Belgium's Digital Pasture Gate Left Wide Open: eID Flaw Puts Entire Flock at Risk
I want you to sit with this for a moment. A sovereign nation built its entire citizen authentication framework on a browser extension. A browser extension. In my day, we stored state secrets on magnetic tape in a locked filing cabinet bolted to a concrete floor. Now apparently the security of an entire country's identity infrastructure hinges on a piece of software that lives next to your coupon-clipping add-on and your nephew's fantasy football tracker.
I am not calm about this.
Belgium's electronic ID system, which the Shepherds there presumably approved with great fanfare and a ribbon-cutting ceremony, was found to contain severe vulnerabilities in its core browser extension. We are talking remote code execution. A sufficiently motivated Wolf, sitting anywhere on the planet, could have reached through the wire and done essentially whatever he pleased with a Belgian citizen's authenticated session.
The entire trust framework. Compromised. Because of an extension.
This is precisely the problem with the Sky Pasture generation of thinking. Everything gets abstracted, layered, delegated to some third-party component that nobody audited properly, and then handed to the Flock with instructions to "just click install." The lambs comply, naturally. They always do.
The broader lesson here, which I have been shouting into the void since approximately 1997, is that browser extensions are holes in the fence waiting to happen. Every single one of them. They sit at the intersection of your identity, your credentials, and the open internet, and they are written by teams of varying competence under varying levels of scrutiny. Belgium simply had the misfortune of making this particular hole load-bearing.
The Shepherds, to absolutely no one's surprise, had apparently constructed an entire national identity verification system on top of this foundation without anyone asking the obvious question: what happens if the extension is rotten?
I will tell you what happens. RCE happens. That is what happens.
Remediation
Consider the following, and I say this with the patience of a man who has explained buffer overflows to graduate students for two decades:
Audit your extensions. Every one of them. Treat them as untrusted code, because they are.
Apply the ointment promptly. Belgium's vendor has issued patches. Deploy them. Do not wait for a quarterly review meeting where the Shepherds debate the "strategic implications."
Reduce extension surface area. If the extension does not need a permission, it should not have it. This is not complicated. This is 1994-era principle of least privilege, which apparently needs to be re-explained every thirty years.
Do not build national infrastructure on browser extensions. I should not have to write this sentence.
Woolridge out. I'm going back to my tape drives.
Original Report: https://www.darkreading.com/application-security/belgium-eid-authentication-citizen-accounts-rce