“The failings are dramatic”: Further security flaws leave Australia’s vaccination certificates open to forgery

“The failings are dramatic”: Further security flaws leave Australia’s vaccination certificates open to forgery

Another tech-savvy Aussie has pointed out how easy it is to forge the government’s COVID-19 vaccination certificates, which could be a huge problem for domestic, and, potentially international travel.

Melbourne-based software developer Finn Bailey told ABC News the government was using “high-school grade” security to protect the document from being copied or altered.

He said the failings are “dramatic” to anyone who is fairly qualified in this field, and that the name and vaccination status on the certificate can both be altered using a well-known technique.

“One could argue that this means these [documents] are not certificates, in that they fail to meet the definition of being certified as authentic,” Bailey said.

“You can make it say whatever you want.”

Last month, a Sydney-based software engineer Richard Nelson posted to Twitter about an “obvious” security flaw that made it possible to forge the vaccine certificates in just 10 minutes using free software including anti-forgery animation used in the background.

Nelson notified the government with details about flaw, but ABC News reported that he had still not heard back as of this morning.

On Wednesday, Tourism Minister Dan Tehan said the government would have a “vaccine passport”, which Australians could use to travel overseas, up and running in the coming weeks.

The certification scheme will be separate from the certificates currently available to Australians through the Express Plus Medicare app.

Tehan said the government was developing a QR code with the International Civil Aviation Organisation that would allow the new certificates to be recognised across the globe.

Australians will be able to use the easily-forged certificates to access greater freedoms in locked-down areas of New South Wales next week, including more time outdoors, with more privileges expected to be added as the vaccination rate grows.

According to ABC News, the NSW government will trial its own “vaccine passport” on the Services NSW app which the state currently uses to check in to venues.

It is now known whether the app will be similar to the Medicare version or feature a QR code like the federal government plans to use for international travel.

A Services NSW spokesperson told ABC News that the vaccination certificate and check-ins would have “a number of security features which can be validated to help reduce risk of fraud”.

Forging proof of vaccination appears to be on the rise overseas, with a 24-year old woman facing charges for using a forged COVID-19 certificate to skip quarantine requirements while travelling to Hawaii.

And she may have gotten away with it if she hadn’t misspelt the name of the vaccine she claimed to have received.

Reuters has reported a booming market for fake vaccine certificates has cropped up online, with the head of a cyber intelligence firm telling the news outlet he has seen “hundreds” of websites on the dark web selling the forgeries for as little as $12.

Latest News

  • Aviation

Low-cost Indian carrier SpiceJet continues to burn cash

It’s not just low-cost Australian carriers that are facing hardship. SpiceJet, India’s version of Bonza, recently announced a 72 per cent reduction in its net loss versus last year. But, despite this improvement, the airline has posted losses for six straight years. But it has secured board approval to raise up to INR 30 billion […]

  • Attractions

SAKA Museum recognised in TIME magazine’s World’s Greatest Places 2024

AYANA Resort Bali’s newly-opened cultural and events centre, SAKA Museum has been recognised in TIME magazine’s World’s Greatest Places list for 2024. Part of AYANA Bali’s resort destination, the museum integrates Bali’s rich history with state-of-the-art facilities, making it the centrepiece for the island’s spiritual and cultural heritage. TIME magazine’s inclusion of SAKA Museum in […]

  • Cruise

Silversea taps Barbara Biffi as senior vice president for global sales

Ultra-luxury and expedition cruise travel brand, Silverseas, has announced Barbara Biffi as its new senior vice president of global sales. Biffi joined the company in 2007, holding numerous positions and gaining a deep understanding of the brand, the preferences of its guests and its strategic goals, the company said. An Italian national with a wealth […]

  • Technology
  • Travel Agents

Amadeus welcomes FCM Travel as new reseller partner of Cytric Easy

Cytric Easy, the travel management tool embedded in Microsoft Teams, is to be integrated into FCM Travel portfolio. Amadeus and FCM Travel have extended their Cytric distribution agreement to include Cytric Easy. With this new agreement, global travel management company FCM Travel, becomes a reseller of the innovative travel management collaboration solution embedded into Microsoft […]