Privacy and Security Analysis of the IATA Travel Pass Android App
Date
2022-04-13
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
The IATA Travel Pass (ITP), a global, opt-in app to receive, store, and share digital COVID-19 test certificates for flights, has a critical flaw in its registration process which allows an attacker to impersonate another user, needing only to know the user’s passport details but not possess the passport itself.
Description
Keywords
IATA Travel Pass, COVID-19, travel, security vulnerability
Citation
Pellaeon Lin. “Privacy and Security Analysis of the IATA Travel Pass Android App,” Citizen
Lab Report No. 154, University of Toronto, April 2022.
DOI
ISSN
Creative Commons
Attribution-ShareAlike 4.0 International
Creative Commons URI
Collections
Items in TSpace are protected by copyright, with all rights reserved, unless otherwise indicated.