Feeds

Blank robbers swipe 3,000 'fraud-proof' UK passports

Game on for the passport fraudsters?

The essential guide to IT transformation

A consignment of 3,000 "useless" blank biometric passports has been stolen on its way to British embassies throughout the world. Or at least, the Identity & Passport Service says they're useless.

IPS' claim is based on the standard, highly optimistic party line that, as the passports contain a chip, they can't be used to produce fake passports. The chip is intended to hold a copy of the data printed in the passport, so in order to produce a fully functional fake, a passport forger would need to overcome this hurdle. And even if they could, a check of the passport against UK records would reveal that it wasn't on file. The serial numbers of the passports are also known so they ought to show up on watchlists if the numbers aren't changed, while if they are, the numbers could be found to be false or incorrect.

Note however that most of these potential problems have been present for users of forged passports for any years, and that one of the reasons fakes are still valuable is that the circumstances in which the data is checked against central records tend to be fairly limited. A UK passport that will fail when checked against the 'gold standard' UK border control could nevertheless be useful for opening a bank account (if the bank is using the Passport Validation Service), as ID or to pass borders where the checks are less rigorous (which probably goes for the majority of the UK ones).

The serial numbers themselves are also less bulletproof than they might be. The numbers of UK biometric passports are generated using a readily reverse-engineerable system (from data such as date of birth and issuing office), so plausible versions, albeit ones that would fail a record check, can be produced.

IPS' presentation of the chip as the absolute, rock-solid guarantee of the document's integrity also has numerous holes in it. The passport is still valid if the chip isn't working, that's the rules, and while having a broken chip is likely to get you an extended interview at a UK border, the passport would still be useful for travel elsewhere, and would have a value even if the forger didn't bother blowing any data onto the chip.

Nobody has so far shown that data on the chip in a biometric passport can be successfully altered, but it has several times been shown that it can be copied fairly easily, and there are a number of ways in which this could be exploited. A copied chip that didn't match the passport data, for example, could be palmed and used to pass automated border controls of the sort that are currently being planned by IPS.

And it's still early in the relationship between forgers and biometric passports. One could perhaps envisage a future where businesses that regularly had to check passports (say, tourist hotels) could be 'farmed' by forgers for passport data, producing data banks of passports that hadn't been stolen, but that could be cloned on demand - just pick somebody the right age and appearance. Put that together with a stock of blank biometric passports and you've got a nice little business there. ®

5 things you didn’t know about cloud backup

More from The Register

next story
UK fuzz want PINCODES on ALL mobile phones
Met Police calls for mandatory passwords on all new mobes
Munich considers dumping Linux for ... GULP ... Windows!
Give a penguinista a hug, the Outlook's not good for open source's poster child
Hello, police, El Reg here. Are we a bunch of terrorists now?
Do Brits risk arrest for watching beheading video nasty? We asked the fuzz
EU justice chief blasts Google on 'right to be forgotten'
Don't pretend it's a freedom of speech issue – interim commish
Detroit losing MILLIONS because it buys CHEAP BATTERIES – report
Man at hardware store was right: name brands DO last longer
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
UK government accused of hiding TRUTH about Universal Credit fiasco
'Reset rating keeps secrets on one-dole-to-rule-them-all plan', say MPs
Caught red-handed: UK cops, PCSOs, specials behaving badly… on social media
No Mr Fuzz, don't ask a crime victim to be your pal on Facebook
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Yes, but what are your plans if a DRAGON attacks?
Local UK gov outs most ridiculous FoI requests...
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.