Re: [saag] Interest COVID-19 'passport' standardization?

Dirk-Willem van Gulik <dirkx@webweaving.org> Mon, 02 August 2021 13:51 UTC

Return-Path: <dirkx@webweaving.org>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C2D153A1F23 for <saag@ietfa.amsl.com>; Mon, 2 Aug 2021 06:51:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M5Tdrx_8Fafs for <saag@ietfa.amsl.com>; Mon, 2 Aug 2021 06:51:16 -0700 (PDT)
Received: from weser.webweaving.org (weser.webweaving.org [148.251.234.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E72DF3A1F50 for <saag@ietf.org>; Mon, 2 Aug 2021 06:51:14 -0700 (PDT)
Received: from smtpclient.apple (77-63-104-22.mobile.kpn.net [77.63.104.22]) (authenticated bits=0) by weser.webweaving.org (8.16.1/8.16.1) with ESMTPSA id 172Dmad8098982 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 2 Aug 2021 15:48:38 +0200 (CEST) (envelope-from dirkx@webweaving.org)
X-Authentication-Warning: weser.webweaving.org: Host 77-63-104-22.mobile.kpn.net [77.63.104.22] claimed to be smtpclient.apple
From: Dirk-Willem van Gulik <dirkx@webweaving.org>
Message-Id: <8C67B77C-A2EB-4203-8713-E10CF8A12EEA@webweaving.org>
Content-Type: multipart/alternative; boundary="Apple-Mail=_7E3CDA8E-AF86-4175-B13F-6C8133019542"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.100.0.2.22\))
Date: Mon, 2 Aug 2021 15:47:33 +0200
In-Reply-To: <360C07DB-2B3A-4CDF-9747-31D2FCBABFC4@tzi.org>
Cc: Henry Story <henry.story@gmail.com>, IETF SAAG <saag@ietf.org>
To: Carsten Bormann <cabo@tzi.org>
References: <CAE1ny+4QdmSJS-spV6Do5yDs1x3iAwyHdSx=Oa+cRXU+ESZ2nA@mail.gmail.com> <CADPMZDBu2cbtWk7Y4YMKXOWXQoKsBkAD9D1AuC_Rp+9xHawX7w@mail.gmail.com> <E0FDB1EE-256D-4925-9EE7-49DE212BFF02@gmail.com> <360C07DB-2B3A-4CDF-9747-31D2FCBABFC4@tzi.org>
X-Mailer: Apple Mail (2.3654.100.0.2.22)
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.6.2 (weser.webweaving.org [148.251.234.232]); Mon, 02 Aug 2021 15:48:39 +0200 (CEST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/FUc0ynjeAGZH8p9taADxhBBfbYo>
Subject: Re: [saag] Interest COVID-19 'passport' standardization?
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Aug 2021 13:51:22 -0000

On 2 Aug 2021, at 15:26, Carsten Bormann <cabo@tzi.org> wrote:
> On 2021-08-02, at 13:41, Henry Story <henry.story@gmail.com> wrote:
>> 
>> In the end we are all going to get it: vaccines rollouts are indeed aiming 
>> at doing just that. So that is why I would not be that worried about privacy 
>> with such Credentials. 
> 
> I’m not sure that I understand what you are saying.
> 
> Clearly, the DGC is a privacy disaster: To enable checking that it actually pertains to me, I need to present some government ID, which reveals my wallet name (and often much more information).

You may need to present (there are very sharp limits at what checks can be done within the area that the Regulation applies - routine/systematic checks is not in the cards). Secondly - the Regulation goes beyond the GDPR - storing/transferring the information is not permitted (even though one could image a proportional need/gool allowing such).

So the check is literally one for the eyeballs (only) of the person doing it.

With kid regards,

Dw.