BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: 8 Out of 10 Banks in Belgium HATE This One Weird eID
  RCE\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: 
 Friday\, Aug 7\, 14:00 - 14:59 PDT\n   Where: LVCCW Level 1 Hall 3 903 (Ma
 in Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   A major signing e
 xtension which has over 2 million users\, primarily in\n   Belgium\, and l
 ets websites interact with electronic ID (eID) and\n   Maestro payment car
 ds. It's used by "8 of the 10 largest banks in\n   Belgium and 60+ Belgian
  government agencies and departments"\, and it\n   facilitates eIDAS signa
 tures\, a cryptographically "secure" signature\n   format trusted by gover
 nments and organizations.\n\n   The company behind it\, is a Qualified Tru
 st Service Provider on the EU\n   eIDAS Trusted List\, the highest trust t
 ier the regulation defines.\n\n   We found multiple major issues with this
  system. Any site a user\n   visited could read their eID and Maestro card
  data\, and recover their\n   eID PIN\, which the binary handed back to th
 e page inside a token that\n   carried both the ciphertext and the key to 
 decrypt it. And\, worst of\n   all\, any site could trigger a drive-by RCE
  by getting the native\n   binary to load and run an attacker-supplied lib
 rary. All the user\n   would see is a file download\, like a PDF\, when th
 ey are getting RCE'd.\n\n   We'll show how they messed literally everythin
 g possible\, and more!\n\n   https://chromewebstore.google.com/detail/conn
 ective-signing-extens/kclpjmhngbacampgcdojmiedamjbgjjm\n   https://web.arc
 hive.org/web/20260427143606/https://www.gonitro.com/about/press/nitro-to-a
 cquire-european-esign-leader-connective\n   https://web.archive.org/web/20
 260226092908/https://www.gonitro.com/resources/nitro-to-acquire-connective
 \n\n   SpeakerBio:  James "Acorn221" Arnott\, Bay Area Labs\n\n   I'm Jame
 s\, founder of Am I Being Pwned (amibeingpwned.com)\, where we\n   hunt ma
 licious and vulnerable browser extensions. I've spent 10+ years\n   buildi
 ng and breaking them\, including LighterFuel\, a Tinder extension\n   that
  hit 10k+ weekly users and\, for one glorious day\, made me\n   (probably)
  the most-liked man on Tinder.\n\n   Recent finds include five drive-by CV
 SS 9.6 RCEs in production\n   software affecting 10M+ users. I've also pub
 lished in IEEE Xplore on\n   Rubik's cube-based FIDO2 authentication (Cube
 Authn)\, because someone\n   had to. Before this I was a founding engineer
  at three YC startups.\n\n   Fun fact: I was almost kicked out of school t
 hree times for finding\n   and exploiting vulnerabilities.\n\n   '\n\n   1
 . #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T215900Z
DTSTART:20260807T210000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:8 Out of 10 Banks in Belgium HATE This One Weird eID RCE
END:VEVENT
END:VCALENDAR
