Attention readers: This blog has moved to a new home at https://chenghlee.wordpress.com/.

Tuesday, February 23, 2010

So Elvis is dead...

But at least his passport lives on:

In the name of improved security a hacker showed how a biometric passport issued in the name of long-dead rock 'n' roll king Elvis Presley could be cleared through an automated passport scanning system being tested at an international airport.

Using a doctored passport at a self-serve passport machine, the hacker was cleared for travel after just a few seconds and a picture of the King himself appeared on the monitor's display.

Van Beek said: "What we did for that chip is create passport content for Elvis Presley and put it on a chip and sign it with our own key for a non-existent country. And a device that was used to read chips didn't check the country's signatures."

So, the ability to enter a country using an electronic passport is essentially dependent on trusting a certificate authority whose public key we don't have? I feel so much safer now...

No comments: