Worrying sign of things to come...
Published: 4 August 2006 15:55 GMT
News that attendees at a US hacking conference have seen a demonstration of how to clone a digital passport has raised fresh concerns about the security of proposed new forms of ID and travel documents.
A hacker called Lukas Grunwald showed attendees at the Las Vegas Black Hat convention how to clone passports, using a German passport for his demonstration. However, standardisation across ePassports means the exploit would work on any other passport which uses RFID chip technology to store details of the individual - such as those now being issued in the UK or US - and was carried out using freely available technology.
According to security guru Bruce Schneier, Grunwald's job was made all the more easy by the publication of standards for ePassports on the website of the International Civil Aviation Organisation.
Simon Perry, VP security strategy at CA and a member of the European Network and Information Security Agency, told silicon.com that if people can crack the security on bank cards then it was inevitable, in time, they would find a way to do the same with passports.
The biggest problem, Schneier wrote on his blog, is that passports will have a shelf-life of 10 years, during which time the technology will not only become antiquated but will almost inevitably be overtaken in sophistication by the methods for cracking it.
Eyeing up ePassports?
Check out this photo story for pictures of the new look UK travel document.
Schneier wrote: "A passport has a 10-year lifetime. It's sheer folly to believe the passport security won't be hacked in that time."
The UK is currently in the process of rolling out ePassports which store biometric data about the holder on a chip.
Because CA's Perry said RFID chips can increasingly be read surreptitiously, often from distances far greater than the six inches which designers originally claimed, he suggested the security conscious might like to consider investing in a metal cigarette or cigar case large enough to hold their passport.
Doesn't say _what_ was cracked. If the informatio...
Evan M
Cloning is the real risk:
So, when you leave y...
Richard
I have just been issued with one. The photo is fuz...
Fergus
I have just been issued with one. The photo is fuz...
Fergus
Please explain what was "cracked". As far as I kn...
Johnny Mnemonic
You will be working for a blue chip company who require a strong VB.net, VBA Developer to come into the business and help design and build a database ...
Design & Produce Visual Elements for the Web-Store such as Home Pages, Meet Daily & Weekly Deadlines for the Upload of new Web-Store Creative. ...
If you have any app's that are published on the App Store then that would also be very useful. The project is to develop a prototype iPhone App for a ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath
Let's shine a light into the public sector IT money pit
With £16bn being spent, why is productivity still falling?
Tim Ferguson
BBC is taking tech seriously, so give it a break!
Auntie is the envy of the world but doesn't get the credit it deserves at home...
Peter Cochrane
Peter Cochrane's Blog: Open info for all?
Government stonewalling citizens
Nick Heath
Home Office CIO on taming tech and why ID cards are good news
Interview: Annette Vernon, Home Office CIO
Nick Heath
NHS records, Google and Microsoft: Where do you want your data?
Politicians: Heal thyself
Alan Hunt
NHS network: Time to get secure
Patient data in need of a check up