How to Clone and Modify E-Passports
...passports
The problem is self-signed certificates
A CA is not a great solution: Using a Certification Authority (CA) could solve the attack but at the same time introduces a new set of attack vectors
The CA becomes a single point of failure. It becomes the juicy/high-value target for the attacker. Single point of failures are not good....
