This morning I wrote a letter to my MP to, hopefully, express the dangers surrounding the numerous “vaccine passport” systems being proposed in this, and other countries.

Discussion around these passports, in my mind, seem to miss the main danger. A cynical mind might say that this omission is deliberate, but I am going to assume good faith for now, at least until it is proved otherwise.

My letter is below:

I am writing to you to express my strongest objection to Tory plans for the introduction of a vaccine passport in the UK, something the Labour leader also opposes. 

Internal vaccine certification is something alien to this country, and with the wide uptake of the Covid vaccine, seems to me unnecessary. After all, if we are at herd immunity, what does it matter whether a particular individual is vaccinated or not? 

It is my belief that requiring us to prove our medical status to anyone who demands it from us is a massive invasion of privacy. It is also my belief that they will be divisive, with those unwilling or unable to get the vaccine being treated as “untouchables” and effectively barred from civil society.

However, fundamentally it is my belief that vaccine passports are clearly meant to be a form of coercion and control. 

Coercion because it is clearly meant to threaten those reticent to take up the vaccine with being effectively “unpersoned” unless they undergo a medical procedure, a practice outlawed in the Nuremberg code of medical ethics. 

Control, because every scan of the bar code will inform a government database of your location, who you’re with, and what you are doing. This is essentially an ID card system by the back door.

It is my firm belief that we are on a dangerous road to a very dark place. Not only are we moving to a world where we allow the state to effectively mandate citizens undergo medical procedures, but we are letting the fear of a virus take us to a world where, with widespread adoption of this system, the government could essentially place political dissidents in internal exile with the press of a button.

Imagine a world, ten years from now, where you have to prove your vaccine status for anything that requires you to come in contact with other people. The government is already talking about pubs and concert venues, but logically, why stop there? Why not shops or public transport systems as well? After all, you will be mixing with just as many, if not more people. You are obviously going to need it to leave or enter the country.

Now, imagine you have the “wrong opinions”. Perhaps you attend an environmental protest, or you write something on social media critical of the government. Any one of a million things that are perfectly reasonable in a liberal democracy, but which inconvenience those in power.

Well, will you look at that! Your vaccine passport suddenly stops working. Now that person has been removed from interacting with society, and all without any of that messy “due process” business!

This is not paranoia, or science fiction. This system exists, right now, in China, and it is called the Social Credit system. There, every citizen has an app on their phone which is scanned numerous times a day to prove, not their vaccine status, but whether they are a “good citizen” or not. Have the “wrong opinions”, or post something on social media critical of the government and look at that! Your score drops, and you are suddenly barred from participating in society. 

The proposed vaccine passport system is obviously, on the face of it, different. However, it is functionally the same mechanism as the Social Credit system. That system is the mechanism by which the Chinese government exercises totalitarian control over their citizens everyday lives and is not something that a so called “free” society should ever seek to emulate!

I therefore urge you to oppose any form of vaccine certification.

The Dear Leader has requested that we all reflect on the last year, as today marks the one year anniversary of when the country I am currently stuck in went into its first (of many) lockdowns.

One year. One fucking year.

One year of dodgy models and disingenuous press conferences.

One year of the theft of hard fought for liberties, and of ever shifting goalposts for when we will get them back.

One year of shattered lives, livelihoods and and stunted futures.

One year spent minimising non-covid deaths.

One year of our lives stolen from us.

Urgh. I could go on.

Mine is a minority view, or so it would seem. Covid is a real virus of course, but it is increasingly clear that the hardship we all face now is down to government policy, not as a direct result of the virus.

Truthfully, I am not even slightly concerned about the virus these days. Do I want it? No. Of course not. But hiding inside the house, not seeing friends and family, not travelling, not doing any one of the number of things, now verboten, which give you a reason to get up in the morning, is not a way to live your life. Especially for a virus which, while serious if you’re unlucky enough to get a bad case, is far from being airborne Ebola or the Zombie plague.

We have several highly effective vaccines now, and say what you want about the government, they have at least done that right. All the elderly and vulnerable have had their dose, and death rates are plummeting as a result. All the data indicates we should really already be almost back to normal. So, why are restrictions tightening rather than relaxing? Why are we talking about internal Covid passports, mandatory vaccinations, ongoing travel bans, and masks and social distancing until 2023 or beyond?

Whenever a minister is pressed on the question of exactly when we will get our freedoms back, they always avoid the question, dissemble or deflect. The goalposts are constantly being shifted. Whenever we reach one of their arbitrary criteria, and we see the end in sight… Lucy moves the football… and the funny thing is we all know she’s going to move the football. Each time we all go along with the lie, we try convince ourselves that she won’t, and run at that football all the same. We pretend it will all be ok.

It’ll all be ok if everyone just obeys the Rules!

“The rules are simple: they lie to us, we know they’re lying, they know we know they’re lying, but they keep lying to us, and we keep pretending to believe them.” 

Elena Gorokhova, A Mountain of Crumbs

I want my God given freedoms back, if it’s all the same to you. They were never yours to take in the first place! But, the medium is the message and the message is crystal clear.

We’re not going to get our freedoms back unless we take them back.

Sadly, if the polls are to be believed, a large swathe of the population are in favour of these restrictions, and the only thing our useless opposition leader would have done different would have been to go tougher, harder and earlier… Charlie big potatoes loves to stand behind that podium. Never mind the decimation of the working classes his party ostensibly is meant to represent, ah yes, but those class traitors in the North voted the wrong way didn’t they? This was meant to be your time, wasn’t it Keir. I guess they get what they fucking deserve, don’t they?

I can only wonder what world the supporters of all this lockdown insanity are living in. I can only imagine it’s a world where they live in a comfortable house, with a comfortable family, where they can comfortably work from home. Or a world where they can play video games all day, getting fat on a year long tax payer sponsored holiday from a job they hate. Charitably, I can only imagine that the fear pumped out in the media has warped their perception of reality, and with everyone around them reflecting their emotionalism back at them, I guess I can understand.

But am I crazy? I’m looking at all the data, and the outlook is better not worse. We have a vaccine. Covid isn’t as deadly as we thought last March. We won. Well done! Take the W, Boris, and let us get back to our lives!

But no.

It seems to me that we are held captive, not by the virus, but by fear. Held captive by emotionalism. Held captive by a “safety at all costs” government, myopically obsessed with covid (and the future public enquiry), as if it was the only thing going on and the only thing anybody ever dies from. Held captive by, frankly, a bunch of hysterical pearl clutching cowards who are afraid of the fucking flu.

Bah. I’m angry, and I’m running my mouth. My blog.

Look, it looked bad back in March 2020, I get that. I got caught up in that wave of emotionalism as well. However, as more and more data came out, the outlook kept on improving… and yet, here we are. One year on, facing increasingly authoritarian measures, not a cautious and proportional response based on a realistic assessment of the threat.

If you’re vulnerable, I get it. But we have the vaccine now, and Covid isn’t the only thing that can bump off someone who’s clinically vulnerable. Nobody wants someone to die, but unfortunately that’s just a fact of being alive and mortal. If you care about someone who’s vulnerable, I get it. We all have elderly parents and grandparents, I’ve not seen mine in over a year, and given that two of my more elderly relatives are in failing health I doubt I’ll ever see them again. Nobody is saying don’t take precautions or exercise good judgement.

But honestly, for the rest of you, I’m out of sympathy. All you fit and healthy folks virtue signalling with your mask selfies. All you Karens glaring and spitting passive aggressive venom when someone dares to walk slightly too close past them on the street. All of you who are so scared to go outside, and because of that fear, want to place restrictions on other people… except of course unless they’re delivering your Amazon packages or Waitrose tender stem broccoli.

Fuck all of you. You are all cowards. You want to limit the lives and opportunities of others because you feel scared.

Sorrynotsorry, but it’s time for you to put on your Big Boy pants, harden the fuck up, and go outside.

Going on 5 years ago, I had to do some integrations with SimpleSAMLPhp for a client. Now, in a Day Job, one of my colleagues is trying to get an integration working, and I’m amused that they find that my post is top hit when they google the error.

Anywho… what I wrote in my post wasn’t working, so I had to dig a little deeper.

Logins were working, but not from Chrome.

After digging into it a little, I found that SameSite headers were being set on the cookie, but no Secure flag.

This is Not Good, and so a lot of the more security focussed browsers will ignore these headers. You can even see this if you look at your developer tools.

Ok, so set the secure flag in your app, and job done, right?

Well. Normally, yes. But the added complexity comes from how our estate is currently configured – containers sat behind a load balancing gateway. This gateway, running haproxy, performs SSL offloading (yes, I know, NSA Smiley, but this is just temporary).

Solution

Once I figured out what was going on, the fix is quite simple. Namely, rewrite any cookies coming from the backend containers to include the secure flag.

This is fine, since none of our services are available over vanilla HTTP.

Adding the following:

rspirep ^(set-cookie:.*) \1;\ Secure

Did the trick after a restart.

Of course, previous tips still apply, you’re going to want to clear your caches etc so that the old cookie isn’t preserved, etc.

Hope this helps!