All the latest UK technology news, reviews and analysis

Biometric passports 'easily cloned'

by Andrew Charlesworth

10 Aug 2006

Be the first to comment

  • Tweet this

The new generation of e-passport, due to be issued to US citizens from October, can be cloned easily – not good news on a day when airports on both sides of the Atlantic are on high-security alert.

German researchers at the Black Hat security conference in Las Vegas have shown how e-passports, sporting an RFID (radio frequency identification) chip containing biometric data, can be copied using a laptop, RFID reader and smartcard reader – yours for an outlay of less than $1,500.

Security experts say this is no great surprise: RFID tags are meant to be cheap and easy to produce.

The tags are used increasingly in logistics, attached to goods so they can be automatically identified as they move from one depot to another through the supply chain.

That makes RFID a suitable technology for tracking tins of soup in Wal-mart, but not up to the job of protecting against identity theft.

"RFID was never designed to manage personal identity details," says Stijn Bijnens, Senior Vice President, Identity Management of Cybertrust. "We have seen the activity of cyber criminals shift from hacking into internet-connected systems to identity theft. This is a real potential threat and you will see cases of fraud based on e-passport [forgery]."

The data in an RFID tag is protected by a password that can be easily cracked.

According to the security experts, the US should be following the lead of several European countries and using more robust public key infrastructure (PKI) systems which use strong encryption to scramble data.

A PKI passport would be more expensive than one with an RFID tag because it would require a chip to perform the cryptography computations required by PKI. But the price of these chips is falling as they are deployed in their millions in identity card and health card schemes in countries such as Belgium, Germany, Finland and Estonia.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

Product Manager, Open Repository (ref:BMC/PMR)

Product Manager, Open Repository (ref:BMC/PMR) End...

Java/JEE Software Developer-Dotcom/eCommerce Software House

Java/J2EE Software Developer/Programmer - Dotcom/ eCommerce...

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

To send to more than one email address, simply separate each address with a comma.