted for several hours. Better preparation for next storm needed.
https://news.err.ee/996771/storm-disrupts-agencies-internet-connection-in-south-of-country - [2019-10-25] Justice ministry conducted an audit into whether judges had accessed documents in the court information system regarding cases in which they do not take part. Judges warned that such audits would undermine judges’ confidence in and willingness to use the information systems.
https://news.err.ee/995904/judges-protest-justice-ministry-court-information-inspection - [2019-10-25] Märt Põder shared a photo from IT minister’s i-voting work group and discussed the risk of i-vote selling.
https://gafgaf.infoaed.ee/posts/myya-v3hekasutatud-kryptogramm/ - [2019-10-23] Tele2 blocked foreign phone numbers associated with massive fraudulent call wave. By contrast, Telia and Elisa are not yet blocking the numbers, claiming that intervention of a regulatory body is required.
https://digi.geenius.ee/rubriik/uudis/ootamatu-kaik-tele2-blokeerib-massilise-petukonede-lainega-seotud-valismaised-telefoninumbrid/ - [2019-10-23] IT and foreign trade minister Kert Kingo submited resignation. MKM workgroups will keep working. The new IT minister is Kaimar Karu. In his view the transparency of i-voting should be improved.
https://news.err.ee/995118/it-and-foreign-trade-minister-kert-kingo-submits-resignation
https://digi.geenius.ee/rubriik/uudis/endise-it-ministri-kert-kingo-algatatud-tooruhmad-jatkavad-tood/
https://news.err.ee/1002119/new-ekre-minister-kaimar-karu-in-first-interview-the-weak-need-protection - [2019-10-21] Full list of all concerns raised by the IT Minister Kingo’s i-voting working group has been published.
https://digi.geenius.ee/rubriik/uudis/taispikk-nimekiri-it-minister-kingo-e-valimiste-tooruhma-koik-valja-toodud-murekohed/ - [2019-10-18] The Estonian state will form a large cyber security policy council. MKM wishes to involve 32 different parties. The tasks of the council will include sharing information on sectoral developments and challenges, building situational awareness on cyber security, and addressing cyber security policies.
https://digi.geenius.ee/rubriik/uudis/eesti-riik-moodustab-suure-kuberturvalisuse-poliitika-noukogu/ - [2019-10-09] Data Protection Inspectorate issued memorandom inviting public authorities to not store data on public cloud services, because the confidentiality of the data may not be guaranteed and also the access to data in case of emergency may not be provided.
https://digi.geenius.ee/rubriik/uudis/ameti-margukiri-eesti-riigiasutused-ei-tohi-andmeid-hoiustada-avalikes-pilveteenustes/
https://www.aki.ee/et/uudised/it-kulutohususest-olulisem-turvalisus - [2019-10-05] Research article by TalTech researchers: On Positive Feedback Loops in Digital Government Architecture. The case of Estonia is presented.
https://www.researchgate.net/publication/336362287_On_Positive_Feedback_Loops_in_Digital_Government_Architecture - [2019-10-03] The state wants to reduce the dependency on a single trust service provider and considers running their own trust service provider. Currently ID card and Mobile-ID both depend on SK ID Solutions. SK is ready for competition – Smart-ID provides them with alternative markets.
https://digi.geenius.ee/rubriik/uudis/riik-soovib-vabaneda-riskist-et-id-kaart-mobiil-id-ja-smart-id-on-soltuvad-uhest-firmast/
https://digi.geenius.ee/rubriik/uudis/sk-tahame-enda-valdkonnas-rohkem-konkurentsi-naha/ - [2019-09-30] In September, Smart-ID downtime exceeded the allowed limits due to the problems with failing hardware. This year, three Mobile ID interruptions have exceeded allowed limits.
https://digi.geenius.ee/rubriik/uudis/sel-aastal-on-kolm-mobiil-id-katkestust-uletanud-lubatu-piire/
https://forte.delfi.ee/news/digi/mobiil-id-torkus-jalle-kas-ppa-kehtestab-lopuks-sanktsioonid?id=87888275
https://forte.delfi.ee/news/digi/smart-id-teenusega-esines-torkeid?id=87389433
https://forte.delfi.ee/news/tarkvara/mobiil-id-teenus-hetkel-ei-toota?id=87357159 - [2019-09-30] DigiDocService will be shut down in October 2020. Mobile-ID service will be provided over REST API similar to Smart-ID. Other services (signature and certificate validation) will not be supported.
https://www.skidsolutions.eu/en/News/the-digidocservice-service-will-be-shut-down-in-2020/
https://digi.geenius.ee/rubriik/uudis/mobiil-id-on-vaikselt-saanud-selle-kasutust-mojutavaid-uuendusi-ja-neid-tuleb-veel-juurde/ - [2019-09-26] LHV bank decided to enable Smart-ID API call that requires their clients to choose in mobile app the correct Smart-ID verification code from the three suggested ones. The change is aimed to force their clients to compare the verification codes shown by the Smart-ID application. Unfortunately, such measure helps only against phishing attacks using static phishing pages.
https://www.lhv.ee/et/uudised/2019/29
https://tehnika.postimees.ee/6787356/enneolematu-lhv-pani-smart-id-kasutamisele-lisakontrolli-peale
https://raha.geenius.ee/blogi/lhv-blogi/lhv-muutis-smart-id-kasutamise-veelgi-turvalisemaks/ - [2019-09-25] The state is looking for next generation Mobile-ID. This is partly motivated by the eIDAS requirement for expensive security certification of currently non-certified SIM card platforms.
https://digi.geenius.ee/rubriik/uudis/riik-tahab-mobiil-id-paremaks-muuta-laual-on-mitu-varianti/ - [2019-09-24] Software error disrupted emergency calls for 20-minute period. In total, 26 people called emergency services during the affected period but were called back later.
https://news.err.ee/993893/ria-number-of-cyber-incidents-in-september-slightly-above-annual-average
https://www.ria.ee/et/uudised/olukord-kuberruumis-september-2019.html - [2019-09-19] Researchers discovered “Simjacker” vulnerability that exploits technology embededed on SIM cards used over the world. According to representatives of Tele2, Elisa and Telia, the SIM cards issued in Estonia do not use technology that would enable the attack.
https://www.adaptivemobile.com/newsroom/press-release/adaptivemobile-security-uncovers-sophisticated-hacking-attacks-on-mobile-phones-exposing-massive-network-vulnerability
https://digi.geenius.ee/rubriik/uudis/mobiilioperaatorid-kinnitavad-sim-kaartide-pohine-haavatavus-ei-mojuta-eestlasi/ - [2019-09-13] RIA plans to eventually remove the bank link as an authentication option in government e-services.
https://digi.geenius.ee/rubriik/uudis/ria-plaanib-riigiteenustes-autentimisvoimalusena-pangalingi-ara-kaotada/ - [2019-09-13] RIA finished price negotiations with SK ID Solutions and have introduced Smart-ID for authentication to government e-services. RIA has assessed that Smart-ID authentication solution provides eIDAS security level “high”. Support for signing using DigiDoc client will come in the future.
https://www.ria.ee/et/uudised/ria-votab-riiklikes-teenuses-kasutusele-smart-id.html
https://news.err.ee/980219/public-services-can-soon-be-accessed-using-smart-id
https://leht.postimees.ee/6776871/eesti-vottis-ametlikult-kasutusele-smart-id - [2019-09-12] Ministry of Foreign Affairs will launch a cyber diplomacy department headed by Heli Tiirmaa-Klaar, a diplomatic representative with special powers in the field of cybersecurity.
https://news.err.ee/979941/department-of-cyber-diplomacy-to-launch-later-this-year - [2019-09-10] EuroPark has obtained the details of 6000 vehicle owners who have not paid the parking fee. Previously the court ordered Estonian Road Administration to share car owner personal data with EuroPark.
https://kasulik.delfi.ee/news/uudised/europark-on-katte-saanud-6000-soidukiomaniku-andmed-kellel-on-parkimistrahv-tasumata?id=87391211 - [2019-07-09] Research article by Emin Caliskan, Risto Vaarandi, Birgy Lorenz (TalTech): Improving Learning Efficiency and Evaluation Fairness for Cyber Security Courses: A Case Study. They present a case study on the Cyber Defense Monitoring Solutions course from TalTech Cyber Security MSc program.
https://link.springer.com/chapter/10.1007/978-3-030-22868-2_45
Cyber Security Newsletter 2019-09-05
- [2019-09-03] OSCE assessed Estonian 2019 parliamentary elections and have produced report containing recommendations for i-voting. According to OSCE, the Election Service should develop a strategy to reduce the risk of internal attack before the next election, and should also publish third-party risk assessments, audits and other reports before the next election.
https://digi.geenius.ee/rubriik/uudis/rahvusvahelise-ekspertruhma-raport-leidis-eesti-e-valimiste-osas-mitu-kriitilist-kohta/
https://www.osce.org/odihr/elections/estonia/424229 - [2019-09-03] Uku Särekanno, head of cyber security at RIA, starting October will take up duty at the European Union’s IT agency eu-LISA, where he will coordinate the deployment of new large-scale databases in the Schengen area. RIA will be looking for new Deputy Director General.
https://www.err.ee/976328/ria-tippametnik-liigub-el-i-it-agentuuri-juhtima-andmebaaside-rakendamist
https://www.ria.ee/et/uudised/uku-sarekanno-asub-toole-euroopa-liidu-it-agentuuri-eu-lisa.html - [2019-09-03] Estonian passports will be manufactured by ID Global Solutions Limited. They will provide all the templates and equipment but PPA will print them. Currently Gemalto OY provides the service (until 2021). To mitigate the risks the state prefers to purchase ID-1 format documents and travel documents from different companies (source: Lips et al.).
https://news.err.ee/976363/id-global-solutions-awarded-estonian-passport-contract-from-2021
https://www.err.ee/976324/eesti-passe-asub-tootma-id-global-solutions-limited - [2019-08-29] I-voting workgroup members have submitted 30 suggestions for improvements. Among them is the proposal that the number of people involved in conducting and supervising elections should increase and to raise the number of independent observers at election counts.
https://news.err.ee/974715/e-voting-workgroup-recommends-more-audits-and-observers - [2019-08-23] MoD announced MSc thesis scholarship competition in categories: cryptography; situational awareness; accounting of defense material; planning and management of defense infrastructure; drones. The Master’s thesis scholarship competition is aimed primarily at students entering the Master’s program, but applications may also be submitted by second-year students who have not yet chosen a Master’s Thesis.
http://www.kaitseministeerium.ee/et/eesmargid-tegevused/teadus-ja-arendustegevus/kaitsealaste-magistritoode-stipendiumikonkurss - [2019-08-15] Minister of Finance showed Director General of PPA printout with the line that the document has been digitally signed. It turned out that the document was only a draft which has not been signed. This created a discussion on whether the printout was a forgery.
https://www.postimees.ee/6754513/lauri-lugna-mina-ei-ole-allkirjastanud-elmar-vaheri-toolepingu-peatamist
https://digi.geenius.ee/rubriik/teadus-ja-tulevik/taltechi-professor-selgitab-mis-on-digiallkiri-ja-ajatempel-ja-kas-neid-saab-voltsida/
https://digi.geenius.ee/rubriik/uudis/advokaat-pelgalt-allkirjastatud-digitaalselt-kirjutamine-dokumendile-pole-allkirja-voltsimine/ - [2019-08-06] The Estonian government approved objectives to simplify processing of identity documents at foreign representations by introducing online applications and streamlining of passport deliveries by mail. Contrary to government proposal, PPA thinks that mailing documents has security risks and is currently not working on such plan.
https://news.err.ee/968060/police-think-delivering-passports-id-documents-via-courier-not-safe
https://news.err.ee/966949/applying-for-receiving-estonian-passports-ids-abroad-to-be-simplified - [2019-08-07] Microsoft Security Response Center published the list of 75 most valuable security researchers who have contributed to securing the Microsoft’s customers and the broader ecosystem this year. Estonian Jaanus Kääp is among them. He was there also last year.
https://msrc-blog.microsoft.com/2019/08/07/announcing-2019-msrc-most-valuable-security-researchers - [2019-08-07] Gemalto left Estonia without paying to PPA legal expenses of litigation process.
https://tehnika.postimees.ee/6747591/gemalto-lasi-eestist-jalga-aga-suur-volg-jai-maha - [2019-07-31] Visually impaired people claimed 10 000 EUR from RIA due to faulty DigiDoc4 software that did not support screen readers for nearly a year. RIA refused to pay.
https://digi.geenius.ee/rubriik/uudis/nagemispuudega-inimesed-esitasid-vigase-id-kaardi-tarkavara-tottu-riigile-10-000-eurose-noude/
https://digi.geenius.ee/rubriik/uudis/ria-jatab-puuetega-inimestele-10-000-eurot-maksmata/ - [2019-07-28] Silvia Lips, Krista Aas, Ingrid Pappel and Dirk Draheim wrote an article “Designing an Effective Long-Term Identity Management Strategy for a Mature e-State” where they analyze the process of developing identity management strategy white paper.
https://link.springer.com/chapter/10.1007/978-3-030-27523-5_16
https://www.ria.ee/sites/default/files/content-editors/EID/valge-raamat-2018.pdf - [2019-07-26] Head of SK ID Solutions reported about a scam where criminals promise several thousands of euros in earnings. During a Skype call people are asked to share access to their computer. After making the connection, people are prompted to insert ID card into the computer and criminals use it to create a Smart-ID account on behalf of the person. This is quite extreme scam which is hard to prevent with technological means. Nevertheless, these scams should not be used as an excuse for the scams that rely on the poor security design choices of Mobile-ID/Smart-ID.
https://digi.geenius.ee/rubriik/uudis/levib-veel-uks-uus-pettus-nuud-luuakse-inimestele-arvutist-ule-kauguhenduse-smart-id-kontosid/
https://news.err.ee/971425/ria-more-cyber-incidents-than-average-registered-in-july - [2019-07-23] IT minister to establish cybersecurity working group whose task will be to coordinate the implementation of the 2019-2022 cybersecurity strategy. This is the third strategy document for the cybersecurity and safety field that defines a longer-term vision for the sector, the objectives to be achieved, and priority courses of action, roles and responsibilities for achieving it.
https://news.err.ee/964005/it-minister-to-establish-cybersecurity-working-group - [2019-07-22] The first-ever Tallinn Summer School of Cyber Diplomacy was held in Estonia, bringing to Estonia approximately 80 diplomats, researchers and experts engaged in cyber issues.
https://vm.ee/en/news/diplomats-eu-and-nato-countries-will-discuss-essential-cyberspace-issues-tallinn-week - [2019-07-22] Cyber Security Summer School 2019 took place. This time it was organized by UT on the bockchain topic.
https://blog.cs.ut.ee/2019/07/22/summary-of-the-cyber-security-summer-school-2019/ - [2019-07-17] Estonian Juhan Lepassaar was elected from among 80 candidates to become the next executive director of the European Union Agency for Cybersecurity (ENISA).
https://blog.ria.ee/juhan-lepassaar-kuberpotis-oleme-koik-koos/
https://news.err.ee/962076/juhan-lepassaar-elected-director-of-eu-agency-for-cybersecurity - [2019-07-12] Olerex had it’s customer transaction database stolen. The leak affects about 100 000 transactions concluded in the previous month and a half. It consisted mostly of business client’s names, personal identification numbers, fueling limits and other undisclosed pieces of data. The database was freely available online for a month and a half. Olerex claims that the data was downloaded only by an IT security expert who has confirmed to Olerex that the data has been deleted.
https://news.postimees.ee/6730265/client-information-leaked-from-olerex
https://news.err.ee/961211/information-authority-urges-attention-to-cybersecurity-following-breaches
https://digi.geenius.ee/rubriik/uudis/ria-tunnistab-et-olerexi-andmelekke-avalikustamisel-tehti-viga/
https://majandus24.postimees.ee/6727953/hiigelleke-olerexis-patid-said-katte-kuni-100-000-kliendi-andmed
https://digi.geenius.ee/rubriik/uudis/olerexi-it-juht-hoiatas-eile-it-spetsialiste-veebiserveritest-norkusi-otsivate-bottide-eest/
https://digi.geenius.ee/rubriik/uudis/uus-suur-andmeleke-olerexi-andmebaasi-turvaaugu-tottu-lekkis-kuni-100-000-tehingu-info/ - [2019-07-10] Tartu Smart Bike Share website maintained by Bewegen Technologies had a security flaw which allowed to access personal data of registered users (contact details and usage history). Bewegen fixed the flaw in few hours and claimed that nobody except the person who reported the flaw had accessed the data.
https://digi.geenius.ee/rubriik/uudis/tartu-rattaringluse-infosusteemist-leiti-turvaviga-mis-lubas-ligi-paaseda-laenutajate-andmetele/
https://www.tartu.ee/en/node/10640 - [2019-07-10] Smart-ID account creation using Mobile-ID has been augumented with SMS notification containing security code that has to be entered when creating Smart-ID instance. This should prevent Mobile-ID phishing attacks towards Smart-ID account creation. To date, there are 42 cases in Estonia where Smart-ID counterfeit accounts were created, in 10 cases it was actually used. Unfortunately, this does not address Mobile-ID/Smart-ID phishing attacks against other services.
https://www.id.ee/index.php?id=39509
https://digi.geenius.ee/rubriik/uudis/smart-id-tegemisel-on-nuud-suur-muudatus-mis-peaks-valistama-voltskontode-loomise/
https://digi.geenius.ee/rubriik/uudis/kalev-pihl-meie-meede-maandab-smart-id-riske-paremini-kui-ria-pakutud-lahendus/
https://digi.geenius.ee/rubriik/uudis/smart-id-petuskeemi-ohvriks-langes-tervelt-28-inimest/
https://digi.geenius.ee/rubriik/uudis/kurjategijad-proovisid-smart-id-kontosid-luua-ka-juunis-kummekond-korda-jouti-kontosid-ara-kasutada/
https://digi.geenius.ee/rubriik/uudis/uus-statistika-kurjategijad-jatkasid-smart-id-kontode-valja-petmist-ka-maikuus/ - [2019-07-03] Web shop charlot.ee leaked usernames, home addresses and plaintext passwords of 14 000 users. The personal details were published as plain text documents and were easily found by googling. The manager of the company initially denied the leak, but later admitted it. So far, there have been no cases in Estonia where the Data Protection Inspectorate has fined some companies for data leakage.
https://digi.geenius.ee/rubriik/uudis/toimus-eesti-ajaloo-suurim-e-poe-andmeleke-ripakil-olid-14-000-eestlase-isikuandmed/
https://digi.geenius.ee/rubriik/uudis/andmekaitseinspektsioon-alustab-andmeid-lekitanud-e-poe-osas-menetlust/
https://news.err.ee/961211/information-authority-urges-attention-to-cybersecurity-following-breaches - [2019-07-02] At the National Defense Council meeting it was agreed that MKM would come out by the end of the year with proposals to strengthen the country’s cryptographic and information security areas. It also gave an overview of the current status of the agreed activities following the ID-card crisis of 2017.
https://www.ituudised.ee/uudised/2019/07/02/kaljulaid-peame-kuberturbe-alast-voimekust-suurendama - [2019-06-28] Email notices sent by the state to personal_ID_code@eesti.ee (but not name@eesti.ee) address will be stored on a virtual “mailbox” on eesti.ee, regardless of whether e-mail forwarding has been configured.
https://blog.ria.ee/eesti-ee-meiliaadressidest-ja-postkastist/ - [2019-06-28] ICR2019 workshop took place. Video recordings of the presentations are online.
https://www.ttu.ee/institutes/centre-for-digital-forensics-cyber-security/events-19/interdisciplinary-cyber-research-icr-workshop/icr2019-3/agenda-6/ - [2019-06-26] PPA found that due to a technical failure, for more than 15 000 automatically revoked ID cards the certificates were not revoked, which in 285 cases resulted in the ID card of the deceased person being electronically abused by other persons. The bug was discovered already in 2015, but investigated only in the begginning of 2019. Praise to the authorities for not sweeping the incident under the carpet!
https://news.err.ee/956106/thousands-of-id-cards-not-properly-deactivated-due-to-software-glitch - [2019-06-26] Father of i-voting Tarvi Martens made quite a strong statement saying that the i-voting system has no weaknesses and nothing depends on people or computers.
https://news.postimees.ee/6715816/e-voting-creator-the-system-is-bulletproof - [2019-06-22] Märt Põder wrote in his blog why he accepted invitation to take part in i-voting workgroup.
https://gafgaf.infoaed.ee/posts/linnamyyr/ - [2019-06-21] The i-voting workgroup has been established and members have been listed. The working group is headed by MKM and includes RIA, the election service, research institutions and other experts. The task of this working group will be to analyze the security and transparency of electoral system processes and, if necessary, make suggestions for improvement. The workgroup will present its report by 12 December 2019 at the latest, which will include an assessment and proposals for system security and public awareness.
https://news.err.ee/958188/it-minister-convenes-inaugural-e-voting-working-group
https://digi.geenius.ee/rubriik/uudis/it-minister-kingo-kutsus-kokku-tooruhma-ja-votab-e-valimised-luubi-alla/
https://www.ituudised.ee/uudised/2019/06/07/it-minister-kingo-kutsub-kokku-e-valimiste-tooruhma
https://mkm.ee/et/uudised/kinnitati-e-valimiste-tooruhma-koosseis
https://www.mkm.ee/et/uudised/valiskaubandus-ja-it-minister-kutsub-kokku-elektroonilise-valimissusteemi-ja-elektroonilise - [2019-06-19] President has rejected the amended Defence Forces Organisation Act for the second time, the Supreme Court will look into the constitutionality of the act this fall. The bill of amendments would grant the Estonian Defence Forces (EDF) the right to secretly gain access to data of the state, municipalities, and legal as well as private persons. EDF argues that this is needed to improve background checks.
https://news.err.ee/953694/supreme-court-to-decide-on-military-surveillance-expansion-this-fall - [2019-06-17] RIA is preparing to implement a new national information security standard, which will replace the ISKE reference security system, which is currently mandatory for public authorities in Estonia. In May, the public procurement process was completed and KPMG Baltics, Cybernetica and TalTech will start assembling a new information security standard. The new standard and accompanying materials should be ready by the end of next year.
https://www.ria.ee/et/uudised/olukord-kuberruumis-mai-2019.html - [2019-06-06] RIA had annual conference. The slides are available.
https://www.ria.ee/et/uudised/ria-juht-peame-pingutama-et-digiriigi-sisu-ei-jaaks-mainest-maha.html
https://www.ria.ee/et/kalender/ria-aastapaeva-konverents-06-06-2019.html - [2019-06-04] PPA will not apply contractual sanctions against SK for Mobile-ID downtime in May.
https://digi.geenius.ee/rubriik/uudis/mobiil-id-teenusepakkuja-paases-politsei-sanktsioonidest/ - [2019-05-14] The report “Development and application of cryptography in the Estonian public and private sectors” commissioned by the Ministry of Defence has been released. The report prepared by Cybernetica gives an overview of the state of art in development of cryptography in Estonia, and analyzes the technological and economic potential of the field. Among recommendations is establishment of a national cryptographic competence centre and improving math and science education in Estonia.
https://www.etag.ee/wp-content/uploads/2019/05/Krypto_KAM.pdf
Cybersecurity related bachelor’s and master’s theses in University of Tartu 2018/2019 (August)

The defences took place on the last week of August.
Student: Aleksandr Tsõganov (Software Engineering MSc)
Title: Integrating User Identity with Ethereum Smart Contract Wallet
Supervisor: Orlenys López Pintado, Aivo Kalu, Kristjan Kuhi
Reviewer: Fredrik Payman MilaniStudent: Rahul Puniani (Innovation and Technology Management MSc)
Title: Conceptualization of a Blockchain Based Voting Ecosystem in Estonia
Supervisor: Fredrik Payman Milani, Mihkel Solvak
Reviewer: Orlenys López PintadoStudent: Indrek Purga (Conversion Master in IT)
Title: Detection of forged PDF documents
Supervisor: Kristjan Krips
Reviewer: Alo PeetsStudent: Shahla Atapoor (Computer Science MSc)
Title: On Privacy Preserving Blockchains and zk-SNARKs
Supervisor: Helger Lipmaa, Janno Siim, Karim Baghery
Reviewer: Ivo KubjasStudent: Mart Simisker (Computer Science MSc)
Title: Security of Health Information Databases
Supervisor: Jan Willemson, Dominique Unruh
Reviewer: Meelis Roos
Links:
https://comserv.cs.ut.ee/ati_thesis/index.php?year=2019
https://www.cs.ut.ee/sites/default/files/www_ut/augusti_kaitsmiste_ajakava_28-08-2019.pdf
Cyber Security Engineering bachelor’s theses defense in TalTech (June 2019)

Monday, June 3 at 9.00-15.00, room 217, curriculum Cyber Security Engineering
Chairman of the Defence Committee: Valdo Praust
The Defence Committee: Kaido Kikkas, Toomas Lepikult• Steven Rugam, “Cyber Security Assessment for Panbaltic Information System”
• Mikus Teivens, “Detection of Web-based Malware in Linux Environment Using YARA”
• Farhan Nayeem Islam, “Testing and Comparing Android Based Penetration Testing Tools”
• Mark Parfeniuk, “Designing Effective Measures to Promote Secure Video Conferencing”
• Frank Korving, “Choosing and Implementing Continuous Integration: the Case of Certidude”
• Kirill Trunov, “Distributed Payment Automated Systems Risk Assessment and Management”
• Nika Ptskialadze, “Comparative Analysis of Open-source and Proprietary Security Information and Event Management (SIEM) Tools”
• Peep Kuulme, “Cybersecurity Awareness Training Program at Hansab Group OÜ”
• Christopher James Vallintine Carr, “Analysing the Security of Internet Facing Industrial Control Systems – Estonian Refrigeration Companies”
• Andris Männik, “Functionality and Efficiency of Modern Protection Software”
Cyber Security Newsletter 2019-06-02
- [2019-05-30] In the EP elections the long time i-voting observer was asked to stop filming the vote counting on the grounds that his camera is a communication device, which could leak the results of i-voting before the allowed deadline. The observer wrote formal complaint, will see the response. It is quite naive to believe that some organizational measures could prevent leaking the results if someone from the observers really wanted to do so.
https://digi.geenius.ee/rubriik/uudis/valimisteenistus-korvaldas-europarlamendi-e-haalte-kokkulugemiselt-vaatleja/
https://www.riigiteataja.ee/akt/305062019003
https://digi.geenius.ee/rubriik/uudis/segadus-e-haalte-vaatleja-osas-valimisteenistuse-juhi-ja-kaebaja-utlused-on-vastuolus/ - [2019-05-27] Bernhards Blumbergs (TalTech) defended his PhD thesis on “Specialized Cyber Red Team Responsive Computer Network Operations”
https://digi.lib.ttu.ee/i/?12015& - [2019-05-26] In the EP elections 2019, 25.4% of voters cast their vote using i-voting method. There was a technical glitch concerning candidate data on the electoral website, which lasted for about 12 hours and meant that candidate searches did not yield a result on names which included diacritical marks.
https://news.err.ee/946026/grazin-e-vote-cancellation-bid-rebuffed-by-electoral-committee - [2019-05-17] Mobile-ID users have experienced phishing attacks, where the victim is tricked into authorizing creation of Smart-ID instances, which then can be used by the attacker without victim’s consent. Some victims lost money, the police investigation is ongoing. In the beginning of the year, users of SEB, Swedbank and LHV bank experienced similar phishing attacks, where the victims were asked to authorize Smart-ID transactions made by the attacker. According to authorities, Mobile-ID and Smart-ID is secure, the negligent users are to be blamed.
https://digi.geenius.ee/rubriik/uudis/hullem-kui-id-kaardi-kriis-smart-id-turvaauk-ajab-pangad-ja-eksperdid-arevile/
https://www.ria.ee/et/uudised/ria-aprillikuu-raport-kurjategijad-loid-inimeste-teadmata-smart-id-kontod.html
https://www.ituudised.ee/uudised/2019/05/23/pangaliit-smart-id-pettusi-aitab-valtida-ettevaatlikkus
https://news.postimees.ee/6689341/e-services-suffer-worst-breach-yet
https://www.err.ee/943492/riik-hindab-smart-id-d-ka-pettustelaine-jarel-turvaliseks-lahenduseks
https://www.err.ee/937490/lhv-hoiatab-lhv-nimel-saadetud-ongitsuskirjade-eest
https://digi.geenius.ee/rubriik/uudis/ettevaatust-kurjategijad-petavad-tana-eestlastelt-smart-id-paroole-valja/ - [2019-05-17] SK’s Mobile-ID service again experienced unexpected downtime. This time the downtime was for more than 24 hours. Due to downtime EMTA decided to extended deadline for submitting declarations. PPA is considering imposing some contractual fines against SK. The contract is confidential and it is not known how much the state pays to SK and what is the benefit for the state to be formally involved in the “issuance” of Mobile-IDs.
https://news.err.ee/938354/mobile-id-service-restored-after-day-of-disruptions
https://raha.geenius.ee/rubriik/uudis/maksuamet-pikendab-mobiil-id-torke-tottu-deklaratsioonide-esitamise-tahtaega/
https://forte.delfi.ee/news/tarkvara/ppa-kaalub-mobiil-id-torgete-tottu-sanktsioonide-rakendamist?id=86240169
https://digi.geenius.ee/rubriik/uudis/mobiil-id-teenuse-katkestus-on-kestnud-juba-ule-poole-paeva/
https://digi.geenius.ee/rubriik/uudis/mis-juhtus-mobiil-id-ga-ja-miks-see-veel-ikka-osaliselt-maas-on/ - [2019-05-13] The new IT minister announced that there are plans to conduct an analysis of the i-voting system and independent international audit to make sure that the process of i-voting is transparent and ultimately verifiable. The previous IT minister, who resigned shortly after being appointed, stated that coalition considers ending i-voting if it does not resist “the toughest tests”.
https://digi.geenius.ee/rubriik/uudis/uus-it-minister-viime-labi-e-valimiste-susteemi-analuusi-ja-soltumatu-rahvusvahelise-auditi/
https://digi.geenius.ee/rubriik/uudis/uus-it-minister-kaalume-e-valimiste-lopetamist-kui-see-ei-pea-vastu-koige-kovematele-testidele/ - [2019-05-09] RIA and MoD is offering 1.1 million to study: “Simulation of Critical Information Infrastructure Protection in the Cyberspace”. The purpose is to develop a virtual environment in which to simulate situations in the area of vital critical information infrastructure.
https://www.ituudised.ee/uudised/2019/05/09/riik-otsib-kuberkaitse-uuringu-labiviijat - [2019-04-23] Estonian Foreign Intelligence Service has published job ad looking for Microsoft administrator and IT support personnel. It is not common for intelligence agencies to publish job advertisements.
https://digi.geenius.ee/rubriik/uudis/eesti-koige-salajasem-luureamet-otsib-enda-ridadesse-avalikult-kahte-it-tootajat/ - [2019-04-03] Baltic Security and Security Summit took place. Among the Estonian speakers were Liisa Past and Uko Valtenberg.
https://tehnika.postimees.ee/6560059/otseulekanne-infoturbekonverentsilt-security-summit - [2019-04-01] RIA released “Annual Cyber Security Assessment 2019”. Among other things it includes interview with Dominique Unruh (UT) about post-quantum cryptography.
https://www.ria.ee/sites/default/files/content-editors/kuberturve/ktt_aastaraport_eng_web.pdf
https://www.ria.ee/sites/default/files/content-editors/kuberturve/kuberturvalisus-2019.pdf - [2019-04-01] In the “Annual Cyber Security Assessment 2019” RIA disclosed details about the vulnerability in eesti.ee authentication system discovered in June 29, 2018. Turns out that bank link implementation on eesti.ee side did not verify signature, which allowed the attacker to bypass authentication. According to RIA, they checked logs and did not find evidence of the flaw being exploited. It is not said whether the logs actually contained full parameters to retrospectively verify the signatures.
https://digi.geenius.ee/rubriik/uudis/eesti-ee-keskkonnas-oli-ohtlik-turvaviga-mis-lubas-sinna-siseneda-teise-inimesena/ - [2019-04-01] RIA plans to expand i-voting system to referendums and other types of elections.
https://news.err.ee/925891/information-system-authority-looks-to-expand-e-voting-as-continuous-service - [2019-03-22] Ministry of Interior published code of conduct for crisis situations, among other things, recommending to be prepared for disruptions in e-services, including the ID card, Mobile-ID, and other means of authentication.
https://kriis.ee/en/preparing-for-crisis-situations/cyberattack-or-cyber-incident/ - [2019-03-22] Margus Noormaa was appointed as the new Director General of RIA by Minister of Economic Affairs and Communications (MKM).
https://www.err.ee/922725/ria-peadirektoriks-saab-margus-noormaa - [2019-03-22] From the leaked password dumps journalists found at least 356 passwords belonging to people working in the public sector.
Head of CERT-EE claims that the cyber hygiene of state officials has improved in the recent years.
https://digi.geenius.ee/rubriik/uudis/bingo1-ja-123kalle-vaata-kui-norgad-paroolid-on-eesti-tipp-poliitikutel-ja-ametnikel/
https://digi.geenius.ee/rubriik/uudis/ria-lekkinud-paroolid-naitavad-kuberhugieeni-taset-viis-aastat-tagasi/ - [2019-03-20] Mihkel Solvak (UT) gave presentation “Anonymized i-voting log data: how can it be used or abused to understand voter behavior?” (time: 1:15:07).
https://www.uttv.ee/naita?id=28355 - [2019-03-14] Authorities plan to perform security analysis to decide whether to implement i-voting with mobile phones starting 2021.
https://tehnika.postimees.ee/6545060/eesti-kaalub-tosiselt-minna-ule-ka-m-haaletamisele
https://digi.geenius.ee/rubriik/uudis/riigi-plaan-mobiiliga-saab-haaletada-juba-jargmistel-valimistel/ - [2019-03-13] Aivo Kalu (Cybernetica AS) gave presentation on SplitKey technology used by Smart-ID solution.
https://csrc.nist.gov/CSRC/media/Presentations/SplitKey-Case-Study/images-media/Kalu%20and%20van-de-Poll-threshold-crypto-March-2019.pdf - [2019-03-13] Cybernetica released now cryptography study commissioned by RIA. This time the focus is on post-quantum cryptography.
https://www.ria.ee/et/uudised/kruptograafia-uuring-aitab-kaasa-turvalisemate-lahenduste-leidmisele.html - [2019-03-07] Estonian pet register used 15-digit chip identifier which was not random. This allowed to download data about thousands of dogs and cats and their owners.
https://epl.delfi.ee/news/eesti/ule-eestiline-register-voimaldas-alla-laadida-tuhandete-lemmikloomaomanike-andmeid?id=85544497 - [2019-03-07] President refused to promulgate the new law that would grant the Estonian Defence Forces (EDF) the right to secretly gain access to data of the state, legal as well as private persons, clandestinely follow individuals, and carry out other surveillance activities against persons.
https://news.err.ee/946931/riigikogu-backs-extension-of-military-surveillance-capabilities - [2019-03-05] CERT-EE warned about malware emails originating from @swedbank.ee domain. Part of the blame, however, must be taken by Swedbank, because it has not enabled DKIM email authentication for swedbank.ee domain.
https://twitter.com/CERT_EE/status/1103214465766641664
https://twitter.com/SadEstonianIT/status/1110220361575120896 - [2019-03-02] In Riigikogu elections 2019, 43.8% of voters cast their vote using i-voting method. One antivirus software considered the i-voting application a virus. There were many appeals. Two appeals related to i-voting procedure reached Supreme Court, but were rejected. However, the Supreme Court found that the rules in place for identifying, counting and mixing up the votes, as well as signing the results, should be clarified in regulatory acts.
http://forte.delfi.ee/news/digi/piltuudis-tuntud-viirusetorje-arvab-et-eesti-valimisrakendus-on-viirus?id=85397077
https://news.err.ee/917378/richness-of-life-demanding-recount-of-e-votes
https://www.valimised.ee/sites/default/files/uploads/rk2019/RK2019_Visitors_programme_slides.pdf
https://news.err.ee/924034/supreme-court-e-voting-regulations-need-legal-act-clarification - [2019-03-01] RIA is planning public procurement for developing Estonian information security standard.
https://www.ria.ee/et/uudised/kolmapaeval-toimub-riigihanke-eesti-infoturbestandardi-valjatootamine-teabepaev.html - [2019-02-28] Starting from March, SEB and Swedbank will stop providing ID card support services. PIN code replacement will be possible only in PPA customer service points.
https://digi.geenius.ee/rubriik/uudis/homsest-saab-id-kaardi-pin-koode-asendada-ainult-politseis/ - [2019-02-28] Data Protection Inspectorate ordered to close down website of math exercises for minors, because no data protection conditions were published and processing of personal data for persons under age 13 was done without consent of the parents.
https://digi.geenius.ee/rubriik/uudis/matemaatikaulesannete-veebileht-edastab-avalikult-paroole-ja-naitab-opilaste-isikuandmeid/ - [2019-02-25] Estonian social network rate.ee is storing plaintext passwords and recently a critical flaw was found which allowed to read private messages.
https://tehnika.postimees.ee/6531236/korobeiniku-flirdiportaali-rate-ee-kasutajate-eravestlused-voisid-lekkida - [2019-02-09] Tallinn public transport ticket system, which allows passengers to pay with contactless payment cards, has no realtime communication with banking systems, debiting the amount when it gets online. As a result, it is possible to pay also with these bank cards where contactless payments have been disabled. The good news (for passengers) is that debiting payments for these cards will fail. To fight against free-riders, such payment cards after their use will get blacklisted by ticketing system terminals.
https://tehnika.postimees.ee/6519517/jahmatav-avastus-tallinna-piletisusteem-muub-soiduoigust-ka-rahatu-pangakaardiga
https://raha.geenius.ee/eksklusiiv/auk-piletisusteemis-validaator-vottis-pangakaardilt-raha-ehkki-viipemaksed-olid-keelatud/ - [2019-02-07] Apparently in Estonia the information what property a person owns is a public information.
https://digi.geenius.ee/rubriik/uudis/kas-teadsid-sellest-portaalist-saab-igauks-tasuta-vaadata-millist-kinnisvara-sa-omad/ - [2019-02-07] Estonian Foreign Intelligence Service released annual report describing cyber threats on page 52. No crypto puzzle this year.
https://www.välisluureamet.ee/pdf/raport-2018-ENG-web.pdf - [2019-02-04] Former State Prosecutor Steven-Hristo Evestus will continue his career in the cybersecurity company CybExer Technologies. CyberExer has already hired top personnel from NATO CCDCOE, CERT-EE, SK, and others.
https://digi.geenius.ee/rubriik/uudis/steven-hristo-evestus-liitub-cybexeriga/ - [2019-01-31] All three major Estonian banks: SEB, Swedbank and LHV have joined the flash payment system today, which means that up to 95% of payments within Estonia will reach the recipient in just a few moments.
https://tehnika.postimees.ee/6512535/eesti-pankade-vahel-liiguvad-tanasest-maksed-valgukiirusel - [2019-01-31] The court has ordered PPA to take down video showing detention of crime suspect. The court found that even though the important details that would allow the person to be identified were blurred, the person had become identifiable by means of additional information available.
http://www.delfi.ee/news/paevauudised/eesti/politsei-peab-eemaldama-sotsiaalmeediast-video-hubert-hirve-kinnipidamisest?id=85191065 - [2019-01-30] On January 17, data leak with 280 000 email addresses and passwords containing Estonian domains (.ee) was published.
https://www.ria.ee/et/uudised/jaanuaris-avalikustatud-andmelekkekogu-sisaldab-460-000-eesti-meiliaadressi.html - [2019-01-28] From 1st to 5th July 2019, the annual Cyber Security Summer School will take place. The focus this year will be on blockchain technologies and its impact on digital transformation.
http://studyitin.ee/c3s2019 - [2019-01-28] The 5th Interdisciplinary Cyber Research (ICR) Conference 2019 will take place on 29th of June 2019. Deadline for abstracts is 15 April 2019.
https://www.taltech.ee/institutes/centre-for-digital-forensics-cyber-security/events-19/interdisciplinary-cyber-research-icr-workshop/icr2019-3/ - [2019-01-25] Card payments rise as ATM withdrawals fall. In Estonia around €1.50 are spent by card for every €1 withdrawn.
https://news.err.ee/904120/card-payments-rise-as-atm-withdrawals-fall - [2019-01-23] Martin Paljak found that the entire electronic functionality of new Estonian ID card can be used also over the contactless interface. To establish the connection only the CAN code printed on the ID card must be known.
https://github.com/martinpaljak/esteidhacker/wiki/NFC - [2019-01-21] Geenius raised attention to a registration form in school’s website, which was not served over a secure connection. Good to see that non-TLS forms are not anymore accepted as a norm.
https://digi.geenius.ee/rubriik/uudis/reaalkool-kogus-sisseastumise-isikuandmeid-ule-ebaturvalise-uhenduse/ - [2019-01-16] Court decided that private company “Europark Estonia” has the right to obtain personal data of car owners from traffic register maintained by Road Administration. Road Administration decided not to appeal the decision.
https://majandus24.postimees.ee/6500697/kohus-europark-voib-maanteeametilt-nouda-parkimisrikkujate-andmeid - [2019-01-14] The use of Smart-ID in state services is behind price negotiations, Smart-ID being twice expensive than Mobile-ID.
https://geenius.ee/uudis/smart-id-kasutamine-riigi-teenustes-seisab-hinnalabiraakimiste-taga/ - [2019-01-12] From February three major banks SEB, Swedbank and Coop Bank will discontinue code cards, Smart-ID being the most popular tool for authentication.
https://news.err.ee/897951/three-major-high-street-banks-phase-out-pass-code-cards-beginning-february
https://tehnika.postimees.ee/6499400/25-000-swedbanki-klienti-ahvardab-veebiteenuseta-jaamine - [2019-01-11] MKM issued regulation specifying requirements for Trust Service Providers who provide certification services for certificates included in Estonian identity documents. According to the regulation, OCSP certificate validity service is currently recognized as vital service, while time-stamping and Mobile-ID service is not.
https://www.riigiteataja.ee/akt/115012019011 - [2019-01-10] Scientific study of Estonian X-Road usage log patterns suggests that e-governance adoption is linear.
https://novaator.err.ee/897071/e-riigi-vereringe-logianaluus-paljastab-millised-e-kodanikud-me-oleme
https://www.sciencedirect.com/science/article/pii/S0736585318309390 - [2018-12-27] RIA released white paper “Identity Management and Identity Documents 1.0”
https://www.ria.ee/sites/default/files/content-editors/EID/valge-raamat-2018.pdf - [2018-10-23] Bank of Estonia has published interesting statistics about bank card fraud in 2016. The majority – 76% of fraudulent transactions are related to e-shopping on the Internet, 18% using payment terminals and only 6% using ATMs.
https://www.eestipank.ee/blogi/kaardipettused-kolinud-internetti
Cybersecurity related bachelor’s and master’s theses in University of Tartu 2018/2019 (June)

The defences are taking place on the first and second week of June.
Student: Ivo Pure (Cyber Security MSc)
Title: An Automated Methodology for Validating Web Related Cyber Threat Intelligence by Implementing a Honeyclient
Supervisor: Risto Vaarandi, Raimundas Matulevicius
Reviewer: Alejandro ManzanaresStudent: Bruno Didier Produit (Cyber Security MSc)
Title: Optimization of the ROCA (CVE-2017-15361) Attack
Supervisor: Arnis Paršovs
Reviewer: Jan VillemsonStudent: Kärt Padur (Cyber Security MSc)
Title: Information Security Risk Assessment in the Context of Outsourcing in a Financial Institution
Supervisor: Raimundas Matulevičius, Liis Rebane, Toomas Vaks
Reviewer: Andro KullStudent: Marek Matsalu (Cyber Security MSc)
Title: The Development of Digital Forensics Workforce Competency on the Example of Estonian Defence League
Supervisor: Raimundas Matulevičius, Hillar Põldmaa
Reviewer: Hayretdin BahsiStudent: Pubudini Gayanjalie Dissanayake (Cyber Security MSc)
Title: A Comparison of Security Risk Analysis in the In-house IT Infrastructure and Cloud Infrastructure for the Payment Gateway System
Supervisor: Hayretdin Bahsi, Raimundas Matulevičius
Reviewer: Alexander Horst NortaStudent: Lukáš Bortník (Cyber Security MSc)
Title: Mobile Phone Digital Evidence Providers to Investigate Driver’s Distraction
Supervisor: Pavel Laptev, Satish Narayana Srirama
Reviewer: Matthew SorellStudent: Mari Seeba (Conversion Master in IT)
Title: A Specification of Layer-Based Information Security Management System for the Issue Tracking System
Supervisor: Raimundas Matulevičius, Ahto Buldas
Reviewer: Meelis RoosStudent: Doris Sarapuu (Conversion Master in IT)
Title: Penetration Testing of Glia’s Web Application
Supervisor: Kristjan Krips, Carlos Paniagua
Reviewer: Riivo TalvisteStudent: Kaspar Kala (Conversion Master in IT)
Title: Refinement of the General Data Protection Regulation (GDPR) Model: Administrative Fines Perspective
Supervisor: Raimundas Matulevičius, Jake Tom
Reviewer: Eneken TikkStudent: Maksym Yerokhin (Software Engineering MSc)
Title: Multi-level Policy-aware Privacy Analysis
Supervisor: Pille Pullonen, Luciano García-Bañuelos
Reviewer: Sara BellucciniStudent: Reelika Tõnisson (Computer Science MSc)
Title: Tighter Post-quantum Secure Encryption Schemes Using Semi-classical Oracles
Supervisor: Dominique Peer Ghislain Unruh
Reviewer: Sven LaurStudent: Helen Tera (Computer Science BSc)
Title: Introduction to Post-Quantum Cryptography in Scope of NIST’s Post-Quantum Competition
Supervisor: Dominique Unruh
Reviewer: Raul-Martin RebaneStudent: Omar Purik (Computer Science BSc)
Title: Creation of Practical Assignments on Information Security for High School Students
Supervisor: Kristjan Krips, Tauno Palts
Reviewer:
Links:
https://comserv.cs.ut.ee/ati_thesis/index.php?year=2019
https://www.cs.ut.ee/sites/default/files/www_ut/kaitsmised_v_30-05.pdf
Cyber Security master’s theses defense in TalTech (May 2019)

May 27th, 2019, Akadeemia Tee 15a, Room ICT-411.
Time: 10:00
Student: Olesia Yaremenko
Title: Skills Evaluation of Participants of Cybersecurity Exercises on the Example of a Virtual Hands-on Forensic Lab
Supervisor: Sten Mäses
Reviewer: Kaie MaennelTime: 10:40
Student: Saber Yari
Title: Creating Cyber Security Exercises for Open Source Intelligence and Reverse Engineering
Supervisor: Sten Mäses
Reviewer: Birgy LorenzTime: 11:20
Student: Heleri Aitsam
Title: Teaching Cyberethics and Measuring Cyberethical Behavior in a Classroom Setting
Supervisor: Sten Mäses
Reviewer: Birgy LorenzLUNCH 12:00-12:40
Time: 12:40
Student: Jaana Metsamaa
Title: Framework for Measuring and Maximizing Security Feature Impact in Business to Business SaaS Products
Supervisor: Andro Kull
Reviewer: Erwin OryeTime: 13:20
Student: Bitchiko Kodua
Title: Creating Labs for Web Application Security and Methods of Defining Difficulty Levels
Supervisor: Hayretdin Bahsi
Reviewer: Kaie MaennelBREAK 14:00-14:30
Time: 14:30
Student: Jorge Alberto Medina Galinda
Title: Generation of Malware Behavioral Datasets in a Medium Scale IoT Networks
Supervisor: Hayretdin Bahsi
Reviewer: Olaf MaennelTime: 15:10
Student: Roman Kononov
Title: Macintosh Operating System Exploitation and Intrusion Prevention
Supervisor: Toomas Lepik
Reviewer: Olaf MaennelTime: 15:50
Student: Kristine Hovhannisyan
Title: Applying Confidence-Building Measures to Cyber Conflict: Computer Emergency Response Cooperation and Cyber Espionage
Supervisor: Eneken Tikk; Olaf Maennel
Reviewer: Anna-Maria Osula
May 28th, 2019, Akadeemia Tee 15a, Room ICT-315.
Time: 10:00
Student: Alberto Zorrilla Garza
Title: Beaconleak: Use and Detection of 802.11 Beacon Stuffing as a Covert Channel
Supervisor: Olaf Maennel
Reviewer: Hayretdin BahsiTime: 10:40
Student: Krishna Vaishnav
Title: Analysis of WhatsApp Data Obtained before the General Election (Lok Sabha) 2019 in India
Supervisor: Olaf Maennel
Reviewer: Adrian VenablesTime: 11:20
Student: Alessandro Mirani
Title: Unintentional Cybercrime
Supervisor: Tiia Sõmer
Reviewer: Sten MäsesLUNCH 12:00-12:40
Time: 12:40
Student: Abenezer Berhanu Weldegiorgis
Title: Developing National Cybersecurity Strategy for Ethiopia
Supervisor: Mika Kerttunen
Reviewer: Tiia SõmerTime: 13:20
Student: Tambet Paljasma
Title: Validating Docker Image and Container Security Using Best Practices and Company Policies
Supervisor: Margus Ernits
Reviewer: Alejandro Guerra ManzanaresBREAK 14:00-14:20
Time: 14:20
Student: Kirke Pralla
Title: Creation of Freely Accessible Interactive Training Materials for Secure Android Development
Supervisor: Margus Ernits
Reviewer: Alejandro Guerra ManzanaresTime: 15:00
Student: Annika Aavaste
Title: How to Improve Data Protection and Information Security in Local Governments Using GDPR compliant training
Supervisor: Eneken Tikk
Reviewer: Matthew SorellTime: 15:40
Student: Randel Raidmets
Title: A Comparative Analysis of Open-Source Full Packet Capture Software Solutions
Supervisor: Mauno Pihelgas
Reviewer: Risto Vaarandi
May 29th, 2019, Akadeemia Tee 15a, Room ICT-315.
Time: 10:00
Student: Nikita Kuznietsov
Title: Researching Underground Forums to Improve Fraud Detection at TransferWise [RESTRICTED defense]
Supervisor: Jaan Priisalu; Sandra Horma
Reviewer: Aleksandr LeninTime: 10:40
Student: Kristopher Ryan Price
Title: Analysis of the Impact of Poisoned Data within Twitter Classification Models
Supervisor: Jaan Priisalu; Sven Nõmm
Reviewer: Kieren LovellTime: 11:20
Student: Andreas Jürimäe
Title: The Security Implications of DMARC in Estonian Goverment Institutions Based on Phishing Attacks in Cambridge University
Supervisor: Kieren Lovell
Reviewer: Hayretdin BahsiLUNCH 12:00-12:40
Time: 12:40
Student: Vita Krainik
Title: Distributed Consensus Problems and Protocols: a Systematic Literature Review
Supervisor: Ahto Buldas
Reviewer: Alex NortaTime: 13:20
Student: Deniz Basar
Title: Uniqueness Criteria for Blockchain Type Distributed Ledgers
Supervisor: Ahto Buldas
Reviewer: Jaan PriisaluBREAK 14:00-14:20
Time: 14:20
Student: Henry Okere
Title: Analysis of a Node-based Integrity Attack on Networked SCADA Power Plant
Supervisor: Hayretdin Bahsi
Reviewer: Ahto BuldasTime: 15:00
Student: Mostafa Hadi
Title: Making the shift from DevOps to DevSecOps at Distribusion Technologies GmbH
Supervisor: Hayretdin Bahsi
Reviewer: Kieren LovellTime: 15:40
Student: Joanna Rose Castillon Del Mar
Title: Automated Photo Categorization for Digital Forensic Analysis Using a Machine Learning-Based Classifier
Supervisor: Hayretdin Bahşi; Leo Mršić; Krešimir Hausknecht
Reviewer: Matthew Sorell
May 30th, 2019, Akadeemia Tee 15a, Room ICT-315.
Time: 10:00
Student: Kayla Marie Cannon
Title: America’s Panopticon: Privacy Implications of Facial Recognition By Law Enforcement
Supervisor: Mika Kerttunen
Reviewer: Hayretdin BahsiTime: 10:40
Student: Andres Antonen
Title: Securing an Automated Code Testing System
Supervisor: Ago Luberg
Reviewer: Toomas LepikTime: 11:20
Student: Jessica Ai Truong
Title: Evaluating the Detection Accuracy of JA3 and JA3S in Security Monitoring of SSL Communication
Supervisor: Hayretdin Bahsi
Reviewer: Toomas LepikLUNCH 12:00-12:40
Time: 12:40
Student: Tornike Nanobashvili
Title: Improving the Use of a Cyber-Insurance Product in Georgia: the Example of Commercial Banks
Supervisor: Eneken Tikk; Mika Kerttunen
Reviewer: Hayretdin BahsiTime: 13:20
Student: Arefeh Fathollahi Kalkhoran
Title: Data Breach: NIST and GDPR
Supervisor: Eneken Tikk
Reviewer: Mika KerttunenBREAK 14:00-14:20
Time: 14:20
Student: Chinmay Khandekar
Title: Cookie Security and its Implementation in the Light of GDPR and E-Privacy Regulation
Supervisor: Eneken Tikk
Reviewer: Rain OttisTime: 15:00
Student: Nurbanu Konayeva
Title: Application of Active Learning for Botnet Detection
Supervisor: Hayretdin Bahsi; Sven Nõmm
Reviewer: Risto VaarandiTime: 15:40
Student: Raul Ezequiel Jimenez Haro
Title: Forensic Tool to Study and Carve Virtual Machine Hard Disk Files
Supervisor: Pavel Laptev
Reviewer: Hayretdin Bahsi
May 31th, 2019, Akadeemia Tee 15a, Room ICT-315.
Time: 10:00
Student: Maarja Heinsoo
Title: Implications of Information Security Culture on Risk Management – Case of a Technology Company
Supervisor: Hayretdin Bahsi
Reviewer: Kaie MaennelTime: 10:40
Student: Prabin Krishna Subedi
Title: Forensics Analysis of Client-Side Artifacts in Cloud-Based Applications
Supervisor: Hayretdin Bahsi
Reviewer: Matthew SorellTime: 11:20
Student: John Chukwufumnanya George
Title: Analysis of the Impact of Bank Verification Number on Financial Security in Nigeria and Potential Cyber Threat Through Social Engineering
Supervisor: Andro Kull
Reviewer: Sten MäsesLUNCH 12:00-12:40
Time: 12:40
Student: Roman Müller
Title: Analysis of the Estonian X-tee network based on centralized log data [RESTRICTED defence]
Supervisor: Jaan Priisalu; Sven Nõmm
Reviewer: Peeter LaudTime: 13:20
Student: Ragnar Kobin
Title: A Model for Evaluating State Cyber Security Exercises
Supervisor: Rain Ottis; Kim Joonsoo
Reviewer: Tiia SõmerTime: 14:20
Student: Sasan Rezaeifars
Title: Hands-on Lab for Teaching Security Misconfiguration and Broken Authentication
Supervisor: Sten Mäses
Reviewer: Andro Kull
























