Feeds

How to clone the copy-friendly biometric passport

So easy the manual tells you that you can do it

The Essential Guide to IT Transformation

Analysis At Black Hat yesterday, security consultant Lukas Grunwald of German company DN-Systems demonstrated the cloning of a biometric passport, observing beforehand to Wired that the "whole passport design is totally brain damaged." But should we be surprised? Not exactly, because that's precisely what it says on the tin.

Grunwald boned-up on ICAO (International Civil Aviation Organisation) documentation, bought an ePassport reader and reading software, read a passport (German, but other ePassports would do the trick too), then cloned it. We should however be clear about what he has done here - he hasn't cracked anything, but he has brought the fundamental flakiness of the ePassports that are now shipping to wider attention. People will no doubt be appalled, but they could just as easily have been appalled some considerable distance back in the production process because that really is what it says on the tin.

The ICAO documentation Grunwald consulted is publicly available, and explains the detail of the various levels of security of the ePassport system, the baseline level being something not unadjacent to zero. For standard ePassports including chip and facial biometric the ICAO assumption is that an open passport can be taken as the bearer's acceptance that the passport is willingly being made available for the data to be read, ICAO's intent here being to duplicate as closely as possible the inherent Ts & Cs of traditional passport inspection systems. But the ePassport is RFID, and therefore vulnerable to skimming and eavesdropping (i.e. being read by a concealed reader and/or having the transaction between passport and 'official' reader snooped on.

Two mechanisms will be used in ePassports to impede this; first, there is the 'tinfoil hat', a mesh of metal in the cover that blocks access to the chip when the passport is closed, and second the machine-readable zone (MRZ) of the passport. The MRZ is designed to be read visually when the passport is open, and this is then compared to the copy of the MRZ held on the chip. If the two match, then the data on the chip can be read.

There are other, optional levels of security that we'll go into shortly, but what we've covered so far is what most countries will be shipping in this generation, and what Grunwald had to deal with. Here what he did again, in slow motion this time.

Grunwald bought an official inspection reader (N.B. this is legal, and even if it weren't the volumes of machines the market will need would make it trivial to obtain one) and placed his passport on top of it. Using Golden Reader Tool software from secunet Security Networks he read the chip in the passport. Golden Reader Tool is again freely available, and is widely used in the current round of ePassport interoperability testing. From there, Grunwald was able burn the data onto a chip in a blank sample passport page, giving him a blank document that looks to readers like the original passport.

Note that there's nothing particularly special about the official reader here, so it would be feasible with this level of security to use a homebrew reader. Note also that this is precisely what ICAO says you can do if this level of security is all that's used. MRZ comparison: "Adds (minor) complexity. Does not prevent an exact copy of chip AND conventional document."(PKI for MRTDs offering ICC Read-Only Access V1.1)

So what can you do with this? You've got an exact copy of the chip from one person's passport, but you do not at the moment have a mechanism for changing the data on the chip, and in order to produce an entire copy of the passport you'd need to get over the more conventional speedbumps to forgery in the rest of the document. But you do have something that's potentially quite useful, and under certain circumstances can brush aside what border security exists.

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
White? Male? You work in tech? Let us guess ... Twitter? We KNEW it!
Grim diversity numbers dumped alongside Facebook earnings
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
Bose says today is F*** With Dre Day: Beats sued in patent battle
Music gear giant seeks some of that sweet, sweet Apple pie
Amazon Reveals One Weird Trick: A Loss On Almost $20bn In Sales
Investors really hate it: Share price plunge as growth SLOWS in key AWS division
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.