8 thoughts on “Cloning and modifying E-Passports

  1. Wouldn’t this all be moot point if the data on the passport was digitally signed by the issuing country’s passport office using a private/public key system?

  2. Whoa, the guy creates a fake epassport (all the specs are public and on the web anyway, icao doc 9303) and reads it using a public demo terminal, which does not check any particular security feature and just displays the contents of the chip.

    Come on, I’ll be impressed the day the same person goes through customs using a totally fake ePassport. I seriously doubt a white smart card such as the one on video will be accepted by border control :-)

  3. Umm, the data IS signed. However the signature isn’t always properly checked and the file that specifies what security features are on the passport is apparently unprotected according to his talk at BH. I’d agree that the fact that a demo station allows this doesn’t mean that it will work in a real passport scanner.

  4. Yeah, leave it to the people leaving comments to downplay this type of thing. Now just imagine the people who don’t want to release the exploits that THEY found.

  5. @2 JimXugle
    That’s true but a hell of a lot haven’t.

    @3 Ed
    The white RFID card could be taken apart (using acetone) and the coil chip taken out I’m sure you could embed it in a passport somehow. Might need to disable the RFID chip already in there would a needle piecing the chip work?

    At least it read it and displayed the info, if the nation hasn’t joined the public key sharing register then this may actually be workable. Once they do join it’ll be much securer.

  6. I have a doppelganger whom is a close personal friend of mine, so close in appearance is he, that people on the same project constantly approached me and started a dialog with me thinking I was him. Now do you think this is potentially scary?

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s