Researcher details Dutch e-passport hack

Topics

Hack, E-passport

NEWS

The researcher who claims to have created code that can emulate and clone e-passports has given details of the purported hack.

The anonymous hacker, who prefers to be known by the handle 'vonJeek', told ZDNet.co.uk that the cloned chip works by bypassing electronic security checks.

"If we're talking about bypassing, I mean manipulating the system in such a way that the intended process is not (fully) performed," wrote vonJeek in an email exchange.

The researcher explained that e-passport systems use a mechanism called 'passive authentication' to detect unauthorised changes of data on the chip. A document security object, or 'SOD', is stored in the chip, which contains between two and 16 mathematical values (check values), used to check whether the passport data has been altered. The collection of values is signed using a digital signature. The signature and the public key of the signer, used to check if the signature is correct, are also in the SOD file.

To check if e-passport content has not been altered, the e-passport system reads the index to see which files are stored on the chip, then reads the indexed files. It calculates the check value of each file, and verifies whether the check values match those in the SOD file. The system checks if the digital signature in the SOD has been signed using the public key in the SOD, and whether the public key is owned by a bona fide country. To do this, an International Civil Aviation Organization (ICAO) service called the Public Key Directory (PKD) can be used.

A country can also decide to use an additional security mechanism called 'active authentication', which is used by the Dutch e-passport system, to check whether the chip data has been altered or cloned.

VonJeek claimed the emulator program worked by exploiting a vulnerability in how the e-passport system initially reads the index to see which files are stored on the chip. Using this vulnerability bypasses active authentication, along with any additional services such as fingerprints or other biometric checks. The researcher claimed to have tested his emulator against each of the steps of the e-passport authentication process, verifying if the equipment reported any problems. VonJeek stressed that a video of the passport reader being fooled into accepting data authenticating Elvis Presley showed only a self-scan machine, which did not properly implement all the checking processes.

However, the researcher claimed the emulator could fool any e-passport system, including that used in the UK, if the system followed ICAO guidelines without modification. According to vonJeek, using th emulator, passport clones could be used on the UK system, as the UK does not use active authentication. VonJeek had not tested an e-passport with altered data on a UK system, and could not comment on the full UK authentication process.

At present, the code only works with blank JCOP v4.1 72k smartcards, manufactured by various smartcard suppliers including NXP. VonJeek said the code could possibly be modified to work on JCOP v3.1 cards, another type of e-passport system.

The researcher added that, at present, only nine countries were signed up to the ICAO's PKD, with only five active users, and that other countries had to exchange public keys via secure diplomatic post. This adds complexity and lowers the efficacy of the system, as each of the 45 participating countries have to recognise each other's keys. The UK does not currently participate in the ICAO's PKD.

The security of the system is further flawed by RFID tags not having to be in close proximity to the readers, according to a commentator on The Hacker's Choice website called 'The Ministry of Truth'.

"Thanks to the e-passports it is now possible to build smart-[improvised explosive devices, or IEDs]," wrote the commentator. "A smart-IED waits until a specific person passes by before detonating, or let's say until there are more than 10 Americans in the room. Boom."

Being able to read e-passports from a distance also opens up the possibility of a hacker reading a passport remotely and then using a person's credentials to authenticate himself, wrote the commentator.

The Home Office denied that e-passports would make identity authentication less secure.

"Continuing investment in biometric technology and enhanced security measures will help ensure that passport security is maintained now and in the future," said a Home Office spokesperson. "We take security and privacy very seriously, which is why the British biometric passport meets international standards as set out by the International Civil Aviation Organisation."

Talkback

> The Home Office denied that e-passports
> would make identity authentication less secure.

I love it. The article debunks, to a reasonable level of detail, the security mechanisms on e-Passports, and by extension UK ID Cards. But by "Saying" in the special way that government departments do, that it's actually all fine, we can now just dismiss it all and hop and skip along in a happy laughing way.

Yet another example of "Policy is Truth" at work. The Policy is that "e-Passports and ID Cards are 100% hacker proof are a stepwise improvement in security" and as a Policy this is now "The Truth", in an almost religious sense. Now we can simply consider any statement or action to the contrary to be counter to policy and so counter to Truth and so therefore it must be a lie, a mistake or irrelevant. We don't actually have to do anything about it because the supposed facts have ceased to exist in a puff of Government Sponsored Logic.

Andrew Meredith 3 Oct 08 12:43 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

georgiox

love the LHC info. Keep up the good work. May God bless all in volved.

3 hours ago by georgiox on LHC to run for longest continuous period
sgardia

You are quite right. HDS has not been marketing their products well. USPV is miles ahead in terms of ease of use and technology on enterprise...

8 hours ago by sgardia on Will the SUN set on Hitachi Data Systems OEM relationship?
apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

19 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

21 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

21 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

23 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

23 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

24 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

24 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

1 day ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

1 day ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

1 day ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

1 day ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now