Due to the widespread COVID-19 pandemic, there has been a push for `immunity passports' and even technical proposals. Although the debate about the medical and ethical problems of immunity passports has been widespread, there has been less inspection of the technical foundations of immunity passport schemes. These schemes are envisaged to be used for sharing COVID-19 test and vaccination results in general. The most prominent immunity passport schemes have involved a stack of little-known standards, such as Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) from the World Wide Web Consortium (W3C). Our analysis shows that this group of technical identity standards are based on under-specified and often non-standardized documents that have substantial security and privacy issues, due in part to the questionable use of blockchain technology. One concrete proposal for immunity passports is even susceptible to dictionary attacks. The use of `cryptography theater' in efforts like immunity passports, where cryptography is used to allay the privacy concerns of users, should be discouraged in standardization. Deployment of these W3C standards for `self-sovereign identity' in use-cases like immunity passports could just as well lead to a dangerous form identity totalitarianism.
翻译:由于广泛流行COVID-19大流行,“豁免护照”甚至技术提案一直受到推动。虽然关于豁免护照的医学和伦理问题的辩论很普遍,但是对豁免护照计划的技术基础的检查较少。这些计划设想用于分享COVID-19测试和一般的疫苗接种结果。最突出的豁免护照计划涉及一系列鲜为人知的标准,如万维网联合会(W3C)的分散识别器(DIDs)和可核实的证书(VCs)。我们的分析表明,这组技术身份标准所依据的是定义不足而且往往不标准化的文件,这些文件具有重大的安全和隐私问题,部分原因是使用阻隔式链技术令人怀疑。关于豁免护照的一项具体建议甚至容易受到字典攻击。在豁免护照等工作中使用“密码学剧场”来消除用户的隐私关切,在标准化中应当不鼓励使用这些W3C标准,在使用“自我主权身份”时,例如使用极权主义,可以作为危险身份档案。