Privacy and Security Analysis of the IATA Travel Pass Android App

Date

2022-04-13

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

The IATA Travel Pass (ITP), a global, opt-in app to receive, store, and share digital COVID-19 test certificates for flights, has a critical flaw in its registration process which allows an attacker to impersonate another user, needing only to know the user’s passport details but not possess the passport itself.

Description

Keywords

IATA Travel Pass, COVID-19, travel, security vulnerability

Citation

Pellaeon Lin. “Privacy and Security Analysis of the IATA Travel Pass Android App,” Citizen Lab Report No. 154, University of Toronto, April 2022.

DOI

ISSN

Creative Commons

Attribution-ShareAlike 4.0 International

Collections

Items in TSpace are protected by copyright, with all rights reserved, unless otherwise indicated.