Back
Original version

The daughter of the State Special Communications Service refuses to examine the certificate for a key that contains Ryaboshapka’s name and a fake tax ID

Automatically translated version. May contain inaccuracies compared to the original.

The state enterprise “Ukrainian Special Systems,” which likely issued a real electronic key to an unknown person in the name of Ruslan Ryaboshapka, did not conduct an examination of the enhanced certificate for that key either in response to a parliamentary inquiry or after journalists’ requests.

The state enterprise “Ukrainian Special Systems,” which likely issued a real electronic key to an unknown person in the name of Ruslan Ryaboshapka, did not conduct an examination of the enhanced certificate for that key either in response to a parliamentary inquiry or after journalists’ requests. This is reported in Alisa Yurchenko’s segment for the program Our Money with Denys Bihus.

The following facts point to the involvement of the SE Ukrainian Special Systems (USS) in the unlawful issuance of an official electronic key used to publish a fake declaration of a member of the National Agency on Corruption Prevention (NACP), Ruslan Ryaboshapka.

An internal inspection by the NACP established that there was no hack of the e-declaration system; they accessed it using a valid electronic key, and the electronic digital signature file on the declaration “contains a hyperlink to the address of the accredited key certification center of the SE ‘USS’.”

After the press conference, programmers downloaded from the SE ‘USS’ website an enhanced public key certificate that contains the same personal data entered into Ryaboshapka’s fake declaration (his initials and tax ID 1234567892).

The SE carried out several manipulations, apparently trying to hide traces of this certificate’s existence. First, the key certificate disappeared from the SE ‘USS’ website, and its number appeared on the official list of revoked keys. Shortly thereafter, that number, along with a number of other keys with similar numbers, also disappeared from the list of revoked keys on the USS website. But programmers had already downloaded that list as well.

Both the certificate itself and the lists of revoked keys are documents that contain an electronic digital signature, so they can be verified at any time. The SE ‘USS’ even provides an official service “Verification of the validity of an electronic digital signature on documents submitted electronically to the CSC at the request of persons who are not CSC clients.”

Journalists from Our Money contacted the USS CSC to verify the certificate and the list of revoked keys published by the programmers. However, the SE ‘USS’ informed them that it could not accept the documents for verification for two reasons: 1) at that very moment, tariffs for the service were under review. 2) the SE doubted that providing such a service complied with the current regulatory framework.

In addition, the journalists personally handed the file with the certificate and a public information request to USS director Taras Oliynyk. After the segment aired, a response was received from the SE ‘USS’.

The journalists asked Taras Oliynyk to state whether the USS CSC had issued or recognized as invalid the specific public key certificate of the electronic digital signature (registration number: 425D4BC6E44FFB1004000000E20E000026190000), attaching it electronically to the information request.

In response, the state enterprise said it had checked only the full name of the owner listed in the certificate and found that Ryaboshapka R. H. had not been issued electronic digital signature services. This is a manipulation, because the key itself was not examined. The likely crime is precisely that a key in the name of Ryaboshapka R. H. was issued to another person so that deputies Anton Herashchenko and Ivan Vynnyk could hold a press conference about a “hack” of the e-declaration system.

The SE gave a similar response to a parliamentary inquiry from People’s Deputy Pavlo Kostenko. Instead of conducting an examination of the key (which would have confirmed the very fact of generating a key certificate in the name of Ryaboshapka R. H.), as the deputy requested to be done in his presence, the SE ‘USS’ sent a letter stating that the key had not been issued to Ryaboshapka R. H.

Open video on the platform
Open the news PDF proof

Document: PDF proof of the original version of the news item "Донька Держспецзв’язку відмовляється провести експертизу сертифіката на ключ, який містить ім’я Рябошапки та фейковий ІПН". It records the publication content at the moment of the first scan, the preservation date and the source: Bihus.Info.

Document: PDF proof of the original version of the news item "Донька Держспецзв’язку відмовляється провести експертизу сертифіката на ключ, який містить ім’я Рябошапки та фейковий ІПН". It records the publication content at the moment of the first scan, the preservation date and the source: Bihus.Info.

Держпідприємство «Українські спеціальні системи», яке, ймовірно, видало невідомій особі справжній електронний ключ на ім’я Руслана Рябошапки, не провело експертизу посиленого сертифікату цього ключа ані на депутатський запит, ані після звернення журналістів.

Держпідприємство «Українські спеціальні системи», яке, ймовірно, видало невідомій особі справжній електронний ключ на ім’я Руслана Рябошапки, не провело експертизу посиленого сертифікату цього ключа ані на депутатський запит, ані після звернення журналістів. Про це йдеться в сюжеті Аліси Юрченко для програми «Наші гроші з Денисом Бігусом».

На причетність ДП Українські спеціальні системи» («УСС») до незаконної видачі офіційного електроного ключа для публікації фейкової декларації члена Нацагентства з питань запобігання корупції (НАЗК) Руслана Рябошапки вказують такі факти.

Внутрішня перевірка НАЗК встановила, що зламу системи е-декларування не було, до неї увійшли за допомогою дійсного електронного ключа, а файл електронного цифрового підпису на декларації «містить гіпер-посилання на адресу акредитованого центру сертифікації ключів ДП «УСС».

Після прес-конференції програмісти завантажили з сайту ДП «УСС» посилений сертифікат відкритого ключа, який містить ті ж персональні дані, що вносили в несправжню декларацію Рябошапки (його ініціали та ІПН 1234567892).

ДП здійснило кілька маніпуляцій, очевидно, намагаючись приховати сліди існування цього сертифікату. Спершу сертифікат ключа зник з сайту ДП «УСС», а його номер з’явився в офіційному переліку відкликаних ключів. Невдовзі цей номер разом з низкою інших, схожих за номерами, ключів зник і з переліку відкликаних на сайті УСС. Але цей перелік також встигли завантажити програмісти.

І сам сертифікат, і списки відкликаних – це документи, які містять в собі електронний цифровий підпис, тож вони можуть бути перевірені в будь-який момент. ДП «УСС» навіть надає офіційну послугу «Підтвердження дійсності електронного цифрового підпису на документах, що надані в електронній формі до ЦСК за зверненням осіб, які не є Клієнтами ЦСК».

Журналісти програми «Наші гроші» звернулися до ЦСК ДП «УСС» для перевірки сертифікату і списку відкликаних ключів, опублікованих програмістами. Однак в ДП «УСС» повідомили, що не можуть прийняти документи на перевірку з двох причин: 1) саме в цей момент триває перегляд тарифів на послугу. 2) у ДП засумнівалися, що надання такої послуги відповідає чинній нормативній базі.

Крім того, журналісти передали файл з сертифікатом та запит на публічну інформацію особисто директору «УСС» Тарасу Олійнику. Вже після виходу сюжету в ефір від ДП «УСС» надійшла відповідь.

Журналісти просили Тараса Олійника повідомити, чи видавав та чи визнавав недійсним АЦСК ДП «УСС» конкретний сертифікат відкритого ключа електронного цифрового підпису (реєстраційний номер: 425D4BC6E44FFB1004000000E20E000026190000), додавши його в електронному вигляді до запиту на інформацію.

На це питання держпідприємство повідомило, що перевірило лише ПІБ власника, зазначеного в сертифікаті, та з’ясувало, що Рябошапці Р. Г. послуг електронного цифрового підпису не видавало. Це маніпуляція, оскільки перевірку самого ключа не зроблено. А імовірний злочин полягає саме в тому, що ключ на ім’я Рябошапки Р.Г. був виданий іншій особі, аби депутати Антон Геращенко та Іван Вінник провели прес-конференцію про «злам» системи електронного декларування.

Аналогічну відповідь ДП надало на депутатське звернення народного депутата Павла Костенка. Замість експертизи ключа, (яка би засвідчила сам факт формування сертифікату ключа на ім’я Рябошапки Р.Г.), яку нардеп просив провести в його присутності, ДП «УСС» надіслало листа про те, що ключ не видавався Рябошапці Р. Г.

Open video on the platform
Open the news PDF proof

Document: PDF proof of the original version of the news item "Донька Держспецзв’язку відмовляється провести експертизу сертифіката на ключ, який містить ім’я Рябошапки та фейковий ІПН". It records the publication content at the moment of the first scan, the preservation date and the source: Bihus.Info.

Document: PDF proof of the original version of the news item "Донька Держспецзв’язку відмовляється провести експертизу сертифіката на ключ, який містить ім’я Рябошапки та фейковий ІПН". It records the publication content at the moment of the first scan, the preservation date and the source: Bihus.Info.

Download Download PDF