Security risks of e-passports exposed

NEWS

Radio tags used in everything from building access cards to highway toll cards to passports are surprisingly easy to copy and pose a grave security risk, researchers said this week.

At security conferences researchers demonstrated that passports equipped with radio frequency identification (RFID) tags can be cloned with a laptop equipped with a $200 RFID reader and a similarly inexpensive smart card writer. In addition, they suggested that RFID tags embedded in travel documents could identify US passports from a distance, possibly letting terrorists use them as a trigger for explosives.

At the Black Hat conference, Lukas Grunwald, a researcher with DN-Systems in Hildesheim, Germany, demonstrated that he could copy data stored in an RFID tag from his passport and write the data to a smart card equipped with an RFID chip. The copied chip could be used in a forged passport, for example. "We programmed the chip to behave like a passport," Grunwald said in an interview on Friday.

The threat of unauthorised duplication could affect millions of Americans who are scheduled to begin receiving RFID passports in October. It also calls into question assertions by government officials — who have defended implanting RFID tags in passports despite privacy worries — that the new passports will be more difficult to forge.

Grunwald did say that he has not unearthed any flaws in the crypto that protect the integrity of the information stored in the chips in passports. In other words, while the data can be cloned merely by scanning the RFID tag, the information cannot be changed. Grunwald was able to read the data on the chip by duplicating a customs inspection station.

It took Grunwald "two weeks and $5,000 in legal fees" to complete his project, which uses RFID reading hardware and some homegrown software, he said. At Defcon on Friday, Grunwald also tested his setup with some corporate access cards, which he was also able to copy. This means an attacker could copy access cards and use the copies to open doors to secured buildings.

"You can add RFID in a secure way, but especially in electronic passports the standards are created by compromise, and by compromise you can not do it securely," Grunwald said. "You need a lot of research to do it right, and that research is not done right now." Grunwald is in the process of establishing a company focused on RFID security, he noted.

Around the world, governments are adding RFID tags to passports as a way to fight counterfeiting. Several European countries already issue passports with RFID tags. Privacy advocates and some security experts have warned about possible threats of moving to electronic passports.

Data leakage is one of those dangers. By design, RFID tags can be read by readers. In their current design, a slightly opened passport would be detectable, said Kevin Mahaffey, a researcher with wireless security company Flexilis. Although the actual data on the chip can't be read, "the simple ability for an attacker to know that someone is carrying a passport is a dangerous security breach", he said.

It may be possible to determine the nationality of a passport holder by "fingerprinting" the characteristics of the RFID chip, Mahaffey said. "Taken to an extreme, this could make it possible to craft explosives that detonate only when someone from the US is nearby," he said. At Black Hat, Mahaffey showed a video that simulates just that.

Flexilis suggests a dual cover shield and a specifically designed RFID tag that will make it unreadable until the passport is fully opened. Grunwald, aware of the leakage danger, carries his passport in a pouch made of aluminium foil and noted that companies in Germany already sell specially made passport pouches to prevent the radio tag from being read.

Alternatively, Grunwald said, due to some problems with the RFID tag in the German passport, the Government decided that the passport will still be valid, even with an inoperative RFID tag. The Chaos Computer Club, a German hacker club, came up with a creative solution, Grunwald said.

"The CCC is recommending to just microwave your passport," he said.

Talkback

The British Govenrment will make "owning such equipment for cloning purposes" a crime and thus will protect UK passports (and citizens) from being exploited in this way.

The sad thing about the above joke is that they are probably already on the case.

7 August, 2006 13:44 Reply

'... possibly letting terrorists' - who are they? Those who oppose the U.S.A. and its confederates - the true, the pure, and the good, the U.S., Israel, and the EU? But how could anyone be opposed to such friends of humanity? The villians!

7 August, 2006 22:26 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

ZDNet UK Live

Jack Schofield

@apexwm >> "They can save maybe up to 1% of their IT costs" > I'd like to know how you propose this number? MS Office costs hundreds > per copy,...

1 minute ago by Jack Schofield on Late starters to Windows 7 migration may find it more costly, says Gartner
Jack Schofield

@apexwm > I would be curious to know what exactly they mean by "mini-notebooks are > less-than-perfect substitutes for standard low-end laptops"....

26 minutes ago by Jack Schofield on While PC shipments will grow to a million per day, netbooks are in decline
superglaze

Digital Britain author attacks the government for delaying the 2Mbps universal service commitment http://bit.ly/ciAS2s

LarsTS

Researchers at Norwegian and German institutes claim to have successfully cracked quantum cryptography equipment http://bit.ly/bfQQRt

benrothke

Quantum crypto detectors cracked by researchers http://tinyurl.com/32orrr8 @schneierblog - your thoughts?

dominic_victor

Suse Linux Enterprise Server for VMware ships: By Jack Clark, ZDNet UK, 2 September, 2010 17:11 VMware and Novell ... http://bit.ly/bL9BMy

Bhackett10

RT @ZDNetUK_News: Dell abandons battle to buy 3Par: HP has won the short, sharp race to add the data storage management company to i... http://bit.ly/aLg1tA

ZDNetUK_News

Suse Linux Enterprise Server for VMware ships: Businesses that buy vSphere licences will get SLES free of charge, ... http://bit.ly/adlav5

superglaze

Dell abandons battle to buy 3Par http://bit.ly/920Spv

qbspchelp

RT @ZDNetUK_News: iOS 4.2 available for iPad in November: The operating system update will allow wireless printing and audio and vid... http://bit.ly/azstPx

superglaze

@gruber @daringfireball It's here, but will it get used? Universal wireless charger standard gets public release http://bit.ly/doJO2u

ZDNetUK_News

Universal wireless charger standard gets public release http://bit.ly/cCdlZv

IP_v6

#IPv6 repost RT @pixeladdikt: RT @RIPE_NCC: ~"IPv6 news: using #IPv6 to connect everything http://bit.ly/dtJvh3 " ... http://bit.ly/aRkCNT

paulallen77

Windows Phone 7 released to manufacturers http://bit.ly/addml7

ImGoneBuzzirk

Windows Phone 7 released to manufacturers http://bit.ly/b9oigT

trejrco

RT @pixeladdikt: RT @RIPE_NCC: ~"IPv6 news: using #IPv6 to connect everything http://bit.ly/dtJvh3 " +ArchRock :)

Droid_Phone

Carter attacks coalition over 2Mbps delay http://bit.ly/aPTmax | #Droid #Android

Droid_Phone

Windows Phone 7 released to manufacturers http://bit.ly/9rL0sc | #Droid #Android

First Take

Tony - on the 28th, Hotmail EAS on iPhone didn't work because it wasn't publicly available then. Ignore the email, which was part of the internal...

6 hours ago by First Take on Hotmail Exchange ActiveSync
BrenoVale

RT @RIPE_NCC: Exciting IPv6 news: using #IPv6 to connect everything from people's homes to the smart grid http://bit.ly/dtJvh3 (by @mlamonica)

Featured white papers

The benefits of email archiving

Email archiving lowers the risk of being unable to find important documents and help in achieving regulatory compliance and answering litigation requests.

Download now

Cloud Computing - What does it really mean?

Technology transforming business - The term cloud is used as a metaphor for the Internet, based on how theInternet is depicted..

Download now

Out-of-box Comparison Between Dell, HP and IBM blade servers

This compelling paper by Principled Technologies compares out-of-box experiences on Dell PowerEdge M600 Blade System, HP BladeSystem..

Download now