The unveiling of the Quebec government’s mobile applications for storing and verifying vaccination passports (VaxiCode and VaxiCode Verif) caused a lot of ink to flow last week.
The flaw is that once a public key is downloaded, it can be used to validate any other passport without being checked to see if the content of the issuer field matches.