Biometric passports 'easily cloned'

Cheap approach to security puts identity at risk

Andrew Charlesworth

The new generation of e-passport, due to be issued to US citizens from October, can be cloned easily – not good news on a day when airports on both sides of the Atlantic are on high-security alert.

German researchers at the Black Hat security conference in Las Vegas have shown how e-passports, sporting an RFID (radio frequency identification) chip containing biometric data, can be copied using a laptop, RFID reader and smartcard reader – yours for an outlay of less than $1,500.

Advertisement

Security experts say this is no great surprise: RFID tags are meant to be cheap and easy to produce.

The tags are used increasingly in logistics, attached to goods so they can be automatically identified as they move from one depot to another through the supply chain.

That makes RFID a suitable technology for tracking tins of soup in Wal-mart, but not up to the job of protecting against identity theft.

"RFID was never designed to manage personal identity details," says Stijn Bijnens, Senior Vice President, Identity Management of Cybertrust. "We have seen the activity of cyber criminals shift from hacking into internet-connected systems to identity theft. This is a real potential threat and you will see cases of fraud based on e-passport [forgery]."

The data in an RFID tag is protected by a password that can be easily cracked.

According to the security experts, the US should be following the lead of several European countries and using more robust public key infrastructure (PKI) systems which use strong encryption to scramble data.

A PKI passport would be more expensive than one with an RFID tag because it would require a chip to perform the cryptography computations required by PKI. But the price of these chips is falling as they are deployed in their millions in identity card and health card schemes in countries such as Belgium, Germany, Finland and Estonia.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

shackleton

Content management tools "barely being used"

Open Text chief predicts more consolidation in ECM market

Scott Totzke

Interview: Scott Totzke, VP global security, RIM

We ask the BlackBerry maker's head of security what CIOs...

Apple Magic Mouse

Review: Apple Magic Mouse

Multi-touch makes an appearance on Apple's latest mouse

clouds

Industry needs to come clean on cloud security

Trend Micro CTO warns of widespread data theft

Primary Navigation