Cloning and modifying E-Passports

[THC/vonJeek] have released an application that allow you to backup and modify E-Passport data.  Check out the video of Elvis checking in at the airport.  Apparently there is no way for the machine to know if the passport has been tampered with.

[via Schneier]


  1. Man On Fire says:

    I bought an RFID proof wallet for mine. haven’t tested it to see if it works yet though.

  2. JimXugle says:

    Wouldn’t this all be moot point if the data on the passport was digitally signed by the issuing country’s passport office using a private/public key system?

  3. Ed says:

    Whoa, the guy creates a fake epassport (all the specs are public and on the web anyway, icao doc 9303) and reads it using a public demo terminal, which does not check any particular security feature and just displays the contents of the chip.

    Come on, I’ll be impressed the day the same person goes through customs using a totally fake ePassport. I seriously doubt a white smart card such as the one on video will be accepted by border control :-)

  4. BLKMGK says:

    Umm, the data IS signed. However the signature isn’t always properly checked and the file that specifies what security features are on the passport is apparently unprotected according to his talk at BH. I’d agree that the fact that a demo station allows this doesn’t mean that it will work in a real passport scanner.

  5. Skitchin says:

    Yeah, leave it to the people leaving comments to downplay this type of thing. Now just imagine the people who don’t want to release the exploits that THEY found.

  6. Ali Raheem says:

    @2 JimXugle
    That’s true but a hell of a lot haven’t.

    @3 Ed
    The white RFID card could be taken apart (using acetone) and the coil chip taken out I’m sure you could embed it in a passport somehow. Might need to disable the RFID chip already in there would a needle piecing the chip work?

    At least it read it and displayed the info, if the nation hasn’t joined the public key sharing register then this may actually be workable. Once they do join it’ll be much securer.

  7. digideth says:

    video been yanked from google, anyone have a link to another copy?

  8. Gulielmo says:

    I have a doppelganger whom is a close personal friend of mine, so close in appearance is he, that people on the same project constantly approached me and started a dialog with me thinking I was him. Now do you think this is potentially scary?

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s


Get every new post delivered to your Inbox.

Join 96,687 other followers