- [2018-12-21] Estonian criminal police has once again published job advertisement that requires to solve some puzzle. This time there is a cryptic MySQL database published.
https://geenius.ee/uudis/kui-suudad-selle-kruptilise-kuber-moistatuse-ara-lahenda-ootab-sind-eestis-ainulaadne-tookoht/ - [2018-12-20] Martin Paljak discovered that PIN envelopes for the new generation Estonian ID cards (issued by IDEMIA) have a security flaw which allows to see through the envelope with flashlight.
https://news.err.ee/886313/new-id-card-issue-codes-can-be-read-using-torch-without-opening-envelope
https://tehnika.postimees.ee/6481827/ekspert-avastas-eesti-uue-id-kaardiga-seotud-turvaprohmaka
https://tehnika.postimees.ee/6486878/id-kaardi-turvaumbrik-ei-paista-enam-labi - [2018-12-19] Due to some human error, several confidential contracts were available publicly on the Ministry of the Environment file management system.
https://tehnika.postimees.ee/6481004/keskkonnaministeeriumist-lekkisid-arisaladused - [2018-12-12] RIA has announced EUR 315k procurement to create SIGa (Signature and Signature Validation Service) which will enable public authorities to add digital signature support to their e-services with minimal development costs. RIA has already created a federated authentication system (supports ID card, Mobile-ID and bank link authentication) which can be used by the public sector.
https://tehnika.postimees.ee/6475645/riik-loob-uhise-digiallkirjastamise-teenuse - [2018-12-04] Cryptography professor Dominique Unruh (UT) has been awarded a 1.7 million grant by ERC to develop quantum cryptography solutions and their computer-based control methods.
https://www.ut.ee/en/news/ut-researcher-awarded-significant-grant-e-estonia - [2018-12-03] The new generation ID cards are being issued by IDEMIA. The cards have color photo and new physical security features. Contact-less interface is disabled by default – requires security analysis before enabling. New cards uses different API (IAS ECC standard), therefore software has to be updated. In the new specification the “Card Management Key” has been renamed to “Police Key”. This has raised suspicion about possible backdoor key in the ID card.
https://news.err.ee/883962/estonia-s-first-new-id-cards-to-be-issued-this-week
https://geenius.ee/uudis/uute-id-kaartide-tootja-lubab-kaartide-isikustamine-toimub-rangelt-ainult-eestis/
https://geenius.ee/uudis/uutele-id-kaartidele-paaseb-ligi-politsei-votmega-milleks-see-moeldud-on/ - [2018-11-28] Estonian Defence Forces Cyber Command (military unit performing also offensive cyber operations) is hiring. The competitive advantage for work in Cyber Command is that people are given quite free hands (because there is no money to be made) and access to exclusive weapon systems not seen in the private sector. The unit has been assembled from the existing staff and communications battalion. The primary recruitment point is the conscripts.
https://geenius.ee/uudis/uus-joud-eesti-it-tooturul-meelitab-helgemaid-paid/
https://geenius.ee/uudis/kuberajateenija-voib-juhtuda-et-tuleb-kirjutada-koodi-ka-lahingvarustuses/ - [2018-11-28] The head of the Institute of Estonian Academy of Security Sciences (SKA) wants to hold a debate about making the state’s work easier by allowing it to analyze masses of cell phone data. There is an opinion that the state is already using far more cell phone data than is admissible for ensuring privacy.
https://news.postimees.ee/6464646/estonia-s-cyber-reputation-owed-to-putin - [2018-11-09] RIA’s Director General Taimar Peterkop has been appointed by the Prime Minister Jüri Ratas as Secretary of State. Peterkop played a key role in solving the 2017 ID card crisis. New head of RIA is to be appointed.
https://geenius.ee/uudis/ria-juht-taimar-peterkop-saab-uueks-riigisekretariks/
https://news.err.ee/875809/taimar-peterkop-named-new-secretary-of-state - [2018-11-08] Smart-ID solution has been certified by German TUViT as a qualified signature creation device (SSCD), hence Smart-ID signatures now are legally equivalent to handwritten signature. From service provider’s perspective, however, the transaction cost for Smart-ID is double the cost of Mobile-ID. Smart-ID still cannot be used for I-voting, because currently the law requires electronic voter identification using a document issued by the Estonian state.
https://news.err.ee/875538/smart-id-signatures-now-legally-equivalent-to-handwritten-signature
https://sk.ee/en/News/smart-ids-security-was-recognized-on-the-highest-possible-level/
https://geenius.ee/uudis/smart-id-arendaja-jargmise-sammu-peab-tegema-riik-et-smart-id-ga-avalikele-teenustele-ligi-paaseda/
https://geenius.ee/uudis/suur-uudis-smart-id-saab-vordseks-omakaelise-allkirja-ja-id-kaardiga/
https://geenius.ee/uudis/smart-id-vordsustamine-omakaelise-allkirjaga-tuli-eesti-riigile-ullatusena/
https://geenius.ee/uudis/elisa-smart-id-uuendus-on-tervitatav-aga-ei-paku-otseseid-eeliseid-vana-ees/
https://geenius.ee/uudis/telia-mobiil-id-on-endiselt-vajalik-ega-kao-kuskile/
https://geenius.ee/uudis/riigikogu-valimistel-e-haalt-smart-id-abil-anda-ei-saa-kull-tulevad-aga-mitmed-muud-vaiksemad-muudatused/ - [2018-11-07] Estonians working in airports and airplanes must fill out a ten-page KAPO form, which requires them to specify, among other things, the names of Facebook, Twitter, Instagram and other social accounts, all telephone numbers, and even the current place of residence and contact details of “previous spouse or person similar to marriage”. It is estimated that up to 3,000 people may be subject to a such background check required by the Minister of the Interior from October 30.
https://ekspress.delfi.ee/kohver/reisiuudised-eesti-alustas-lennundustootajate-radikaalse-taustakontrolliga?id=84238029 - [2018-11-07] Personal identification code for the woman was updated due to the change of date of birth. The state information systems were not ready for such change. Around 300 persons will get new personal identification code because of updated date of birth.
https://news.err.ee/875268/birth-date-mismatches-mean-nearly-300-getting-new-id-code
https://www.postimees.ee/6401054/87-aastase-oilme-taassund-raputas-e-riiki - [2018-11-06] PPA submitted one more claim against Gemalto asking 300k EUR for not informing PPA about the ID card ROCA vulnerability.
https://news.err.ee/874973/ppa-seeking-300-000-from-gemalto - [2018-11-06] RIA plans to create few 2-3 minutes long educational videos showing how cyber attacks happen.
https://geenius.ee/uudis/riik-tahab-hakata-demovideotega-naitama-kuidas-kuberrunnakud-tootavad/ - [2018-11-06] Criminals took over transaction partners’ email accounts and phished out from Estonian company 80k EUR.
https://tehnika.postimees.ee/6446437/eesti-ettevote-langes-erakordse-kuberpettuse-ohvriks-ja-maksis-hakkeritele-kopsaka-summa - [2018-10-31] Owners of 3-year valid digital ID cards can remotely extend their Digi-ID validity to 5 years.
https://www.ria.ee/et/uudised/ppa-digi-id-kaartide-kehtivusaega-saab-kahe-aasta-vorra-pikendada.html
https://www.id.ee/index.php?id=39010
https://medium.com/e-residency-blog/estonia-is-extending-the-validity-period-of-32-000-digital-id-cards-810d6dbaf73b - [2018-10-25] Gemalto has submitted counter-claim against PPA for PPA being in bad faith (whatever it means) in the compromise negotiations in September.
https://news.err.ee/871871/former-id-card-manufacturer-gemalto-files-against-ppa - [2018-10-19] CERT.LV organized international cybersecurity conference “Cyberchess 2018”. Webapp pentester from Estonia Silvia Väli (Clarified Security) talked about the vulnerabilities she found in the Electron framework.
https://cert.lv/en/2018/09/cybersecurity-conference-cyberchess-2018
https://www.youtube.com/watch?v=NXq1uVyBbkU - [2018-10-18] SilverTicket system had a flaw which allowed to buy tickets without paying for them. The user had to simply access the return URL visible in the bank link request.
https://geenius.ee/uudis/turvaauk-eesti-piletiportaalist-sai-endale-tasuta-pileteid-valjastada/ - [2018-10-15] Due to unknown error, for years sensitive personal data of children was publicly available in the Estonian Schools Information System (EKIS) document register.
https://news.postimees.ee/6431380/personal-information-of-children-publicly-available-for-years
https://geenius.ee/uudis/koolide-infosusteemist-lekkisid-opilaste-iseloomustused/ - [2018-10-10] Interview in jail with Russian student Aleksei Vasilev accused of penetrating state systems on the orders of FSB. According to him, he wrote a code to access the internal wireless network of an unnamed state agency. He is disappointed that Russian authorities show no interest to help him in his situation.
https://news.postimees.ee/6426230/spy-left-out-in-the-cold-my-homeland-forgot-about-me - [2018-10-10] In the Riigikogu scientific policy conference Professor of Information Security Ahto Buldas (TalTech) in his presentation “E-government base-technologies as a secure protector” stated that current e-government information systems have not been built with the knowledge of engineering based on scientific worldview and attack resistance of systems and components has not been measured. He invited the state to cooperate with universities.
https://novaator.err.ee/867961/teadlane-eesti-e-riigi-kui-susteemi-rundekindlust-ei-tahetagi-moota - [2018-10-05] Starting from November it is possible to buy tickets in Tallinn public transport using contact-less bank cards.
http://forte.delfi.ee/news/digi/uus-valideerimissusteem-toob-kaasa-muudatused-opilastele-ja-mitme-kaardiga-viipajatele?id=83891613
http://forte.delfi.ee/news/digi/video-puust-ja-punaseks-kuidas-toimib-uus-viipemaksetega-validaator?id=83902919 - [2018-10-01] Estonian police is using license plate recognition cameras on the Estonian roads (scale not known). Large part of cameras used by police have known security vulnerabilities.
https://geenius.ee/uudis/eesti-politsei-kasutab-kahtlaseid-hiina-kaameraid-mis-on-usas-turvakaalutlustel-keelatud/ - [2018-09-27] Police (PPA) sued Gemalto claiming 152 million for generating keys outside Estonian ID card.
https://news.err.ee/864523/police-claim-152-million-from-id-card-producer-gemalto - [2018-09-21] Last year Estonian security authorities eavesdropped on a total of 4,596 calls made in Telia’s network. This is ten times that of Sweden (taking into account countries’ population). Judges sign off on an average of 90% of the wiretap requests. Of all wiretaps 30% concern drug crime investigations, and another 30% suspected corruption cases. Number of wiretaps has stayed the same in recent years. For the purpose of counterintelligence the Office of the Prosecutor General does not need to suspect someone of having committed a crime to order a wiretap. Frequently the information obtained is in turn used to open actual criminal proceedings against individuals.
https://news.err.ee/862992/estonian-state-taps-ten-times-as-many-phones-as-sweden-finland
https://news.err.ee/866369/prosecutor-sees-no-problem-with-high-number-of-wiretaps-lawyers-disagree - [2018-09-20] Professor of eGovernment Robert Krimmer (TalTech) calculated price for voting, i-vote being the cheapest (2.32 EUR) compared to voting on election day (4.37 EUR).
https://tehnika.postimees.ee/6409689/hinnalipik-sai-kulge-kui-palju-maksab-uks-haal-eesti-valimistel - [2018-09-19] eID Forum 2018 was held on 19-20 September. ID card 2017 crisis was among the discussed topics.
https://www.eidforum.org/agenda
https://novaator.err.ee/862756/oppetund-id-kaardi-kriisist-me-ei-peaks-ootama-tehnoloogialt-taiuslikkust - [2018-09-18] In the context of upcoming elections, RIA will provide personalized cybersecurity counseling to political parties and will pentest their websites. RIA has also significantly contributed to the ENISA handbook on election security “Compendium on Cyber Security of Election Technology”.
https://geenius.ee/uudis/riik-hakkab-otsima-erakondade-veebide-norkusi-ja-koolitama-kandidaate/
https://www.ria.ee/en/news/european-union-members-share-advice-cyber-security-elections.html
https://www.err.ee/851275/ria-euroopa-parlamendi-valimised-voivad-saada-kuberrunnakute-marklauaks - [2018-09-17] Cybernetica AS and TalTech organizes Second Workshop on the Protection of Long-Lived Systems (17-18 September, Pärnu, Estonia).
http://plls2018.ttu.ee/ - [2018-09-12] Draft regulation has been prepared for allowing the face recognition robots to identify people who apply for Mobile-ID. The purpose is to enable enrollment for Mobile-ID without the need to confirm the application using the ID-card. It would be necessary to visit the PPA only if identification by robot fails.
https://news.postimees.ee/6403388/estonia-to-have-ai-identify-people - [2018-09-07] Cybernetica AS won the defense ministry’s procurement to prepare study to identify opportunities in the Estonian economy in the field of cryptography and to develop concrete proposals to enable the development of the field at national level.
http://www.ituudised.ee/uudised/2018/09/07/cybernetica-asub-uurima-kruptomajandust - [2018-09-06] Apparently Gemalto leaked to local journalists some internal presentation trying to convince the public that Gemalto informed the Estonian state about the ID card vulnerability (ROCA) already in June 15, 2017. In the response PPA concluded that Gemalto is not interested in compromise and will settle the dispute in court.
https://tehnika.postimees.ee/6277212/miljoneid-maksma-lainud-kuberuimerdamine
https://news.postimees.ee/6399999/police-to-take-gemalto-to-court-postimees
https://geenius.ee/uudis/hans-lougas-kuidas-meile-id-kaardi-kriisi-kohta-dokumendid-lekitati-ja-miks-me-neid-ei-usu/ - [2018-09-05] Märt Põder in Civic Tech Stockholm #2 explains Estonian I-voting.
https://youtu.be/nllpriKcmVY?t=2876 - [2018-09-04] Article “Key Factors in Coping with Large-scale Security Vulnerabilities in the eID Field” by Silvia Lips, Ingrid Pappel, Valentyna Tsap, Dirk Draheim. Describes few positive and negative effects of the vulnerability and key factors that helped to cope with the Estonian ID-card crisis 2017.
https://link.springer.com/chapter/10.1007%2F978-3-319-98349-3_5 - [2018-09-04] Heli Tiirmaa-Klaar has been appointed cybersecurity ambassador (Ambassador at Large for Cyber Diplomacy), being responsible for developing Estonia’s foreign policy on cyber security, ensuring its coordinated implementation, representing Estonia in international organisations and contributing to international cooperation in the field.
https://vm.ee/en/news/estonia-appoints-heli-tiirmaa-klaar-its-first-ambassador-large-cyber-security - [2018-09-01] Jaak Tarien takes over as director of NATO CCDCOE. The current director Merle Maigre will go to work for CybExer Technologies.
https://news.err.ee/853814/col-jaak-tarien-to-take-over-as-director-of-nato-ccd-coe - [2018-08-31] Significant DDoS attack by unknown actors for half an hour hit news portals owned by Express Group (Delfi, EPL, Eesti Ekspress, Õhtuleht) and PPA website.
http://forte.delfi.ee/news/digi/eesti-asutusi-ja-ettevotteid-tabasid-eile-kuberrunnakud?id=83515931
https://geenius.ee/uudis/eestit-rasib-ddos-runnakute-laine-mis-see-on-kust-see-tuleb-ja-kuidas-ennast-kaitsta/ - [2018-08-08] There are ideas for the next generation ID card to replace PIN-based cardholder verification with fingerprint verification.
https://geenius.ee/uudis/plaani-id-kaart-saab-pin-koodide-asemele-sormejalje-ning-dokumentide-saaks-iseteeninduskioskitest/ - [2018-08-06] Tele2 could not provide roaming service for its customers due to faulty software update by Comfone. The failure lasted for several hours. As a compensation Tele2 will cancel the monthly bill for the affected customers.
https://geenius.ee/uudis/tele2-tuhistab-pea-20-000-eestlasel-randlusteenuse-rikke-tottu-augusti-arved/ - [2018-07-22] Card payments and ATMs for two hours were down on Sunday due to malfunction on Nets Estonia side.
https://majandus24.postimees.ee/5904349/kaardimakseterminalid-ule-eesti-lakkasid-tootamast - [2018-07-06] Smart-ID is soon to be certified as qualified signature creation device (QSCD). This will require change from 4096-bit to 6144-bit RSA keys (providing 3072-bit RSA security).
https://github.com/SK-EID/smart-id-documentation/wiki/Smart-ID-service-will-start-to-use-6K-RSA-keys
Tag Archives: Heli Tiirmaa-Klaar
Conference “The Present and Future of Cybersecurity”
Conference “The Present and Future of Cybersecurity”
April 26, 2017, National Library of Estonia13.00-13.30 – Registration and welcome coffee
13.30-13.40 – Opening words – Urve Palo (Minister of Entrepreneurship and Information Technology)
13.40-14.00 – Keynote – Jaak Aaviksoo (Rector of TUT)
14.00-15.00 – Discussion “Evolution of cyber attacks – what has changed in ten years?” Klaid Mägi (RIA, head of CERT-EE) leader. Debating: Hillar Aarelaid (Police and Border Guard Board), Jaan Priisalu (TUT), Merike Käo (Farsight Security CTO)
15.00-15.30 – Cofee break
15.30-17.00 – Discussion “Discurses, paradigms and form of cyber policy in practice” Taimar Peterkop (Director General of RIA) leader. Debating: Sven Sakkov (Director of NATO CCD CoE), Heli Tiirmaa-Klaar (European Union, Head of Cyber Policy Coordination at European External Action Service), Lauri Lugna (Secretary General at the Ministry of Interior), Lauri Almann (Co-Founder of BHC Laboratory)
17.00-17.30 – Closing words – Toomas Vaks (RIA, Head of Cyber Security Branch)
17.30-19.30 – After conference reception. Appearance of RIA band VaRIA.
Work language of the conference is Estonian.
Tallinn International CyberCrime Conference 2014
Location: Tallinn, Estonia – Radisson Blu Hotel Olympia
On 12 and 13 november 2014 the Tallinn University of Technology organizes the International Cybercrime Conference of 2014. The main agenda of the conference is to announce the official opening of TUT Centre of Digital Forensics and Cyber Security and to discuss current cyber security research.Conference CyberCrime 2014, day 1, 12.11.2014 (most of the day in estonia – english simultaneous translation, with the exception of 2 presentations in english)
Moderator Aare Tammemäe, FinanceEstonia, Chairman of the Board
09.00 – 10.00 Registration and welcome coffee
10.00 – 10.15 Conference Opening Address: Prof Erkki Truve, Vice rector of Tallinn University of Technology
10.15 – 10.25 Mr Hanno Pevkur, Minister of the Interior, Republic of Estonia
10.25 – 11.10 Plenary Session 1
Key note speaker: Mrs Heli Tiirmaa-Klaar, Cyber Security Policy Advisor, European External Action Service.
EU Cyber Security Strategy and Capacity Building to Fight Cybercrime.
11.10 – 11.20 Mr Üllar Lanno, Estonian Forensics Science Institute.
The beginning of IT forensics in Estonia or how the 2CENTRE Estonia started
11.20 – 11.50 Coffe-break
11.50 – 12.20 Plenary Session 2
Mr Gert Jervan, Dean of Faculty of Information Technology, Tallinn University of Technology; Mrs Anu Baum, 2CENTRE Estonia; Rain Ottis, TUT Centre of Digital Forensics and Cyber Security. TUT Cyber centre – past, present and future
12.20 – 12.25 The importance of the establishment of 2CENTRE Estonia. Welcoming word by Minister of the Justice of the Republic of Estonia, Andres Anvelt
12.25 – 12.50 Signing the memorandum of association of TUT Centre of Digital Forensics and Cyber Security
12.50 – 13.30 Panel Discussion – Erkki Truve, Heli Tiirmaa-Klaar, Andres Anvelt, Priit Pärkna, moderated by Gert Jervan, Dean of IT faculty of TUT
13.30 – 14.30 Lunch
14.30 – 14.50 Ms Ann Mennens – B-CCentre (Belgium). The B-CCENTRE, establishing exchange and cooperation between academia, public and private sector in Belgium: a major challenge
14.50 – 15.10 Ms Cheryl Baker – University College Dublin (Ireland)
Success story of the university (UCD), IT-forensics in Ireland, Irish experience and challenges in the global forensics market
15.10 – 15.40 Coffe-break
15.40 – 16.00 Mr Tanel Tammet, Mr Rain Ottis, Mr Jüri Vain. Introduction of the Four Projects (e-Crime, ECESM, SEREIN, IT-Akadeemia)
16.00 – 16.30 Mr Andres Kütt – Advisor at Estonian Information System’s Authority. E-state, e-governance & e-citizen or why we need experts in digital forensics.
16.30 – 17.00 Conclusions of the Day 1
19.00 – 22.00 Reception hosted by prof Erkki Truve, Vice rector of Tallinn. University of Technology (admittance based on earlier registration). House of Brotherhood of the Blackheads
Pikk str 26, 10133 Tallinn
Phone: +372 631 3199Conference CyberCrime 2014, day 2 (all day in English), 13.11.2014
Moderator Olaf Maennel
08.45 – 09.15 Registration
09.15 – 10.00 Gorazd Božič, Slovenia
Incident Response and CERT Cooperation in the Modern Age
10.00 – 10.15 Coffee break
10.15 – 11.00 Varis Teivāns, Deputy Manager of CERT.LV
“Role of Digital Forensics in Fight Against Cybercrime in Baltic States”
11.00 – 11.15 Coffee break
11.15 – 12.00 Matthew Sorell, Australia
Beyond metadata: non-cooperative provenance tracing of digital photography
12.15 – 13.15 Lunch
13.30 – 14.15 Nickolas Falkner, University of Adelaide, Australia.
Security and Automated Configuration: Where Standards and Policy Fail, Complexity Will Not be Enough to Save Us.
14.15 – 15.00 Pavel Laptev, Estonia
Cyber Forensics view from the Estonian Forensic Science Institute
15.00 – 15.15 Coffee break
15.15 – 16.00 Gergely Toth, Deloitte Cyber Security Team
An Industry perspective on cyber security challenges
16.00 – 16.40 Olaf Maennel, Professor, Tallinn University of Technology.
Summarizing the 2’nd day of the conference
Links:
http://www.conference-expert.eu/en/cybercrime-conference-2014/162-event-programme
https://www.b-ccentre.be/12-13-november-tallinn-international-cybercrime-conference-2014/