Covpass - Vaccination status App?

The certificates signatures and exchange themselves you seem to be right about:

But getting the cert in the first place requires another flow, it seems. Still unclear.

I got a first response from the RKI.
The original Version in German:

Sehr geehrte Frau , / Sehr geehrter Herr ,

vielen Dank fĆ¼r Ihre Anfrage zum Digitalen Impfnachweis.

Die CovPass-App wird unterstĆ¼tzt ab iOS-Version 12.0 und Android-Version 6.0. Um die CovPass-App vollumfƤnglich nutzen kƶnnen, benƶtigt Ihr Smartphone eine Kamera.

Die Entwicklung der Apps orientiert sich an der in der Bevƶlkerung mehrheitlich genutzten Systeme. Eine Weiterentwicklung fĆ¼r Ƥltere Versionen wird anschlieƟend geplant.

Wir hoffen, Ihnen mit diesen Informationen weitergeholfen zu haben.

Bleiben Sie gesund!

Wir empfehlen, sich an die allgemein geltenden Abstands- und Hygieneregeln (AHA+A+L-Regeln) zu halten, um das Ansteckungsrisiko generell zu minimieren: Coronavirus - infektionsschutz.de.

Freundliche GrĆ¼ĆŸe aus dem Robert Koch-Institut,
Im Auftrag
xxxxxxx yyyyyyyyy

And the same translated by Google:

Dear Madam, dear Sir ,

Thank you for your inquiry about the digital vaccination certificate.

The CovPass app is supported from iOS version 12.0 and Android version 6.0. In order to be able to use the CovPass app fully, your smartphone needs a camera.

The development of the apps is based on the systems used by the majority of the population. Further development for older versions is planned afterwards.

We hope that this information was helpful to you.

Stay healthy!

We recommend adhering to the generally applicable distance and hygiene rules (AHA + A + L rules) in order to generally minimize the risk of infection: Coronavirus - infektionsschutz.de.

Kind regards from the Robert Koch Institute,
On behalf
xxxxxxx yyyyyyyyy

A vaccination without a sticker in an official vaccination center? Incredible in Germany. You have to bring your vaccination pass with you, that is a condition. If you donā€™t have one, youā€™ll get a new one. You also have to bring a lot of explanations, a lot of paper ā€¦

My experience in Lower Saxony: If the first vaccination was made in the vaccination center, no family doctor will vaccinate you the second time. You will then automatically have the second appointment 12 weeks later in the same vaccination center. It follows a rule. Both vaccinations in the same place.

By the way, the digital covpass is completely overrated. Why does everything always have to be in the smartphone? What is so unreasonable about a paper certificate. Not cool enough? I donā€™t care, only if something like this has to be digital, then it should be done right. In any case, my paper vaccination pass cannot be hacked LOL

2 Likes

The Doctor at the vaccination center had said the sticker would only be put in the certificate booklet when the second dose had been administered. I was a bit shocked. Then, bad luck, the Astra vaccine was suspended just as the second dose (at 9 weeks, not 12) was due. It may be the chaos was more so in Berlin?

And yeah, I donā€™t want to have anything to do with the further centralization of personal Data in the EU. So no covpass for me, thanks. The borders are open down to Istria as far as I can tell?

1 Like

Itā€™s Berlin, poor but sexy :roll_eyes:

But back to the topic ā€¦

1 Like

I thought so too, but they had no new vaccination certificates in stock in the center ā€¦ (maybe because they are all traded on the black market :wink: ). Now the sticker has just landed in my old GDR vaccination card.
In addition, you get the form ā€œreserve documentation on vaccinationā€

1 Like

Our health service released this yellow pass after parliament asked for it. In a few days 50.000 booklets are ordered by citizens. They cost E7,50 each. People are aware of the fact that corona apps werenā€™t that effective in European countries and they want to have a say over their own data, so this booklet isnā€™t such a bad idea. Germany has acknowledged it too.

1 Like

In case itā€™s of interestā€¦

Here in the UK (no longer in the EU) the National Health Service (NHS) has created an app (the ā€˜NHS Appā€™) which will display a 2D barcode showing you have been vaccinated. (It requires Android >4 so it wonā€™t run on my Jolla C.) You can also download a pdf with the vaccination details and the barcode, either from the app or a browser. The intended use is travel.

The app screen and the pdf print makes clear that the identity of the bearer should be checked - using a passport or whatever.

The pdf print has an expiry date: it seems to be 21st June for everybody, or was when this was discussed on a forum a couple of weeks ago. If you have the app it will presumably display the latest barcode, but if you print the barcode then you have to remember to reprint it if itā€™s expired.

The barcode starts ā€˜HC1:ā€™ and appears to be as specified here:

Iā€™ve decoded mine and it contains (in json-ish format) my name (twice), date of birth, and details of my two vaccine doses (type, date, batch number.) It doesnā€™t appear to contain any unique identifier to me; we have an NHS Number but I donā€™t think itā€™s there - though it could be encrypted, encoded, or obfuscated.

Since I investigated my barcode the EU has launched its green certificate. Iā€™ve read that /does/ include a unique person identifier. (And one of the specs I read mentioned the NHS Number as used in the UK.)

Itā€™s possible - indeed I expect - that the format or content NHS barcode will be updated to match the EU one - if it doesnā€™t already. I think thatā€™s why it expires in a few weeks.

In the Germany I live inā€¦ :slight_smile: ā€¦
things differ. I had an old WHO vaccination document which was stamped and got the sticker at the first shot.
My wife had no vaccination document at all and instantly got a new one. No problems, no discussions.
We visited our local doctor.

1 Like

I hope the hackaz will do a good job to get a positive feedback from the survailance dictators when they scan a QR.
100% sure that all data will leak from everyone. Thatā€™s always the case when official authorities code someething.

Vaccination is a great thing, but vaccinating against corona viruses is almost as ridiculous as against influenca viruses. There is less genshifting and gendrifting in comparison, still far too much.

Sorry for OT, but this really triggers myself and is war against everything Iā€™ve learned and practiced for centuries.

6 Likes

Sorry not accepted. Why so negative? You also believe that politicians drink blood from children and that vaccination should genetically change you? This is ridiculous and can be fixed by education outside the bubbles.

I wish everyone who played down or denies Corona, a visit to each family of a dead person and 1 month 24/7 of work on a Corona emergency ward in the hospital. You have to be pretty ignorant not to want to see all of this. If everything is harmless, let ICU patients kiss you and fate will decide. Then you are my hero!

5 Likes

OMFG, NO, totally NOT!! Iā€™m not of that crazy kind, plz do not frame me, I am working on the front against Covid!
But I do not like that this pandemic is used by politicians for survailance again.
Really 4carlos, Iā€™ve treated hundreds of C patients and I know exactly what it can do, you got me totally wrong.

7 Likes

OT: It must be considered what consequences the current Covid policy has for democracy, society and freedom. We also should not forget all experiences mankind had made with surveillance systems in totalitarian states. All this access control, contact tracing and data concentration systems, once installed, will NEVER AGAIN be uninstalled.

6 Likes

OT: Nobody must install an app or get vaccinated? Tell me if Iā€™m wrong. So far, you can comfortably resist in the living room without fear of the consequences?

T:
I donā€™t see any point in installing an app if the vaccination certificate is sufficient, but there isnā€™t a conspiracy lurking around every corner. An app contradicts my understanding of data economy, but is not the topic here.

3 Likes

For those who can read french, hereā€™s an interesting article about how the situation in France: Pass sanitaire : la poudre aux yeux du pseudonymat, des donnĆ©es mĆ©dicales en clair

Iā€™ll try to summarize:

  • thereā€™s far too much data in the 2D code
  • thereā€™s no encryption for the sensitive data
  • the verification application is not open-source, and does not work in flight mode (while it is not a sufficient guarantee, the fact that this basic requirement is not even met shows how much they care for privacyā€¦)
  • it seems that the whole content of the 2D code is sent to a central server
  • the verification application relies on google services for the android version
  • there are no technical guarantees that the data wonā€™t be used for other purposes.
11 Likes

@Seven.of.nine, @apozaf, please keep it on topic. Iā€™m not interested in opinions about governments being evil or not, Iā€™m interested in getting apps on SFOS.

4 Likes

Yes, i read this article. Thanks.
At this time, from my own point of view, the best solution, in France is Sanipasse.
Always for those who read french : https://sanipasse.fr/
And also : SanipasseĀ : le dĆ©confinement libreĀ ! - LinuxFr.org
An app build on sanipasse for Sailfish OS would be the best solution, i think.

2 Likes

A ā€˜Leitz folderā€™ can not be revoked for any unspecified reason by an unknown operator at an unknown organisation.

1 Like

A Leitz folder can also be stolen.

Sorry but I do not understand youā€¦