What Expert Says on Vaccine Passport Security

Please see security expert comments below on vaccine passport security.

Experts Comments

September 12, 2021
Rick McElroy
Principal Cybersecurity Strategist
Distributed

What security risks should governments keep in mind when progressing vaccine passports initiatives?

There are a number of short-term risks that should be kept in mind along with some longer-term ones. Short term, the security of the applications being developed to support this effort needs to be built by design and not thought of after the application is released. Misuse cases (common attack vectors and tactics) need to be tested upfront and the application should be remediated as a result.

.....Read More

What security risks should governments keep in mind when progressing vaccine passports initiatives?

There are a number of short-term risks that should be kept in mind along with some longer-term ones. Short term, the security of the applications being developed to support this effort needs to be built by design and not thought of after the application is released. Misuse cases (common attack vectors and tactics) need to be tested upfront and the application should be remediated as a result. Attackers have shown time and time again that they care about this data for multiple reasons and any application vulnerabilities will be used by them to access this data. Secondarily, you have the exchange of all of this data through various governments and third parties. This exchange and verification of data become crucial in any consideration of risk for digital vaccine passports.

What can cybercriminals do with stolen vaccine passport data?

This type of system makes it a big target for phishing as a vector to lure people into clicking or downloading an app that may or may not be malicious. Attackers have and will continue to set up fake apps and websites that seem legit and trick users into giving them all kinds of information. Secondarily, this presents a present and future risk to the privacy of health data. Organizations, individuals, and governments need to consider where the line for personal health information and the free exchange thereof stops.

What security features should vaccine passports have?

Interestingly enough, no formal standards for this type of technology have been defined. Best security practices and following a HIPAA (US-based standard) model would be needed to ensure the privacy and security of the data.

 

  Read Less

Submit Your Expert Comments

What do you think of the topic? Do you agree with expert(s) or share your expert opinion below.
Be part of our growing Information Security Expert Community (1000+), please register here.

Write Your Expert Comments *
Your Registered Email *
Notification Email (If different from your registered email)
* By using this form you agree with the storage and handling of your data by this web site.