Slashdot Mirror


RFID Passports Raise Safety Concerns

CurtMonash writes "CNNMoney.com features a skeptical article about the US State Department's plans to soon issue RFID passports (currently being tested on State Department employees). One fear is that they can be hacked for information about you. And even if they can't, carrying around a little transmitter saying 'I'm an American! I'm an American!' isn't a fun and safe thing to do in all parts of the world." From the article: "Basically, you've given everybody a little radio-frequency doodad that silently declares 'Hey, I'm a foreigner,' says author and futurist Bruce Sterling, who lectures on the future of RFID technology. 'If nobody bothers to listen, great. If people figure out they can listen to passport IDs, there will be a lot of strange and inventive ways to exploit that for criminal purposes.'"

5 of 459 comments (clear)

  1. Re:Save tinfoil hat for passport by alanxyzzy · · Score: 4, Informative
    Bruce Schneier thinks that it will be OK

    ...

    The new design also includes a thin radio shield in the cover, protecting the chip when the passport is closed. More good security.

    Assuming that the RFID passport works as advertised (a big "if," I grant you), then I am no longer opposed to the idea.

    ...

  2. Re:Confused? by Mayhem178 · · Score: 4, Informative

    As I understand it, RFID cards don't do anything until they're exposed to an electromagnetic field, which gives them just enough juice to fire off a message, usually an identity code. Unless I've been completely misinformed, you'd have to generate quite the field to even have a chance of reading one of these things at a distance. I know that my RFID card doesn't work until it's within a coupla inches of the appropriate reader.

    The whole "it's broadcasting all of your personal information!!!!" hype is a bunch of FUD. The only way it could really be a security risk is if the card itself was stolen, and then it's really no different than having your S.S. card or driver's license stolen.

    --

    "You will pay for your lack of vision..." - Emperor Palpatine to Ray Charles

  3. Re:What happens if the RFID doesnt work by jcupitt65 · · Score: 3, Informative
    The UK's ID card regulations include a £1,000 fine if you know your card to be defective but do not report it :-(

    You will be required to attend an enrolment centre with some form of identifying material - bank statements, credit cards, driving licence or birth certificate, who knows what. Then you will be fingerprinted, photographed and the iris in your eye will be measured. You will give the authorities 49 pieces of information about yourself. If you don't, you may be fined up to £2,500. Additional fines of up to £2,500 may be levied every time you fail to comply.

    If you fail to inform the police or Home Office when you lose your card, or if it becomes defective, you face a fine of up to £1,000. If you find someone else's card and do not immediately hand it in, you may have committed a criminal offence punishable by imprisonment for up to two years, or a fine, or both. And you will be fined £1,000 if you fail to inform the NIR of any change of address. You will also be expected to tell the authorities your previous addresses. Truly the government will be able to say with all the menace of the underworld enforcer: "We know where you live."

    If you don't inform the register of significant changes to your personal life, or any errors they have made, you will face a fine of up to £1,000. Astonishingly, you may also face a fine if you fail to submit to being reinterviewed, rephotographed, refingerprinted and rescanned.

    http://www.guardian.co.uk/g2/story/0,,1817436,00.h tml
  4. Re:yeah by afidel · · Score: 5, Informative

    According to Schneier the State Department already plans (and has since sometime last year) to include a RF shield so the chip can only be read while the passport is open and they are encrypting the data on the RFID.

    --
    There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
  5. Re:endangering civilians by MCraigW · · Score: 4, Informative
    Using RFID for passports is not only stupid but completely irresponsible. It would put anyone in danger, especially traveling abroad. It doesn't take alot of brains to imagine the worst how this can be exploited by terrorists and rogue forces. Hopefully our government will recognize and stop this crazy proposal in time.

    As I stated in an earlier post, Austrailia, New Zealand and Singapore already have RFID passports. The information that can be obtained from the chip is encrypted, and will only be readable using the public-key which is encoded in a machine readable format inside the passport http://www.dfat.gov.au/dept/passports/. The plan in the U.S. is the to do the same thing, as well as putting a metal lining in the cover of the passport so that the RFID cannot be read when the passport is closed. See http://www.aimglobal.org/members/news/anmviewer.as p?a=394&print=no