Info

You are currently browsing the The Systemic Analyst weblog archives for the day August 17 2007.

Calendar
August 2007
M T W T F S S
« Jul   Sep »
 12345
6789101112
13141516171819
20212223242526
2728293031  
Links

Archive for August 17 2007

Scan This Guy’s E-Passport And Watch Your System Crash

Here is an interesting article from Wired. Despite the fact that technology was used to answer age old problems with identity documents, the issues appear still to remain. One has to ask whether the costs of implementing expensive solutions to “improve” upon traditional measures makes much sense or not?

A German security researcher who demonstrated last year that he could clone the computer chip in an electronic passport has revealed additional vulnerabilities in the design of the new documents and the inspection systems used to read them.

Lukas Grunwald, an RFID expert who has served as an e-passport consultant to the German parliament, says the security flaws allow someone to seize and clone the fingerprint image stored on the biometric e-passport, and to create a specially coded chip that attacks e-passport readers that attempt to scan it.

Grunwald says he’s succeeded in sabotaging two passport readers made by different vendors by cloning a passport chip, then modifying the JPEG2000 image file containing the passport photo. Reading the modified image crashed the readers, which suggests they could be vulnerable to a code-injection exploit that might, for example, reprogram a reader to approve expired or forged passports. Click here for more.

|