On TV.com: 2009's Most PIRATED TV Show
BNET Business Network:
BNET
TechRepublic
ZDNet

July 14th, 2009

RFID passports: a tragedy waiting to happen

Posted by Robin Harris @ 4:59 pm

Categories: Uncategorized

Tags: Passport, RFID, Security, Wireless And Mobility, Biometrics, Robin Harris

You’re strolling in the south if France when a van stops, men burst out and in seconds hustle you into the van. “American scum!” they hiss as they hood you. But wearing a Sorbonne t-shirt and no fanny pack, how did they know? Thank your government - and a bad storage choice.

In a recent article Todd Lewan accompanied ethical hacker Chris Paget as he found chipped tourists around San Francisco’s Fishermans Wharf - from a van. Your Canadian flag patch won’t save you now.

Panic + stupid = RFID passports
In 9/11’s aftermath panic ruled the nation’s domestic security bureaucracies, Congress and the White House. Paranoid mid-level bureaucrats were given free rein to “innovate” and guess what popped up? RFID tags in your passport.

And now they are adding them to driver’s licenses too.

Just How Stupid Is It?
Threat Level: Red and rising. Passports have a 10 year life, so the bad guys who want your info – or your scalp – will have 10 years of technology advances to refine their technique.

RFID scanners will get smaller and cheaper. You’ll get older and slower.

But the data is encrypted!
Well, no, it isn’t.

Even if it were encryption works best on unstructured data. What’s in a passport? Name, birthdate, birthplace, date of issue, height, weight, eye color, photo.

Gosh, who could break the code for that? It took security pros using a PC two hours to crack the Dutch version in 2005. Skimming your data for identity theft isn’t too hard.

Then: Z-Hunting. Now: RFID Crack & Track
Of course you are much more likely to die in a car accident than a terrorist attack. Crime is much more likely.

In the 90’s Florida criminals went “Z-hunting” - rental cars had “Z” tags - looking for easily confused or intimidated tourists to rip off. Now foreign criminals - like kidnapping gangs in Mexico - will have the same opportunity.

Put that hammer DOWN, Sarah Connor!

Some people - who’d rather not be secretly ID’d as Americans when traveling - have suggested that the chip could be broken with a hammer. True, but the State Department is way ahead of you:

Any passport which has been materially changed in physical appearance or composition, or contains a damaged, defective or otherwise nonfunctioning electronic chip, . . . may be invalidated.

Slaves of the ICAO
The irony is that this dangerous scheme was hatched by an administration - America’s most popular EX-President - famous for go-it-alone, protect-America-first bluster. And the justification for NOT using a smart card or optical ID system?

This choice is compatible with standards and recommendations of ICAO.

Oh, the United Nations recommended it? Sign us up!

And remember all those ranting “UN-world-government-foreign-laws-destroy-American-freedom” congressman protesting this ill-conceived program? Fox news? Bill O’Reilly? Anderson Cooper? Oprah? Anybody outside the tech and security communities?

Me neither. Probably took the day off.

The Storage Bits take
This is a bad tech decision made by people who really don’t understand the technology or the pace of change. 10 years - the life of a US passport - is several lifetimes in tech.

It will take almost 5 years before half of all passports are e-chipped. We will have e-chipped tourists wandering around the world for the next 15 to 20 years. And more vulnerable each year.

There are so many better options - smart cards, 2D optical codes, dataglyphs and more - that would not compromise citizen security the way RFID does. I hope some unlucky Americans aren’t injured or killed before this misguided program gets revoked.

Comments welcome, of course. Also check out Edward Hasbrouck’s blog for some more background.

Robin HarrisRobin Harris has been messing with computers for over 30 years and selling and marketing data storage for over 20 in companies large and small. See his full profile and disclosure of his industry affiliations.


Email Robin Harris

Subscribe to Storage Bits via Email alerts or RSS.

  • Talkback
  • Most Recent of 197 Talkback(s)
RFID Banknotes
As postulated by a dutch friend of mine in 2001....

"Floyd, don't bother with the guy in the Armani suit, he's only carrying $50. The skanky looking guy in the hoodie is carrying $50k - must be a banking courier, let's get him"



... (Read the rest)
Posted by: Uncle Stoat Posted on: 08/09/09 You are currently: a Guest | | Terms of Use
Spot on about RFID - bad technology choice  Richard Flude | 07/14/09
No fanny pack is a good start.  Robin HarrisZDNet Moderator | 07/14/09
Don't forget about...  Letophoro | 07/15/09
Actually poor implmentation...  mrlinux | 07/15/09
I guess we know ...  chrisportela | 07/15/09
Actually wrong technology....  codeguy007 | 07/15/09
Apparently they don't use RFID tags hmm  codeguy007 | 07/15/09
No personal info imbedded  kragjensen@... | 07/19/09
Personal info does not matter  eburger | 07/19/09
RE: RFID passports: a tragedy waiting to happen  psquared007 | 07/14/09
It may not be that bad, as long as . . .  EdinPeoria | 07/15/09
Solution to problem  deowll | 07/16/09
Newest travel accessory  a.barry@... | 07/16/09
Yeah...  Calknight | 07/16/09
Carved out  Gizbar | 07/17/09
Would it work?  ausvirgo | 07/17/09
Yes  rdhalsteatzd | 07/18/09
RE: RFID passports: a tragedy waiting to happen  ksj99 | 07/14/09
A Fritos bag?  Robin HarrisZDNet Moderator | 07/14/09
BX sales  JJ Brannon | 07/16/09
Protected Wallets and Cases  jpr75_z | 07/14/09
supplied protection  berniesa@... | 07/15/09
ouch  jfederline@... | 07/16/09
Wallet?  vermonter | 07/16/09
Hey guys.... Is anybody sane in this post...  cosuna | 07/16/09
So, tell us...  Dr. John | 07/16/09
So tell US, "Dr. John" --  deltadan | 07/16/09
Try again, deltadan  Dr. John | 07/17/09
Yep! I'm Sane - Do you actually think the US govt did it the smart way?  ausvirgo | 07/17/09
It was not suppose to be of benefit to you.  clareJ | 07/16/09
Problem with 3D bar codes happy  ausvirgo | 07/17/09
Yes  rdhalsteatzd | 07/18/09
RE: RFID passports: a tragedy waiting to happen  jgundrey@... | 07/14/09
RE: RFID passports: a tragedy waiting to happen  michael@... | 07/14/09
RE: RFID passports: a tragedy waiting to happen  pparks_2000 | 07/15/09
The only time I carry it...  jimb01 | 07/16/09
No Passport, No Cambio  dnendza | 07/16/09
Required to carry in India etc.  ausvirgo | 07/17/09
Just spent three weeks in India  jorjitop | 07/18/09
RFID Blocking Folders  snaconst | 07/15/09
Has anybody tried the "Take a Hammer to it" method gotten in trouble?  vernonhorn@... | 07/15/09
Every try to re-enter the US with out a vaild passport.  No_Ax_to_Grind | 07/15/09
Just think like an illegal immigrant  dferguson75@... | 07/16/09
Why would anyone  GOTBO | 07/17/09
A tourist, maybe?  john.foggitt@... | 07/23/09
I imagine a minute in the microwave  A.Sinic | 07/16/09
Only a second or two...  Calknight | 07/16/09
more hassle than it is worth  adr5@... | 07/16/09
RE: RFID passports: a tragedy waiting to happen  jcqs.bchrd@... | 07/15/09
Would help much.  codeguy007 | 07/15/09
Better than "a copy of your finger print(s)": your actual fingers.  fejlinton | 07/16/09
What a bunch of scare tactics...  xXSpeedzXx | 07/15/09
Keep drinking the kool aid!!  Reality Bites | 07/15/09
Kidnapping is Small Potatoes  Jalapeno Bob | 07/15/09
WE HAVE A WINNER!  Lerianis10 | 07/16/09
Thats why the actual data....  mrlinux | 07/16/09
But then...  Calknight | 07/16/09
I think you are missing something.  deowll | 07/16/09
actually..  a.barry@... | 07/16/09
yes and no  adr5@... | 07/16/09
That isn't worth the trouble.  deowll | 07/16/09
very short range  pupkin_z | 07/15/09
Since the majority of Americans don't own a passport ...  de-void | 07/15/09
depends on the size of the antenna  pupkin_z | 07/15/09
depends on the size of the antenna  codeguy007 | 07/15/09
Depends on the reader  philculmer | 07/21/09
RFID Range.  StanMM | 07/15/09
True but...  deowll | 07/16/09
One only, maybe, bu in bulk...  philculmer | 07/21/09
that will change  adr5@... | 07/16/09
Or...  Calknight | 07/16/09
Credit cards are even worse  jb4096 | 07/15/09
Does this author do any research before posting a crap story...  xXSpeedzXx | 07/15/09
Ha-ha!! You believed them!!!  Robin HarrisZDNet Moderator | 07/15/09
Considering the article you refered to is from 2005  xXSpeedzXx | 07/15/09
Uh...the article in the lead story is from 7-11-09  JDWalley | 07/15/09
Using that philosophy...  gvtooker@... | 07/15/09
Sue the government? An interesting fantasy,  gardoglee | 07/15/09
Can't sue the government without its permission.  plonk@... | 07/15/09
Actually, you can sue the government  alaniane@... | 07/15/09
Judge not lawyer worries me.  adr5@... | 07/16/09
hidden terrorist  adr5@... | 07/16/09
Thank you, Robin  pgit | 07/15/09
Indeed...  Calknight | 07/16/09
I believe you are an idiot.  drobinow | 07/16/09
As a PROUD fellow American ....  kd5auq | 07/16/09
you should be worried.  adr5@... | 07/16/09
Article Points at PASS and Drivers License  DGSteig | 07/17/09
Ooops!  deowll | 07/16/09
RE: RFID passports: a tragedy waiting to happen  TAPhilo | 07/15/09
excellent points  adr5@... | 07/16/09
You are several decades to late.  deowll | 07/16/09
Real life experience  jy.durocher@... | 07/15/09
Real life experience but not scientific testing.  codeguy007 | 07/15/09
RE: RFID passports: a tragedy waiting to happen  m_a_simons@... | 07/15/09
Hammer time  raelalt | 07/15/09
bad idea  adr5@... | 07/16/09
Gawd save us from those wishing to protect us.  No_Ax_to_Grind | 07/15/09
But did they protect us.... or expose us?  shawkins | 07/16/09
Facts vs. FUD  BHarris@... | 07/15/09
DON'T YOU BELIEVE IT!  Lerianis10 | 07/16/09
Passport stores same data on the data page of passport!  The Mickster | 07/16/09
... secure government databases ...  fejlinton | 07/16/09
RE: RFID passports: a tragedy waiting to happen  RodinUK | 07/15/09
RE: RFID passports: a tragedy waiting to happen  acalea | 07/15/09
RE: RFID passports: a tragedy waiting to happen  compudog | 07/15/09
RE: RFID passports: a tragedy waiting to happen  iamanerd | 07/15/09
Tracking.  codeguy007 | 07/15/09
Tracking is NEW?  Spainy53 | 07/16/09
No.  deowll | 07/16/09
But then what?  Calknight | 07/16/09
George Bush or UN?  JDough | 07/15/09
The UN isn't always right.  codeguy007 | 07/15/09
The UN does something / anything right?  Dogbadger | 07/16/09
Not Really!  Calknight | 07/16/09
Both  adr5@... | 07/16/09
RE: RFID passports: a tragedy waiting to happen  morrieg@... | 07/15/09
Lead Lined Passport Folders  bgavin | 07/15/09
RE: RFID passports: a tragedy waiting to happen  davidhite | 07/15/09
RE: RFID passports: a tragedy waiting to happen  markosjal@... | 07/15/09
RE: RFID passports: a tragedy waiting to happen  luis.guembes@... | 07/15/09
And more vulnurable  chrisportela | 07/15/09
dumb idea  adr5@... | 07/16/09
Ummm..Try a google search for RFID Blocking Wallets  CyberCritic | 07/15/09
RFID Blocking Wallets and Passort Covers  paulkmecak | 07/17/09
RE: RFID passports: a tragedy waiting to happen  codeguy007 | 07/15/09
RE: RFID passports: a tragedy waiting to happen  MadWhiteHatter | 07/15/09
RFID implementation  davidlewis7 | 07/15/09
RE: RFID passports: a tragedy waiting to happen  teddly | 07/15/09
Good Advice... Bad Attitude!  TomParris | 07/15/09
RE: RFID passports: a tragedy waiting to happen  jim_d@... | 07/15/09
RE: RFID passports: a tragedy waiting to happen  RAMChYLD | 07/15/09
A recent RFID article  lipl1 | 07/15/09
Re: A recent RFID article  ioot@... | 07/16/09
RE: RFID passports: a tragedy waiting to happen  handryjaya | 07/15/09
Then: Z-Hunting. Now: RFID Crack & Track  ioot@... | 07/16/09
Then: Z-Hunting. Now: RFID Crack & Track  David the Nerd | 07/16/09
Political hacks posing as journalists  syfr | 07/16/09
Ditto  djivan@... | 07/16/09
RE: RFID passports: a tragedy waiting to happen  mbz | 07/16/09
RE: RFID passports: a tragedy waiting to happen  vilppuu@... | 07/16/09
a tragedy  ca1ic0cat | 07/16/09
I'm suprised Zdnet haven't focussed on the Microsoft angle  whisperycat | 07/16/09
RE: RFID passports: a tragedy waiting to happen  jamer123 | 07/16/09
RE: RFID passports: a tragedy waiting to happen  adr5@... | 07/16/09
Utter nonsense  Dan Dengle-23016931076989175935280328352818 | 07/16/09
Agreed  Mercutio_Viz | 07/16/09
RE: RFID passports: a tragedy waiting to happen  michael56555@... | 07/16/09
Need to take the State Department to court over RFID tag destruction rights  Dr_Zinj | 07/16/09
On/Off switch  Alzie | 07/16/09
RFID Passports. Whats the real reason?  jgb_z | 07/16/09
No stupidity exceeds that of government stupidity  Mtn_Man | 07/16/09
Blindly?  Spainy53 | 07/16/09
RE: RFID passports: a tragedy waiting to happen  chermack | 07/16/09
RE: RFID passports: a tragedy waiting to happen  vger_z | 07/16/09
RFID on humans  cas_frezer79@... | 07/16/09
Not sure how to respond...  boothby | 07/16/09
Solution is simple.  agohige | 07/16/09
Classier than Aluminum Foil  mbz | 07/16/09
RE: RFID passports: a tragedy waiting to happen  patbot | 07/16/09
Would Foil act as a shield?  jgwinner | 07/16/09
Shielding  skottieg | 07/16/09
RE: RFID passports: a tragedy waiting to happen  alzie@... | 07/16/09
RE: RFID passports: a tragedy waiting to happen  theguru1995@... | 07/16/09
Of course, but that is unamerican...  Tommy S. | 07/16/09
RE: RFID passports: a tragedy waiting to happen  BRD2 | 07/16/09
RE: don't let it happen to me  vall7744@... | 07/16/09
Sam Rohrer of PA is on top of REAL ID, the same thing  CyberPerk | 07/16/09
RE: RFID passports: a tragedy waiting to happen  kaiakaiak | 07/16/09
well said...  jiagebusen | 07/17/09
Might as well paint your SSN on the side of your car  Aboleyn | 07/16/09
RE: RFID passports: a tragedy waiting to happen  clareJ | 07/16/09
Sit on it  Technogeez | 07/16/09
RE: RFID passports: a tragedy waiting to happen  pragerr | 07/16/09
a new industry is born...  jiagebusen | 07/16/09
RE: RFID passports: a tragedy waiting to happen  kinghitz | 07/16/09
Non-US passports  mgcarley-zdnet | 07/16/09
RE: RFID passports: a tragedy waiting to happen  davelester | 07/17/09
A New Market Opportunity  donden@... | 07/17/09
Already exists  seanferd | 07/17/09
8 years to go - NOT LIKELY !  ausvirgo | 07/17/09
RE: RFID passports: a tragedy waiting to happen  rdhalsteatzd | 07/18/09
RE: RFID passports: a tragedy waiting to happen  rj_wilson@... | 07/18/09
RE: RFID passports: a tragedy waiting to happen  ap.author | 07/18/09
RE: RFID passports: a tragedy waiting to happen  taustin21@... | 07/19/09
RE: RFID passports: a tragedy waiting to happen  asstchief48@... | 07/19/09
RE: RFID passports: a tragedy waiting to happen  chad@... | 07/19/09
Tin Foil  DT2 | 07/20/09
buy or make one  adr5@... | 07/21/09
RE: RFID passports: a tragedy waiting to happen  lucianonote | 07/20/09
The shame is that we *used* to.  jdickey | 07/21/09
RE: RFID passports: a tragedy waiting to happen  Joey1058 | 07/22/09
Then we truly are FUBARed, since...  jdickey | 07/24/09
RE: RFID passports: a tragedy waiting to happen  john.foggitt@... | 07/23/09
Paranoid morons...  tenimotsu | 07/23/09
Sorbonne t-shirts are even worse  Eric957 | 08/03/09
RFID Banknotes  Uncle Stoat | 08/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here