{"guid":"bcb70852-acef-5197-8b73-7e0c1728bec2","title":"Screaming into the void: All e-signatures in the world are broken!","subtitle":null,"slug":"mch2022-214-screaming-into-the-void-all-e-signatures-in-the-world-are-broken-","link":"https://program.mch2022.org/mch2022/talk/TW9ECH/","description":"E-signatures in your country are insecure.\nThey have been hacked 10 years ago.\nEveryone knew that but no one wanted to talk about it since there is no easy fix.\n\nWe decided to create a PoC and poke the government with it.\n\nThis is a story on what happened.\n\n⭐ PoCs included ⭐\n\nElectronically signed documents were a great relief to organizing our daily life during the pandemic. They have actually been helping us for many years (depending on the country).\n\nIt's been known for some time that **dynamic content + e-signatures = trouble**, but we were surprised that no one has really done anything about it.\nIn 2021 we got tired of explaining the vulnerability each partner that sends in a vulnerable asice for signing, so we created multiple practical PoC that allow you to modify content of e-signed documents post-signing.\n\nSome of these PoC work against many countries. And there is PoC for every single country.\n\n- What is the actual impact?\n- Why is no-one fixing this?\n- Can we even fix it?\n- What are we gonna do about it then?","original_language":"eng","persons":["Kirils Solovjovs"],"tags":["mch2022","214","2022","MCH2022 Curated content"],"view_count":692,"promoted":false,"date":"2022-07-23T10:20:00.000+02:00","release_date":"2022-07-24T00:00:00.000+02:00","updated_at":"2025-08-11T23:00:06.081+02:00","length":1703,"duration":1703,"thumb_url":"https://static.media.ccc.de/media/events/MCH2022/214-bcb70852-acef-5197-8b73-7e0c1728bec2.jpg","poster_url":"https://static.media.ccc.de/media/events/MCH2022/214-bcb70852-acef-5197-8b73-7e0c1728bec2_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/MCH2022/214-bcb70852-acef-5197-8b73-7e0c1728bec2.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/MCH2022/214-bcb70852-acef-5197-8b73-7e0c1728bec2.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/mch2022-214-screaming-into-the-void-all-e-signatures-in-the-world-are-broken-","url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_title":"May Contain Hackers 2022","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022","related":[],"recordings":[{"size":142,"length":1703,"mime_type":"video/webm","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2022-07-24T10:34:08.242+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/webm-hd/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/60109","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"},{"size":65,"length":1703,"mime_type":"video/webm","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2022-07-24T10:10:05.548+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/webm-sd/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/60104","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"},{"size":25,"length":1703,"mime_type":"audio/mpeg","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2022-07-24T09:58:03.865+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/mp3/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/60103","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"},{"size":17,"length":1703,"mime_type":"audio/opus","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2022-07-24T09:43:03.492+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/opus/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_opus.opus","url":"https://api.media.ccc.de/public/recordings/60100","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"},{"size":56,"length":1703,"mime_type":"video/mp4","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2022-07-24T09:42:05.097+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/h264-sd/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_sd.mp4","url":"https://api.media.ccc.de/public/recordings/60099","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"},{"size":166,"length":1703,"mime_type":"video/mp4","language":"eng","filename":"mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2022-07-24T09:31:57.448+02:00","recording_url":"https://cdn.media.ccc.de/events/MCH2022/h264-hd/mch2022-214-eng-Screaming_into_the_void_All_e-signatures_in_the_world_are_broken_hd.mp4","url":"https://api.media.ccc.de/public/recordings/60092","event_url":"https://api.media.ccc.de/public/events/bcb70852-acef-5197-8b73-7e0c1728bec2","conference_url":"https://api.media.ccc.de/public/conferences/MCH2022"}]}