Monday Museum: Cloning e-passports

[Dave Birch] We thought it would be fun to loot the archives of our blogs to see how the world of transactions has developed. So here is another in our “Monday Museum” series, from� 24th August 2006.

[Stuart Fiske] Because of the CHYP Electronic Passport Interoperability Service, we’ve already had a few calls about today’s Wired News story on the cloning of e-passports.   But what exactly is this story about?  Is it about uncrackable e-passports being broken open by hackers?  Or is it about someone reading the specifications and discovering that e-passports work as they are supposed to?

I don’t understand the word “crack” in the context of the electronic passports. There is nothing personal stored in the chip that is not human readable on the data page of the passport.  If you want to make a clone of the data inside the chip in my passport, you can do it by reading my passport: you don’t need to read what’s in the chip.  Obviously it saves a bit of time getting the digital photo out of the chip, but it’s just the same as the photo in the passport. “Basic Access Control” doesn’t protect the data stored in the chip: it just means that you have to have access to the physical passport in order to read the chip.  “Active Authentication” in the specifications allows the data to be linked to the specific chip, but it’s an optional extra which can be implemented if any government so chooses.  It’s a bit like the Static Data Authentication (SDA) versus Dynamic Data Authentication (DDA) issue for “chip and PIN” cards. Of course, if you have physical access to my passport you can read all the other chip data which secures my personal data as being valid, but you can’t change it, only copy it.   So you could copy my passport but what’s the point if you can’t change my data to match your face? When a passport control person puts your passport in their reader, it displays the picture inside the chip: if it doesn’t match the picture in the passport (or your face), I expect they will notice. Much as we love them, this is just not a “brilliant hackers break unbreakable code” story.  It’s a “person reads specification” story.

I don’t think much has changed in the press reporting of this kind of story over the years. The stories never reflect the kind of risk analysis that has gone into the design of such systems and as a consequence they don’t reflect real vulnerabilities.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

In which style battles function and confusion ensues

[Jane Adams] Partly because I want to be down with the kids and partly because of my job, I recently took delivery of a lovely new Barclaycard PayTag. This I duly stuck to my phone, as suggested, and prepared to be part of the new wave of consumers who can leave their wallets at home (personally, I’d rather leave my phone at home but don’t tell anyone).

Not long afterwards I noticed that my phone was behaving very strangely. Every time I unlocked it, it generated an ‘empty tag’ screen that I had to delete. Using the keypad during calls (for example to call centres) became nightmarish as every time I moved the phone, I generated another tag, which switched the keypad off. As I’d recently downloaded an Android update, I assumed that this was to blame and hoped there’d be another release soon to get rid of the problem.

It wasn’t till I was fiddling around with my Wi-fi settings that I noticed that NFC on the phone was switched on. The phone (a Samsung S3) and the tag were fighting with each other. I switched it off, removed the tag just in case and the problem stopped.

I’d actually quite like to keep NFC enabled on my phone (it goes with the job) so where do I stick the tag? Not to my beautiful, expensive, new leather purse, for a start. Nor is there any point in putting it in the purse where it would nestle next to my Barclaycard and cause no end of collisions. I’m not sure I want to attach it to my keyring (more expensive leather) or to the Cryptocard that hangs from it. Nor to my passport either or to my driving licence, which lives in my purse. It’s a bit too big to stick to a lipstick or a pen. I don’t remember anything about this befuddling issue in the otherwise exhaustive pack of paperwork from Barclaycard that came with the tag.

So what’s the point of this? After all, I’m not writing an accessories column for a style blog (it’s a red, faux-snake Longchamp purse by the way – to die for, darling). The point, it seems, is that I know what NFC is because I work for a company that is expert in NFC and so I didn’t take too long to figure out what the problem was. For the regular punter, that is unlikely to be the case and as a result, I predict that there will be an uplift of people taking their tag-encrusted,NFC- enabled phones into their local MNO shop, complaining that it’s broken. This is actually a great opportunity for Barclaycard and network operators to do some positive education around NFC – not just about tags but about contactless in general. As the reader comments resulting from the recent M&S contactless press scare showed, there’s certainly a need for that.

Where would you stick your PayTag if not to your phone?

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.