Chipped Passport Cloned In Minutes
Death Metal Maniac writes "New microchip passports designed to be foolproof against identity theft failed the test when a researcher was able to manipulate one in minutes. The cloned passports were accepted as genuine by the computer software recommended for use at international airports. According to the article: 'A computer researcher cloned the chips on two British passports and implanted digital images of Osama bin Laden and a suicide bomber. The altered chips were then passed as genuine by passport reader software used by the UN agency that sets standards for e-passports.'"
Is anyone surprised? At all? Seriously...
Evolution is a state-sponsored, state-protected religion.
It's becoming obvious that low-tech paper is preferable in both elections and passports.
yes, cos god knows, paper passports were NEVER falsified.
-- All this knowledge is giving me a raging brainer.
...at least not human technology.
Without exception, everything we try to lock up with a key can be unlocked by someone else. I'd like to hear it from anyone else that they recognize the fact that locks only keep honest people out and then perhaps we can move on to the bigger issue of why they are trying so hard to control honest people.
Sounds great, You're in charge to get all the countries in the world to agree to this.
How about an easier task, convince all countries to agree that one server somewhere is where all their trust of their passports is placed.
Really simple. you should have that done by the end of this week right?
Do not look at laser with remaining good eye.
Hmmmm. OK, but the corollary may well be that pretending something other than paper is any better is also folly!
As some other poster says above, you want a level of security that makes it sufficiently difficult for joe-public to not think about trying to beat it, but not so intrusive as to adversly affect people's lives too much in day-to-day use.
All the claptrap and palaver to do with air travel goes too far down the "intrusive" side of things, without actually offering any greater level of security (hence the term Security Theatre). The attempt to track every individual using ID cards, etc, is also too intrusive, and just as ineffective - whereas a simple chip containing a picture which is displayed when the passport (or credit card) is put into a reader would allow a human to easily compare the picture with the person and thereby foil most of the casual passport/credit card fraud.
Finally, you have to recognise that you CANNOT completely stop people from doing bad things and to think you can will lead to the 1984-type society that most right-minded people fear is where we are going already!
Eclectic beats from Leeds, UK
handmadehands.co.uk
Sucessful paper forgeries are usually more time consuming to create, and require skills that are less common in this day and age.
Or another way, a forged passport is one forged passport. A broken authentication system is a thousand forged passports.
As an aside, there is a parallel between pictures on ID and encryption: A picture on an ID allows me to verify that you look exactly like the guy on the ID (for various definitions of "exactly"), and symmetric encryption allows me to be fairly certain no one is listening in on a communication (assuming protected keys, sufficient key size, etc). But neither allow me to KNOW who you are or who I am communicating with. In other words, both systems fail at authentication, which is, in the end, what passports are trying to provide, and many people think encryption provides.
-- Humans, because the hardware IS the software.
So the chip itself hasn't been cracked, it's more a question of the international passport encryption network being worthless.
Technically accurate. But. The chip by itself is worthless. It's only worth something if it counters some kind of threat. This is why security isn't about products or techniques, it's about working systems. If the "chipped passports" don't have a working PKI, then there's really no point to the chips. They go together.
ObQuote: "Security is a process, not a product." -- Bruce Schneier
dragonhawk@iname.microsoft.com
I do not like Microsoft. Remove them from my email address.
Apathy: one of the greatest gifts you can give a tyranny.
Come play free flash games on Kongregate!
History tells us that cryptography usually falls down in implementation, not theory. As soon as you start building networks, selling chip readers, issuing passports then your theory starts to slowly crumble.
Even if the whole chain of trust is perfect it only takes one act of stupidity/corruption by a human to bring the whole thing crashing down.
Passports are also one of the worst possible places for security to fail. Passports, passport readers, etc. can't be updated via a patch, they need to be thrown away and replaced.
The technology for this is in its infancy and rushing out hundreds of millions of passports at an international level is doomed to failure.
I'm sure it won't stop philistine politicians from trying though - after all, it's not their money they're flushing.
No sig today...
Where did you here that? I understand that all the hijackers were 'white' travelling on their own non-terrorist identities. Yes, some had been flagged as suspicious (Mohammed Atta, I believe) by the Germans but this was ignored.
Remember that the British 7/7 bombers were British. the only possible red flag was the visit to Pakistan, but many do that legitimately.
See my journal, I write things there