Hacker News new | ask | show | jobs
by namibj 235 days ago
German id cards essentially record the newest issuance timestamp seen; then they block certificates that expired prior to this recorded value.
1 comments

So one erroneously issued certificate can brick every ID card in the country?
Pretty much. But you would need, first, to issue a valid certificate with a timestamp far ahead in the future. And then expose every ID card in the country to it.