An information and analytics digest for everyone going abroad or staying home
News

Biometric Passports Already Hacked

It turns out biometric passports are even easier to fake than ordinary paper ones. A German programmer managed to prove this by stealing information from a microchip, spending only two weeks and $200.

The hype around biometric passports, which store fingerprints and iris patterns of their holders, began five years ago. At that time, chip passports started being used in Malaysia and the United States. China, South Korea, Japan, Australia, and New Zealand announced the possible introduction of this convenient form of personal data storage. In March of this year, the first biometric passports appeared in Russia as well. They began to be issued to residents of Kaliningrad Oblast, and later every Russian was supposed to receive such a passport.

It is believed that electronic passports have no (or almost no) drawbacks. But there are significant advantages: reliable information protection will help fight terrorism and crime more effectively, and also simplify visa processing and travel abroad. However, last week the security of data on the chips was called into question.

At the DefCon electronic data security conference held in Las Vegas, a consultant for a German company, Lukas Grunwald, stated that he had discovered a method for copying data from new biometric passports. Moreover, the programmer himself was shocked by the simplicity and low cost of the hack: he spent only two weeks and about $200 on his 'research'. According to him, the scheme for illegal copying of information is so simple that it can be applied to absolutely any new passport issued in the USA, UK, and other countries.

If what he says is true, then two discouraging conclusions follow. First of all, criminals will be able to obtain personal information about the country's citizens (previously, government officials swore that this was impossible). But that's not all. 'The data can be transferred to new chips and used to make fake passports,' Grunwald asserts. To confirm, the programmer demonstrated to the public a complete 'clone' of the cracked document.

In response to the programmer's speech, the UK Foreign Office, where biometric passports have been used since March, angrily stated that British electronic documents, unlike American ones, cannot be forged. However, Herr Grunwald was quick to skeptically retort that he could crack the passport of any country.

'The hack is quite real and has been publicly demonstrated several times,' said Alexander Gostev, leading virus analyst at Kaspersky Lab. 'The RFID chips used in passports are designed not only for reading but also for rewriting. This is their main essence, and that is exactly what is the target of hacker attacks.'

What levels of protection could safeguard personal information from hackers? Alas, the expert's answer is pessimistic. 'If the entire security of a passport comes down only to an RFID chip, then consider that such protection simply does not exist,' Alexander Gostev is convinced. 'Additional traditional checks are needed: the presence of a regular photograph, stamps, etc.' And those have been forged since time immemorial.

Ilya NOSYREV.
Novye Izvestia