CNNMoney.com
Companies Economy International Corrections Pre-market Trading After-hours Trading Winners/Losers/Actives Bonds Currencies Commodities World Markets Money Magazine Real Estate Taxes Jobs Ask the Expert Money 101 Autos Mutual Funds The Help Desk Loan Center Best Places to Live Ask the Expert Ultimate Guide to Retirement Retirement Calculators Best Funds Best Places to Retire Fortune Brainstorm Tech Apple 2.0 Blog Big Tech Blog Sectors and Stocks Tech Talk Resource Guide Small Business Makeovers Questions & Answers Small Business Video 100 Best Places to Launch FSB 100 Fortune Small Business Fortune 500 Brainstorm Tech Investing Management C-Suite Rankings Main Create Portfolio Edit Portfolio Create Alerts Edit Alerts

e-Passports get hacked in new security threat

Researcher finds another vulnerability in RFID-passports, analysts see potential for trouble.

By Chris Zappone, CNNMoney.com staff writer

NEW YORK (CNNMoney.com) -- As the nation grapples with difficulties getting new passports, a technology researcher has found another problem with the radio frequency ID technology the new documents carry.

Computer security expert Lukas Grunwald cloned and manipulated the content of an RFID passport, then used the hacked e-Passport to crash the machine needed to read it.

retail_rfid_tag_upc.03.gif
darington_forbes.03.jpg
Lukas Grunwald of DN-Systems Enterprise Internet Solutions

Grunwald says that although the passport wasn't American the threat certainly extends to American passports, which use similar technology.

RFID technology combines silicon chips with antennas to make data accessible via radio waves. It's already a $650 million industry, according to ABI Research, which expects the market to more than triple by 2011.

Technologists, however, have insisted that RFID technology as implemented in the U.S. Passport is not secure and cannot assure privacy.

The U.S. government began rolling out RFID-chipped E-passports last year over the objections of numerous security experts.

The RFID passport is "fundamentally insecure by design," Grunwald said. The vulnerability could enable a person "to crash the reading machine at an airport or to manipulate it in a nasty way so that a forged passport could be accepted," he said.

Industry representatives disputed the conclusion of the work.

"I don't know if there is any credibility in this story," said Randy Vanderhoof, executive director of the Smart Card Alliance, who said he would hold off any judgment until he was more familiar with the claims.

Vanderhoof did point out, however, that Grunwalk was using a German passport with a fingerprint biometric.

"In the U.S. we're not using a fingerprint biometric," he said.

The State Department did not respond to a request for comment.

The U.S. e-Passport uses a digital image of the passport photograph as the biometric identifier, according to the State Department Web site.

Paul Proctor of technology research group Gartner said the vulnerability that Grunwald discovered is, like many exploits of RFID technology, "low probability but high impact."

The problems with securing information on RFID are "real" and "well-known," Proctor said, who called Grunwald's work "sound."

"If the government discovers a cloned passport, it will be stuck with millions of insecure passports. RFID will be in there but just ignored," he said.

But in order for the government to act, it "will have to catch someone cloning it in a nefarious way." Then Proctor predicts the whole RFID infrastructure (passports, readers, etc) would become null and void for the government.

"Governments aren't going to respond to a researcher but to a baddie," Proctor said.

Grunwald is undaunted. He says he is "shocked at how naive the industry - specifically the security document industry is - going into this field and trying to implement security that puts us at risk."

Grunwald will discuss the vulnerability Saturday at the DefCon 15 hacker convention in Las Vegas this weekend.

DefCon is an annual convention attended by hackers, corporate IT security professionals and federal authorities from around the world. Top of page

Sponsors
© 2009 Cable News Network. A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Privacy Policy
Copyright © 2009 BigCharts.com Inc. All rights reserved. Please see our Terms of Use.
MarketWatch, the MarketWatch logo, and BigCharts are registered trademarks of MarketWatch, Inc.
Intraday data provided by Interactive Data Real-Time Services and subject to the Terms of Use.
Intraday data is at least 20-minutes delayed. All times are ET.
Historical, current end-of-day data, and splits data provided by Interactive Data Pricing and Reference Data.
Fundamental data provided by Morningstar, Inc..
SEC Filings data provided by Edgar Online Inc..
Earnings data provided by FactSet CallStreet, LLC.