SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Politics : Impeach George W. Bush -- Ignore unavailable to you. Want to Upgrade?


To: Orcastraiter who wrote (83072)8/5/2007 5:18:40 PM
From: Skywatcher  Read Replies (2) | Respond to of 93284
 
BUSH AND HIS INCOMPETENT CLOWNS>>>>FURTHER PUTTING AMERICANS AT RISK!
e-Passports get hacked in new security threat
Researcher finds another vulnerability in RFID-passports, analysts see potential for trouble.
By Chris Zappone, CNNMoney.com staff writer
August 3 2007: 2:30 PM EDT

NEW YORK (CNNMoney.com) -- As the nation grapples with difficulties getting new passports, a technology researcher has found another problem with the radio frequency ID technology the new documents carry.

Computer security expert Lukas Grunwald cloned and manipulated the content of a RFID passport, then used the hacked e-Passport to crash the machine needed to read it.
retail_rfid_tag_upc.03.gif
darington_forbes.03.jpg
Lukas Grunwald of DN-Systems Enterprise Internet Solutions

Grunwald says that although the passport wasn't American the threat certainly extends to American passports, which use similar technology.

RFID technology combines silicon chips with antennas to make data accessible via radio waves. It's already a $650 million industry, according to ABI Research, which expects the market to more than triple by 2011.

Technologists, however, have insisted for that RFID technology as implemented in the U.S. Passport is not secure and cannot assure privacy.

The U.S. government began rolling out RFID-chipped E-passports last year over the objections of numerous security experts.

The RFID passport is "fundamentally insecure by design," Grunwald said. The vulnerability could enable a person "to crash the reading machine at an airport or to manipulate it in a nasty way so that forged passport could be accepted," he said.

Industry representatives disputed the conclusion of the work.

"I don't know if there is any credibility in this story," said Randy Vanderhoof, Executive Director of the Smart Card Alliance, who said he would hold off any judgment until he was more familiar with the claims.

Vanderhoof did point out, however, that Grunwalk was using a German passport with a fingerprint biometric.

"In US we're not using a fingerprint biometric," he said.

The State Department did not respond to a request for comment.

The U.S. e-Passport uses a digital image of the passport photograph as the biometric identifier, according to the State Department website.

Paul Procter of technology research group Gartner said the vulnerability that Grunwald discovered is, like many exploits of RFID technology, "low probability but high impact."

The problems with securing information on RFID are "real" and "well-known," Procter said, who called Grunwald's work "sound."

"If the government discovers a cloned passport, it will be stuck with millions of insecure passports. RFID will be in there but just ignored," he said.

But in order for the government to act, it "will have to catch someone cloning it in a nefarious way." Then Procter predicts the whole RFID infrastructure (passports, readers, etc) would become null and void for the government.

"Governments aren't going to respond to a researcher but to a baddie," Procter said.

Grunwald is undaunted. He says he is "shocked at how naive the industry - specifically the security document industry is - going into this field and trying to implement security that puts us at risk."

Grunwald, will discuss the vulnerability Saturday at the DefCon 15 hacker convention in Las Vegas this weekend.

DefCon is an annual hackers convention attended by hackers, corporate IT security professionals and federal authorities from around the world. Top of page
As RFID tracking booms, privacy issues loom



To: Orcastraiter who wrote (83072)8/6/2007 2:53:13 PM
From: one_less  Respond to of 93284
 
I look forward to seeing good clear conservative thinking and good clear liberal thinking, as it helps when addressing issues that have broad reaching implications. Too bad we can't find any of that type of thinking in these political dog fight arenas.