English

The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland

Cryptography and Security 2025-07-24 v1

Abstract

This paper presents a vulnerability assessment activity that we carried out on PosteID, the implementation of the Italian Public Digital Identity System (SPID) by Poste Italiane. The activity led to the discovery of a critical privilege escalation vulnerability, which was eventually patched. The overall analysis and disclosure process represents a valuable case study for the community of ethical hackers. In this work, we present both the technical steps and the details of the disclosure process.

Keywords

Cite

@article{arxiv.2507.17007,
  title  = {The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland},
  author = {Gabriele Costa},
  journal= {arXiv preprint arXiv:2507.17007},
  year   = {2025}
}