Saturday, November 18, 2006

Insecure Passports

Why mixing poor security design with a new technology the bureaucrats don’t understand and combining them with highly important, personally-identifying, required travel documents is a really, really bad combination

Six months ago, with the help of a rather scary computer expert, I deconstructed the life of an airline passenger simply by using information garnered from a boarding-pass stub he had thrown into a dustbin on the Heathrow Express. By using his British Airways frequent-flyer number and buying a ticket in his name on the airline’s website, we were able to access his personal data, passport number, date of birth and nationality. Based on this information, using publicly available databases, we found out where he lived, his profession, all his academic qualifications and even how much his house was worth.

It would have been only a short hop to stealing his identity, committing fraud in his name and generally ruining his life.

Great news then, we thought, that the UK had just begun to issue new, ultra-secure passports, incorporating tiny microchips to store the holder’s details and a digital description of their physical features (known in the jargon as biometrics). These, the argument went, would make identity theft much more difficult and pave the way for the government’s proposed ID cards in 2008 or 2009.

Today, some three million such passports have been issued, and they don’t look so secure. I am sitting with my scary computer man and we have just sucked out all the supposedly secure data and biometric information from three new passports and displayed it all on a laptop computer.

I have, of course, mentioned how the US is switching to RFID passports in the near future. Also, how to make a RFID jammer… for what good it will do you.

No comments: