← all papers · overview

The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland

Abstract

This paper presents a vulnerability assessment activity that we carried out on PosteID, the implementation of the Italian Public Digital Identity System (SPID) by Poste Italiane. The activity led to the discovery of a critical privilege escalation vulnerability, which was eventually patched. The overall analysis and disclosure process represents a valuable case study for the community of ethical hackers. In this work, we present both the technical steps and the details of the disclosure process.

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).