<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: passports]]></title>
    <link>http://securityratty.com/tag/passports</link>
    <description></description>
    <pubDate>Tue, 17 Jun 2008 13:57:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[on HITB 2008 Conference]]></title>
      <link>http://securityratty.com/article/7182dd4ae495366352b2abc23339e496</link>
      <guid>http://securityratty.com/article/7182dd4ae495366352b2abc23339e496</guid>
      <description><![CDATA[Not to pretend to steal Halvar Flake's glory , but I just got my own &quot;fun&quot; international travel story, which also spells bad news to those who wanted to hear my fun keynote at Hack In The Box 2008 in...]]></description>
      <content:encoded><![CDATA[Not to pretend to <a href="http://it.slashdot.org/it/07/07/29/2057243.shtml">steal Halvar Flake's glory</a>, but I just got my own "fun" international travel story, which also spells bad news to those who wanted to hear <a href="http://conference.hackinthebox.org/hitbsecconf2008kl/?page_id=59">my fun keynote at Hack In The Box 2008</a> in Kuala Lumpur, Malaysia.<br /><br />To make the short story ... even shorter :-), I got kicked off my flight since my passport is only valid 5.5 months in the future and Malaysia requires that visitors' passports are valid for 6 months from the date of arrival (not that they make it anywhere near clear on their embassy website or anything :-)). <br /><br />What makes it funnier is that I got so used to US dates of <span style="font-style: italic;">month/day/year </span>that I actually was genuinely shocked when they said "you passport is not valid for 6 months" while it clearly said "Expires on 8/4/2009" ...<br /><br />So much for Kuala Lumpur :-(  Back to work now.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=FdDIM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=FdDIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=VJ6HM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=VJ6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0BdyM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0BdyM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/433838238" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 07:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kuala lumpur">kuala lumpur</category>
      <category domain="http://securityratty.com/tag/malaysia requires">malaysia requires</category>
      <category domain="http://securityratty.com/tag/fun keynote">fun keynote</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/valid">valid</category>
      <category domain="http://securityratty.com/tag/malaysia">malaysia</category>
      <category domain="http://securityratty.com/tag/international travel story">international travel story</category>
      <category domain="http://securityratty.com/tag/spells bad news">spells bad news</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/433838238/on-hitb-2008-conference.html">on HITB 2008 Conference</source>
    </item>
    <item>
      <title><![CDATA[How To Disable Your Passport's RFID Chip ]]></title>
      <link>http://securityratty.com/article/6c26bfd6df008f7ec9aaee034c3f2cad</link>
      <guid>http://securityratty.com/article/6c26bfd6df008f7ec9aaee034c3f2cad</guid>
      <description><![CDATA[All passports issued by the US State Department after have always-on RFID chips, making it easy for officials and hackers to grab your personal...]]></description>
      <content:encoded><![CDATA[All passports issued by the US State Department after have always-on RFID chips, making it easy for officials – and hackers – to grab your personal stats.]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 16:20:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/always-on rfid chips">always-on rfid chips</category>
      <category domain="http://securityratty.com/tag/personal stats">personal stats</category>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/easy">easy</category>
      <category domain="http://securityratty.com/tag/grab">grab</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://digg.com/security/How_To_Disable_Your_Passport_s_RFID_Chip_3">How To Disable Your Passport's RFID Chip </source>
    </item>
    <item>
      <title><![CDATA[How To Disable Your Passport's RFID Chip ]]></title>
      <link>http://securityratty.com/article/b15cc5f4150c8c1d3b8d5892b2a0d452</link>
      <guid>http://securityratty.com/article/b15cc5f4150c8c1d3b8d5892b2a0d452</guid>
      <description><![CDATA[All passports issued by the US State Department after have always-on RFID chips, making it easy for officials and hackers to grab your personal...]]></description>
      <content:encoded><![CDATA[All passports issued by the US State Department after have always-on RFID chips, making it easy for officials – and hackers – to grab your personal stats.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/fyjq3-IeaN0" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 16:20:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/always-on rfid chips">always-on rfid chips</category>
      <category domain="http://securityratty.com/tag/personal stats">personal stats</category>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/easy">easy</category>
      <category domain="http://securityratty.com/tag/grab">grab</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/fyjq3-IeaN0/How_To_Disable_Your_Passport_s_RFID_Chip_3">How To Disable Your Passport's RFID Chip </source>
    </item>
    <item>
      <title><![CDATA[How to Clone and Modify E-Passports]]></title>
      <link>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</link>
      <guid>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</guid>
      <description><![CDATA[The Hackers Choice has released a tool allowing people to clone and modify electronic passports
The problem is self-signed certificates
A CA is not a great solution: Using a Certification Authority...]]></description>
      <content:encoded><![CDATA[<p>The Hackers Choice has <a href="http://blog.thc.org/index.php?/archives/4-The-Risk-of-ePassports-and-RFID.html">released</a> a tool allowing people to clone and modify electronic passports.</p>

<p>The problem is self-signed certificates.</p>

<p>A CA is not a great solution:</p>

<blockquote>Using a Certification Authority (CA) could solve the attack but at the same time introduces a new set of attack vectors:

<ol><li>The CA becomes a single point of failure. It becomes the juicy/high-value target for the attacker. Single point of failures are not good. Attractive targets are not good.

<p>Any person with access to the CA key can undetectably fake passports. Direct attacks, virus, misplacing the key by accident (the UK government is good at this!) or bribery are just a few ways of getting the CA key.</p>

<p><li>The single CA would need to be trusted by all governments. This is not practical as this means that passports would no longer be a national matter.</p>

<p><li>Multiple CA's would not work either. Any country could use its own CA to create a valid passport of any other country. Read this sentence again: Country A can create a passport data set of Country B and sign it with Country A's CA key. The terminal will validate and display the information as data from Country B.This option also multiplies the number of 'juicy' targets. It makes it also more likely for a CA key to leak.</p>

<p>Revocation lists for certificates only work when a leak/loss is detected. In most cases it will not be detected.</ol></p>

<p>So what's the solution? We know that humans are good at Border Control. In the end they protected us well for the last 120 years. We also know that humans are good at pattern matching and image recognition. Humans also do an excellent job 'assessing' the person and not just the passport. Take the human part away and passport security falls apart.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UYU6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UYU6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=z7bQL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=z7bQL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 08:24:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/passport">passport</category>
      <category domain="http://securityratty.com/tag/passport security falls">passport security falls</category>
      <category domain="http://securityratty.com/tag/passport data set">passport data set</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <category domain="http://securityratty.com/tag/electronic passports">electronic passports</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/undetectably fake passports">undetectably fake passports</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/how_to_clone_an.html">How to Clone and Modify E-Passports</source>
    </item>
    <item>
      <title><![CDATA[For Some, Stealing IDs Means More Than Fast Cash]]></title>
      <link>http://securityratty.com/article/fa339ae0069b559c084077a74a78ce7a</link>
      <guid>http://securityratty.com/article/fa339ae0069b559c084077a74a78ce7a</guid>
      <description><![CDATA[Over a hundred people in the last few years have been charged with stealing IDs of dead people, in order to evade the law for various reasons something that could probably be avoided with better...]]></description>
      <content:encoded><![CDATA[<p>Over a hundred people in the last few years have been charged with stealing IDs of dead people, in order to evade the law for various reasons &#8212; something that could probably be avoided with better computerized ID systems. Granted a hundred out of how many billion in the States is not that many people, however other reasons for ID theft are sometimes overlooked when we talk about scams. Here are some of the details:</p>
<blockquote><p>Several of the defendants have been convicted of stealing dead people&#8217;s identities to cover up their status as illegal immigrants, military deserters or convicted drunken drivers, federal officials said.</p>
<p>Between July 2005 and August of this year, 112 people were charged in federal court as part of the investigation, which federal officials called &#8220;Operation Deathmatch.&#8221; Authorities seized $650,000 in cash, a Mercedes-Benz, three guns and more than 80 of the fraudulent passports.</p></blockquote>
<p>For more case studies, read the article in the <a rel="nofollow" target="_blank" href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/09/17/BAVV12VO5L.DTL&amp;feed=rss.bayarea">SF Gate </a>(online version of the Chronicle).</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 07:54:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dead people">dead people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/federal officials">federal officials</category>
      <category domain="http://securityratty.com/tag/dead peoples identities">dead peoples identities</category>
      <category domain="http://securityratty.com/tag/operation deathmatch">operation deathmatch</category>
      <category domain="http://securityratty.com/tag/military deserters">military deserters</category>
      <category domain="http://securityratty.com/tag/ids">ids</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/illegal immigrants">illegal immigrants</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/396532338/">For Some, Stealing IDs Means More Than Fast Cash</source>
    </item>
    <item>
      <title><![CDATA[Dont Put Too Much Faith in High-Tech Passports]]></title>
      <link>http://securityratty.com/article/40d9b3ca8741d496f5774da7a69fbd56</link>
      <guid>http://securityratty.com/article/40d9b3ca8741d496f5774da7a69fbd56</guid>
      <description><![CDATA[Two European researchers have found a way to defeat the chips being placed in passports to eliminate fraud. Its another reminder never to place blind faith in...]]></description>
      <content:encoded><![CDATA[Two European researchers have found a way to defeat the chips being placed in passports to eliminate fraud. It’s another reminder never to place blind faith in technology.]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 04:38:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/european researchers">european researchers</category>
      <category domain="http://securityratty.com/tag/blind faith">blind faith</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/chips">chips</category>
      <category domain="http://securityratty.com/tag/defeat">defeat</category>
      <category domain="http://securityratty.com/tag/reminder">reminder</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <source url="http://digg.com/security/Don_t_Put_Too_Much_Faith_in_High_Tech_Passports">Dont Put Too Much Faith in High-Tech Passports</source>
    </item>
    <item>
      <title><![CDATA[E-Passports Can Be Hacked and Cloned in Minutes]]></title>
      <link>http://securityratty.com/article/105ebc05ca29d986171344b815ea53c9</link>
      <guid>http://securityratty.com/article/105ebc05ca29d986171344b815ea53c9</guid>
      <description><![CDATA[A computer researcher proved it by cloning the chips in two British passports and then implanting digital images of Osama bin Laden and a suicide bomber. Both passports passed as genuine by UN...]]></description>
      <content:encoded><![CDATA[A computer researcher proved it by cloning the chips in two British passports and then implanting digital images of Osama bin Laden and a suicide bomber. Both passports passed as genuine by UN approved passport reader software. The entire process took less than an hour.]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 09:30:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/british passports">british passports</category>
      <category domain="http://securityratty.com/tag/passport reader software">passport reader software</category>
      <category domain="http://securityratty.com/tag/osama bin">osama bin</category>
      <category domain="http://securityratty.com/tag/computer researcher">computer researcher</category>
      <category domain="http://securityratty.com/tag/digital images">digital images</category>
      <category domain="http://securityratty.com/tag/suicide bomber">suicide bomber</category>
      <category domain="http://securityratty.com/tag/entire process">entire process</category>
      <category domain="http://securityratty.com/tag/hour">hour</category>
      <source url="http://digg.com/security/E_Passports_Can_Be_Hacked_and_Cloned_in_Minutes">E-Passports Can Be Hacked and Cloned in Minutes</source>
    </item>
    <item>
      <title><![CDATA[UK Electronic Passport Cloned]]></title>
      <link>http://securityratty.com/article/6a81d22ed8789bb1273fb4d5796cb199</link>
      <guid>http://securityratty.com/article/6a81d22ed8789bb1273fb4d5796cb199</guid>
      <description><![CDATA[The headline says it all: &quot;Fakeproof e-passport is cloned in minutes
Does this surprise anyone? This is what I wrote about electronic passports two years ago in The Washington Post : The other...]]></description>
      <content:encoded><![CDATA[<p>The <a href="http://www.timesonline.co.uk/tol/news/uk/crime/article4467106.ece">headline</a> says it all: "‘Fakeproof’ e-passport is cloned in minutes."</p>

<p>Does this surprise anyone?  <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/09/15/AR2006091500923.html">This</a> is what I wrote about electronic passports two years ago in <i>The Washington Post</i>:</p>

<blockquote>The other security mechanisms are also vulnerable, and several security researchers have already discovered flaws. One found that he could identify individual chips via unique characteristics of the radio transmissions. Another successfully cloned a chip. The State Department called this a "meaningless stunt," pointing out that the researcher could not read or change the data. But the researcher spent only two weeks trying; the security of your passport has to be strong enough to last 10 years.

<p>This is perhaps the greatest risk. The security mechanisms on your passport chip have to last the lifetime of your passport. It is as ridiculous to think that passport security will remain secure for that long as it would be to think that you won't see another security update for Microsoft Windows in that time. Improvements in antenna technology will certainly increase the distance at which they can be read and might even allow unauthorized readers to penetrate the shielding.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WxEtPK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WxEtPK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LKjanK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LKjanK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 02:11:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passport">passport</category>
      <category domain="http://securityratty.com/tag/passport chip">passport chip</category>
      <category domain="http://securityratty.com/tag/fakeproof e-passport">fakeproof e-passport</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/passport security">passport security</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/security mechanisms">security mechanisms</category>
      <category domain="http://securityratty.com/tag/chip">chip</category>
      <category domain="http://securityratty.com/tag/antenna technology">antenna technology</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/uk_electronic_p.html">UK Electronic Passport Cloned</source>
    </item>
    <item>
      <title><![CDATA[3,000 Blank British Passports Stolen]]></title>
      <link>http://securityratty.com/article/06f706b7e2eb3f38470ba04837c85deb</link>
      <guid>http://securityratty.com/article/06f706b7e2eb3f38470ba04837c85deb</guid>
      <description><![CDATA[Looks like an inside...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.time.com/time/world/article/0,8599,1827501,00.html">Looks</a> <a href="http://www.foxnews.com/story/0,2933,393581,00.html">like</a> an <a href="http://news.sky.com/skynews/Home/Politics/British-Passports-Stolen-After-Van-Hijacked-En-Route-From-Oldham-to-RAF-Northolt/Article/200807415058916?lpos=Politics_1&lid=ARTICLE_15058916_British+Passports+Stolen+After+Van+Hijacked+En+Ro">inside job</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vTx7eJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vTx7eJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JNNWtJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JNNWtJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 02:08:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/inside job">inside job</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/3000_blank_brit.html">3,000 Blank British Passports Stolen</source>
    </item>
    <item>
      <title><![CDATA[Danger in Dubai?]]></title>
      <link>http://securityratty.com/article/98b75579ae29805b62278e6d64bd9360</link>
      <guid>http://securityratty.com/article/98b75579ae29805b62278e6d64bd9360</guid>
      <description><![CDATA[Those who come to Dubai could be forgiven for thinking that this is an Oasis in a peaceful desert. In reality though, they would do well to remember that this Oasis is located in the middle of a...]]></description>
      <content:encoded><![CDATA[Those who come to Dubai could be forgiven for thinking that this is an Oasis in a peaceful desert.  In reality though, they would do well to remember that this Oasis is located in the middle of a volatile region. <br /><span id="fullpost"><br />I came to Dubai and the United Arab Emirates a week ago to promote an International Executive Protection course that we are holding here later in the summer.  While it is true that most citizens in the U.A.E. are law abiding, there is potential here for opportunists to turn that around.  Anyone who spends anytime here, especially in the vicinity of Dubai, will see that it is an extremely wealthy area.<br /><br />I was talking to an ex-pat business man last night at dinner and he made the comment that a friend of his could not get the attention of the Valets at a local club recently because he was "only driving a Porsche 911".  The valets were too busy finding premium parking spots for the Bentleys, Aston Martins and Ferraris.  This is why Sexton Executive Security is opening an office in the U.A.E.  We believe it is only a matter of time before cunning criminals realize how much money they could make from kidnappings, stealing luxury cars/chop shops and a host of other crimes.<br /><br />Then yesterday morning something else happened.  One of the Embassies released a terrorist alert warning for the U.A.E.  Despite the fact that this is the Middle East, alerts like this are not common.  Afteralll, this is a shopper's paradise where vistors can spend thousands of dollars on a hotel suite for the night.  Now we have begun to compile a list of Executive Protection Specialists with current passports who are available for International assignments.<br /><br />Don't let the bright lights fool you.  This is not Kansas Dorothy.  Keep your eyes open and like they used to say on Hill Street Blues; "let's be careful out there."             <br /></span><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 13:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dubai">dubai</category>
      <category domain="http://securityratty.com/tag/luxury carschop shops">luxury carschop shops</category>
      <category domain="http://securityratty.com/tag/sexton executive security">sexton executive security</category>
      <category domain="http://securityratty.com/tag/middle east">middle east</category>
      <category domain="http://securityratty.com/tag/bright lights fool">bright lights fool</category>
      <category domain="http://securityratty.com/tag/middle">middle</category>
      <category domain="http://securityratty.com/tag/executive protection specialists">executive protection specialists</category>
      <category domain="http://securityratty.com/tag/international executive protection">international executive protection</category>
      <category domain="http://securityratty.com/tag/hill street blues">hill street blues</category>
      <source url="http://www.thebulletproofblog.com/2008/06/danger-in-dubai.html">Danger in Dubai?</source>
    </item>
  </channel>
</rss>
