Researcher details Dutch e-passport hack

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

E-passport, NXP, Hack

NEWS

The researcher who claims to have created code that can emulate and clone e-passports has given details of the purported hack.

The anonymous hacker, who prefers to be known by the handle 'vonJeek', told ZDNet.co.uk that the cloned chip works by bypassing electronic security checks.

"If we're talking about bypassing, I mean manipulating the system in such a way that the intended process is not (fully) performed," wrote vonJeek in an email exchange.

The researcher explained that e-passport systems use a mechanism called 'passive authentication' to detect unauthorised changes of data on the chip. A document security object, or 'SOD', is stored in the chip, which contains between two and 16 mathematical values (check values), used to check whether the passport data has been altered. The collection of values is signed using a digital signature. The signature and the public key of the signer, used to check if the signature is correct, are also in the SOD file.

To check if e-passport content has not been altered, the e-passport system reads the index to see which files are stored on the chip, then reads the indexed files. It calculates the check value of each file, and verifies whether the check values match those in the SOD file. The system checks if the digital signature in the SOD has been signed using the public key in the SOD, and whether the public key is owned by a bona fide country. To do this, an International Civil Aviation Organization (ICAO) service called the Public Key Directory (PKD) can be used.

A country can also decide to use an additional security mechanism called 'active authentication', which is used by the Dutch e-passport system, to check whether the chip data has been altered or cloned.

VonJeek claimed the emulator program worked by exploiting a vulnerability in how the e-passport system initially reads the index to see which files are stored on the chip. Using this vulnerability bypasses active authentication, along with any additional services such as fingerprints or other biometric checks. The researcher claimed to have tested his emulator against each of the steps of the e-passport authentication process, verifying if the equipment reported any problems. VonJeek stressed that a video of the passport reader being fooled into accepting data authenticating Elvis Presley showed only a self-scan machine, which did not properly implement all the checking processes.

However, the researcher claimed the emulator could fool any e-passport system, including that used in the UK, if the system followed ICAO guidelines without modification. According to vonJeek, using th emulator, passport clones could be used on the UK system, as the UK does not use active authentication. VonJeek had not tested an e-passport with altered data on a UK system, and could not comment on the full UK authentication process.

At present, the code only works with blank JCOP v4.1 72k smartcards, manufactured by various smartcard suppliers including NXP. VonJeek said the code could possibly be modified to work on JCOP v3.1 cards, another type of e-passport system.

The researcher added that, at present, only nine countries were signed up to the ICAO's PKD, with only five active users, and that other countries had to exchange public keys via secure diplomatic post. This adds complexity and lowers the efficacy of the system, as each of the 45 participating countries have to recognise each other's keys. The UK does not currently participate in the ICAO's PKD.

The security of the system is further flawed by RFID tags not having to be in close proximity to the readers, according to a commentator on The Hacker's Choice website called 'The Ministry of Truth'.

"Thanks to the e-passports it is now possible to build smart-[improvised explosive devices, or IEDs]," wrote the commentator. "A smart-IED waits until a specific person passes by before detonating, or let's say until there are more than 10 Americans in the room. Boom."

Being able to read e-passports from a distance also opens up the possibility of a hacker reading a passport remotely and then using a person's credentials to authenticate himself, wrote the commentator.

The Home Office denied that e-passports would make identity authentication less secure.

"Continuing investment in biometric technology and enhanced security measures will help ensure that passport security is maintained now and in the future," said a Home Office spokesperson. "We take security and privacy very seriously, which is why the British biometric passport meets international standards as set out by the International Civil Aviation Organisation."

Talkback

> The Home Office denied that e-passports
> would make identity authentication less secure.

I love it. The article debunks, to a reasonable level of detail, the security mechanisms on e-Passports, and by extension UK ID Cards. But by "Saying" in the special way that government departments do, that it's actually all fine, we can now just dismiss it all and hop and skip along in a happy laughing way.

Yet another example of "Policy is Truth" at work. The Policy is that "e-Passports and ID Cards are 100% hacker proof are a stepwise improvement in security" and as a Policy this is now "The Truth", in an almost religious sense. Now we can simply consider any statement or action to the contrary to be counter to policy and so counter to Truth and so therefore it must be a lie, a mistake or irrelevant. We don't actually have to do anything about it because the supposed facts have ceased to exist in a puff of Government Sponsored Logic.

Andrew Meredith 3 October, 2008 12:43
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

2 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

3 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

9 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

13 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

15 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

19 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

24 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

1 day ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

1 day ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround