(Mis)Uses of Technology

(Mis)Uses of Technology

by Mike Masnick




RFID Passports... Close, But Not Quite

from the one-more-step-please dept

Last week, we wrote about the new plans by the State Department to put RFID chips in passports, noting that the precautions they took this time around looked much better, and hoped that they would do an adequate job protecting peoples' information. Bruce Schneier has chimed in to say that, indeed, the two big steps they took (shielding and access control) are absolutely steps in the right direction that others should follow, but there's still one more problem they need to fix. The chips broadcast unique IDs to help readers isolate the signal of a single chip, and it's not clear how these unique IDs are implemented. Schneier is afraid that the implementation can lead to vulnerabilities. But, more importantly, seeing that this point was missed, it points out how hard it really is to make things like this truly secure. There's always "something else" that opens you up to security holes, especially when the details of how something is implemented aren't made clear. The worst case scenario is finding out about yet another security vulnerability, well after these passports are out there.

1 Comments | Leave a Comment..

 
 

Reader Comments (rss)

(Flattened / Threaded)

  1. Nov 3rd, 2005 @ 12:56pm

    No Subject Given

    by Anonymous Coward

    unique IDs -- how?

    Simple -- random number generator + database of used numbers = unique ID

    Embed it in the paper of a passport and ship to the printing office.

    When assigned, the code is associated with a person -- just as every US passport issued has a unique passport number on it today.

    Don't everybody freak

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It