<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Engadget - Comments for Dutch RFID e-passport cracked -- US next?</title>
<link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link>
<description>Engadget Comments for Dutch RFID e-passport cracked -- US next?</description>
<image>
<url>http://www.engadget.com/media/feedlogo.gif</url>
<title>Engadget</title>
<link>http://www.engadget.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2012 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[Riscure press release link is broken due to some extra < br > tags (see comment #6). The working link is:<br><a href='http://www.riscure.com/news/passport.html'>http://www.riscure.com/news/passport.html</a>]]></description><dc:creator><![CDATA[Juha-Matti Laurio]]></dc:creator><pubDate>Feb 6th 2006 6:38PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[This news is actually old, from July 2005!<br>These guyes presented this thing first at The What The Hack conference back them. This is not new. <br><br>Check those slides from What The Hack:<br><br><a href='http://wiki.whatthehack.org/images/2/28/WTH-slides-Attacks-on-Digital-Passports-Marc-Witteman.pdf<br><br>'>http://wiki.whatthehack.org/images/2/28/WTH-slides-Attacks-on-Digital-Passports-Marc-Witteman.pdf<br><br></a>]]></description><dc:creator><![CDATA[Jan Dev]]></dc:creator><pubDate>Feb 3rd 2006 9:32AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[would it be that hard to change the encryption before they start the roll out?]]></description><dc:creator><![CDATA[mike]]></dc:creator><pubDate>Feb 3rd 2006 9:33AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[THey better... THO that reminds me... I must RENEW my passport BEFORE october...]]></description><dc:creator><![CDATA[jmg_bt21]]></dc:creator><pubDate>Feb 3rd 2006 9:39AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[I'm Dutch and i saw the tv show where they demonstrated it. You can watch it too by clicking this link: <br><a href='http://cgi.omroep.nl/cgi-bin/streams?/tv/vara/nieuwslicht/bb.20060127.asf<br><br>if'>http://cgi.omroep.nl/cgi-bin/streams?/tv/vara/nieuwslicht/bb.20060127.asf<br><br>if</a> you skip to 6:20 you can see how it's done.<br><br>The hacker and female voice explains they can hack it beacause the passport numbers are sequential and are linked to the expire date. That way the can narrow the range and brute force it. That way it will take 3 hours to decypher a rfid passport chip. <br><br>The Dutch goverment also noticed this and they are willing to change the numbering of the passport, but since such a decision will take some time and new RFID passports are ariving in august 2006, it will not come in time. So the new dutch passoport will be weakly encrypted/protected.]]></description><dc:creator><![CDATA[Arnoud Ringoir]]></dc:creator><pubDate>Feb 3rd 2006 9:43AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[Of course, but what's to prevent someone from hacking that encryption as well.<br><br>There needs to be some sort of "off" switch so that the RFID isn't broadcasting 24/7 to anybody listening.  (A la one of those fancy Hallmark Cards that plays music when you open the card, the RFID "enables" itself when you open the passport book)<br><br>Again, the simple rule of encryption is that every code/password/algorythm can be hacked with enough time, software and network passwords will disable after so many failed attempts, thus restricting the access to the possible hack. <br><br>RFID is intrisically unsafe because there is no mechanism to disable itself, it just sits there like Forrest Gump at the bus stop talking to anybody who will listen.<br><br>Wonderful security there Mr. President.]]></description><dc:creator><![CDATA[BlueLightBandit]]></dc:creator><pubDate>Feb 3rd 2006 9:47AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[<br>July 28, 2005:<br><a href='http://www.riscure.com/news/passport.html<br><br>'>http://www.riscure.com/news/passport.html<br><br></a>]]></description><dc:creator><![CDATA[Jan Dev]]></dc:creator><pubDate>Feb 3rd 2006 9:48AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[This research by Riscure is actually quite old. It has been done in July 2005. <br><br>It was presented at the What The Hack conference. People have no memory.<br><br>You can download the presentation of this hack here:<br><br><a href='http://wiki.whatthehack.org/images/2/28/WTH-slides-Attacks-on-Digital-Passports-Marc-Witteman.pdf'>http://wiki.whatthehack.org/images/2/28/WTH-slides-Attacks-on-Digital-Passports-Marc-Witteman.pdf</a>]]></description><dc:creator><![CDATA[Jan Dev]]></dc:creator><pubDate>Feb 3rd 2006 9:50AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[<br>     They will continue to go forward with the idea. ]]></description><dc:creator><![CDATA[James]]></dc:creator><pubDate>Feb 3rd 2006 10:21AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[also worth noting: german passports with rfid won't be reissued if the<br>rfid part is damaged, this may be the same with other countries as well<br>due to personel shortages at passport offices. paranoid? stick your<br>passport in the microwave for a few seconds or simply bend it gently in<br>your hand a few dozen times to break the rfid antenna. alternatively, wrap your rfid based passport in foil, tin foil hat style.<br><br>side<br>note: if you are a french citizen and were lucky enough to think of<br>renewing your passport before october of 2005 and you have the machine<br>readable two lines on the bottom edge of your passport required by the<br>united states, you are good to travel without a rfid passport for ten<br>years.<br><br>also see harald welte's research pertinent to most rfid passports:<br><br><a href="http://openmrtd.org/about.html%3Cbr%3Ehttps://events.ccc.de/congress/2005/fahrplan/events/769.en.html%3Cbr%3Ehttp://gnumonks.org/%7Elaforge/weblog/linux/mrtd/%3Cbr%3E%3Cbr%3Echeers,%3Cbr%3Efbz">http://openmrtd.org/about.html<br>https://events.ccc.de/congress/2005/fahrplan/events/769.en.html<br>http://gnumonks.org/~laforge/weblog/linux/mrtd/</a><br><br>cheers,<br>fbz]]></description><dc:creator><![CDATA[fabienne]]></dc:creator><pubDate>Feb 3rd 2006 10:35AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA["There needs to be some sort of "off" switch so that the RFID isn't broadcasting 24/7 to anybody listening."<br>-BlueLightBandit<br><br>This is not possible, since RFIDs do not 'broadcast'anything. That's the whole point behind them, and hence why they don't require a power supply. They simply bounce signals in a sophisticated way.<br><br>That being said, your idea has merit, and could work if there is a way to make passport books fitted with sheilding to keep the RFIDs from being detected until they are opened. Albeit, it would be expensive.]]></description><dc:creator><![CDATA[john c]]></dc:creator><pubDate>Feb 3rd 2006 10:36AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[Flawed math. Haven't we heard this lame-ass excuse before? Why don't the 'professionals' get it? Does 'zero defects' ring any bells?<br><br>I'm waiting for someone to rig up a backpack with a directional antenna that can read RFID passports and IDs across the room. Or airport.]]></description><dc:creator><![CDATA[Jerry Whiting]]></dc:creator><pubDate>Feb 3rd 2006 10:38AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[The even scarier part is they clearly did not use even the most convenient cracking options.  With one intercepted ID, they cracked in 3 hours.  Even if the algorithm were improved, one could easily stand near a tourist group from a single country and intercept several.  Using the commonality would also allow a reduction of cracking time even assuming the numbering scheme is eventually fixed.<br><br>This is a Bad, Bad, Bad idea promoted by the governments paranoid about their citizens in such a way to make the paranoia of citizens against government and other citizens a valid fear.  Neo-Orwellian.]]></description><dc:creator><![CDATA[Bill]]></dc:creator><pubDate>Feb 3rd 2006 10:51AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[This is probably a stupid question, but why RFID?  What's the advantage over a "Smart Card" chip?  One that would require actual contact?]]></description><dc:creator><![CDATA[Ladderless]]></dc:creator><pubDate>Feb 3rd 2006 11:58AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[#10--><br><br>Just checked travel.state.gov and it indicates there will be shielding on all U.S. passports that will protect data from "skimming" as long as the passport remains closed. As well, all new U.S. passports (beginning 30 December 2005 in most areas!) will be "e-passports"<br><br>]]></description><dc:creator><![CDATA[AH]]></dc:creator><pubDate>Feb 3rd 2006 12:01PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[Who cares about strong encryption or zero defects - the DMCA protects our passports...<br><br>I'm sure RFID is being used instead of a SmartChip because of marketing and reduced costs due to mass production - they probably forgot to add in the cost of shielding though. A SmartChip wouldn't help much anyway, as anyone who has had their CC data dup'ed by restaurant waitstaff can attest.<br><br>I agree with the idea behind all this, that analog passports don't really offer much in the way of a guaranteed ID, but an easily duplicated digital system  sure isn't going to help.]]></description><dc:creator><![CDATA[Mike]]></dc:creator><pubDate>Feb 3rd 2006 1:15PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[I just renewed my passport so I'm safe for 10 years, at least.  While I'm not exactly confident about it, I'm hopeful that they'll work out all the issues by then and will have either a) secured this system better, or b) ditched it completely.  One good thing is that the US government has shown that while they may be pretty clueless about the technological issues behind this scheme, they're at least open to change when convinced of the negative aspects of it (they've made changes to alleviate concerns before).  So hopefully in the 10 years I have to renew my passport again, they'll do something about this sorry system they've got planned.<br><br>Otherwise I will seriously be wrapping my next passport in tinfoil.  Look for an explosion in the aftermarket "protective passport case" market, with all sorts of new materials designed to thwart identity thieves.<br>]]></description><dc:creator><![CDATA[Jeff]]></dc:creator><pubDate>Feb 3rd 2006 3:30PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[I just renewed my passport so I'm safe for 10 years, at least.  While I'm not exactly confident about it, I'm hopeful that they'll work out all the issues by then and will have either a) secured this system better, or b) ditched it completely.  One good thing is that the US government has shown that while they may be pretty clueless about the technological issues behind this scheme, they're at least open to change when convinced of the negative aspects of it (they've made changes to alleviate concerns before).  So hopefully in the 10 years I have to renew my passport again, they'll do something about this sorry system they've got planned.<br><br>Otherwise I will seriously be wrapping my next passport in tinfoil.  Look for an explosion in<br>the aftermarket "protective passport case" market, with all sorts of new materials designed to thwart identity thieves.]]></description><dc:creator><![CDATA[Jeff]]></dc:creator><pubDate>Feb 3rd 2006 3:32PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[" I just renewed my passport so I'm safe for 10 years, at least."<br><br>Are you sure? What makes you think that the gov't will not just decide in 2 years that RFID-less passports are no longer accepted? You know, in the name of fighting terrrrrists.]]></description><dc:creator><![CDATA[consumer_q]]></dc:creator><pubDate>Feb 3rd 2006 5:48PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[" I just renewed my passport so I'm safe for 10 years, at least."<br><br>Are you sure? What makes you think that the gov't will not just decide in 2 years that RFID-less passports are no longer accepted? You know, in the name of fighting terrrrrists.]]></description><dc:creator><![CDATA[consumer_q]]></dc:creator><pubDate>Feb 3rd 2006 5:52PM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[here's a scary but realistic terrorism senario that got the US gov'ts attention:<br><br>(from dailykos; <a href='http://www.dailykos.com/story/2006/2/3/162911/3140'>http://www.dailykos.com/story/2006/2/3/162911/3140</a>)<br><br>To his credit, UnderSecretary of state Frank Moss came to the International Conference on Computers, Freedom, and Privacy last sporing to face the critics of the US RFID passport scheme. During his panel, the ACLU's Barry Steinhart demonstrated a reader effective at 10 inches.<br><br>Afterwards, in the hallway, photo (That's me in the background.) EFF's John Gilmore explained how the range could be extended to 10 feet. Travel writer Ed Hasbrouck then laid out a scenario in which terrorists used an off the shelf RFID reader to detect the presence of a US Passport holder on a bus in Beirut, triggering a pre-installed bomb. <br><br>This apparently impressed Moss, who delayed introduction of the chipped passports originally scheduled for last June, so that they could be made with wire mesh shielding to prevent them from being read when closed. He also directed the data be encrypted, bringing us to the flaw identified in the diary.<br><br>A Senator YOU can afford<br>$1 contributions only.<br>Masel for Senate <br>1214 E. Mifflin St.<br>Madison, WI 53703]]></description><dc:creator><![CDATA[Ryan]]></dc:creator><pubDate>Feb 4th 2006 10:15AM</pubDate></item><item><title><![CDATA[Comments on Dutch RFID e-passport cracked -- US next?]]></title><link>http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</link><guid isPermaLink="true">http://www.engadget.com/2006/02/03/dutch-rfid-e-passport-cracked-us-next/</guid><description><![CDATA[Instead of throwing all the data across with the RFID transfer (address, picture, etc), why don't they use a unique key that is looked up in a central database on the airport computers? That way, even if someone decodes it and gets the hash, they'll still need all the information in order to dupe a passport.]]></description><dc:creator><![CDATA[Ross]]></dc:creator><pubDate>Feb 4th 2006 1:37PM</pubDate></item></channel></rss>
