DEF CON — A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium.
Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures.
James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission.
According to Arnott, a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups. Because the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, users had no way to verify whether a prompt was legitimate or a phishing attempt.









