New Electronic Passports Vulnerable to Hackers


Recommended Posts

The State Department will soon begin production of an electronic passport card that security specialists and members of Congress fear will be vulnerable to alteration or counterfeiting.

The agency has contracted with L-1 Identity Solutions Inc. to produce electronic-passport cards as a substitute for booklet passports for use by Americans who travel frequently by road or sea to Canada, Mexico and the Caribbean.

About the size of a credit card, the electronic-passport card displays a photo of the user and a radio frequency identification (RFID) chip containing data about the user. The State Department announced recently that it will begin producing the cards next month and issue the first ones in July.

Security specialists told The Washington Times that the electronic-passport card can be copied or altered easily by removing the photograph with solvent and replacing it with one from an unauthorized user.

James Hesse, former chief intelligence officer for the Immigration and Customs Enforcement Forensic Document Laboratory, which monitors fraudulent government documents, said the card should have been designed with a special optical security strip to make it secure and prevent counterfeiting. The selection of a card with an RFID chip is "an extremely risky decision," Mr. Hesse said in an interview.

"The optical strip has never been compromised," he said. "It's the most secure medium out there to store data."

Joel Lisker, a former FBI agent who spent 18 years countering credit-card fraud at MasterCard, said the new cards pose a serious threat to U.S. security. "There really is no security with these cards," he said.

Mr. Lisker, a consultant to a competitor for the electronic-passport card contract, said the State Department's selection of the RFID card shows it favors speedy processing at entry points more than security. He charged that the department "will not make changes until it is satisfied that compromises are occurring on a regular basis."

The State Department rejected a more secure card because it is "surrendering to speed over security, essentially creating new vulnerabilities. ... It will not take long for the bad guys to figure out which ports have readability and which do not," he said.

Steve Royster, a State Department spokesman, declined to comment.

Another State Department official, however, said the agency thinks the RFID passport card is secure.

"The passport card is the result of an interagency effort to produce the most durable, secure and tamper-resistant card for the American public using state-of-the-art, laser-engraving and security features," said the official, who spoke on the condition that he not be identified.

Members of Congress have raised concerns about the new card in a bipartisan letter to Secretary of State Condoleezza Rice and Homeland Security Secretary Michael Chertoff.

"We have serious concerns regarding the final card chosen for the Passport Card," the April 25 letter states. It was written by Reps. Brian P. Bilbray, California Republican, and Christopher Carney, Pennsylvania Democrat. Seventeen Republicans and one Democrat signed the letter.

"Each card will carry the same rights and privileges of the U.S. passport book with the exception of international air travel. As such, the cards will be used not only to cross the border, they will also be used throughout the interior United States as proof of citizenship and identity in everyday transactions; as a proof of identity in [Transportation Security Administration] lines, to enter federal buildings, to engage in financial transactions, and to obtain driver's licenses," the letter said.

The lawmakers noted that the bipartisan Sept. 11 commission final report stated that "travel documents are as important as weapons" for global terrorists.

In a separate letter to the State Department on May 2, Mr. Carney asked for a briefing on the passport cards, saying "we need to have confidence that these cards cannot be compromised by terrorists, drug smugglers, human traffickers and others who would break our laws and do us harm."

The State Department considered a prototype passport card designed by General Dynamics that used the optical security strip but rejected the option, preferring a passport card that contains an RFID chip made in Europe.

An optical security strip appears as a dark, 1-inch-wide line on the top of a card. Close inspection of the strip reveals ultra-high resolution images that security specialists say cannot be counterfeited and can be identified easily by border officials. Security specialists say the strip is needed to boost the security features of the RFID chip in the passport cards.

L-1 Identity Solutions announced in March that it won the State Department contract, which has an estimated value of $107 million over five years.

The cards are intended for use by travelers in U.S. border communities as a "less expensive and more portable alternative to the traditional passport book," according to the State Department Web site. The cards are not valid for entry into the United States by travelers arriving by aircraft.

Mr. Hesse, the former Forensic Document Laboratory intelligence chief, stated in a 2006 letter to Mr. Chertoff that he is "seriously alarmed" by the use of RFID technology on the passport card. He also noted that the U.S. permanent residence and border-crossing cards that use the optical security strip are being phased out.

"With my 30-plus years experience in the field of travel and identity document security, this is, in my opinion, a shortsighted and extremely risky decision," Mr. Hesse stated.

Because the passport card will be widely accepted as an official travel document for entry into the country, "this card will definitely become the document of choice for counterfeiters," Mr. Hesse said.

"Why would a non-U.S. citizen even bother to counterfeit the green card? The PassCard makes you a U.S. citizen and gives you the access to and/or the privileges mentioned above," he stated. "Therefore, it should be imperative that the U.S. government produce and provide the most secure card as possible."

Brian Zimmer, a former House Judiciary Committee investigator, said the new passport cards lack sufficient security features because the State Department did not demand them of the contractor, L-1 Identity Solutions.

"It's critical that the passport card be made highly counterfeit-resistant," said Mr. Zimmer, now head of the Coalition for a Secure Driver's License. "The State Department should address these deficiencies and change the contract so the manufacturer can address them." Mr. Zimmer was for a time a consultant on the passport card to a subcontractor of General Dynamics.

Frank Moss, a former State Department passport office official who is now a consultant to L-1, said the State Department and the Department of Homeland Security set the specifications for the contract.

"It was government security experts who determined the specifications," Mr. Moss said in an interview. "The optical stripe, quite honestly, was never used as a stand-alone security feature."

The federal government plans to supply only 39 ports of entry with equipment capable of checking the validity of the cards with electronic scanners. More than 300 other entry points will not have the RFID chip readers.

Kelly Klundt, a spokeswoman for U.S. Customs and Border Protection, said the deployment of passport card readers to the largest and busiest 39 border-entry points was intended to expedite travel. The more than 300 remaining points of entry without passport card scanners are in remote locations, and officials will visually inspect passport cards at those entry points, she said.

"Just because there aren't RFID readers at every entry point doesn't mean we don't inspect [the passport cards]," she said.

source

This is news? RFID chips are insecure by design. Using it for authentication of anything is a bad idea.

Oh Electric Bolt, you can't store anything other than a unique number on the chips, the current generation is very limited, hopefully they'll make them with larger and read/write memory in the future.

Why don't they store the picture on the chip... So when your going for your plane or wherever, they scan it and the picture appears on the screen...

Our electronic IDs in Belgium do that. It defies the point of such cards, if you're still keeping "analog" data.

32 bytes? More like a couple of k, plenty of space for a compressed image. Maybe a chip for tracking a parcel has limited capacity, but not e-passport ones.

You're right. The chips in passports have 64kb (Wow. That's a LOT for these kind of chips.)

They must be expensive as hell....

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft is bringing a much-needed Recap app to Teams, here is a first look by Usama Jawad Microsoft Teams is heavily used in work and school environments, and perhaps one of its core but extremely useful features is the ability to record meetings. In past years, Microsoft has further improved upon this functionality by integrating AI, but you do need a Microsoft 365 Copilot license to leverage most, if not all, all of those capabilities. Now, the Redmond tech firm is making another significant enhancement in the area of Teams meeting recordings. Up until now, if you wanted to access Teams recordings, you had to arduously locate the meeting invite and navigate to the dedicated tab, or go to the cloud storage location such as a SharePoint site. This was a rather overwhelming activity, especially if you don't remember the name of the meeting or the meeting occurred quite a while ago. Microsoft is now attempting to solve this problem through a dedicated Recap app that consolidates all your recordings. This centralized experience will allow users to find all recordings from the past 30 days and also offer access to other related services such as transcripts and AI-powered summaries. Customers will have the option to search for recordings, filter them, and review multiple meetings by generating AI-powered podcast-style recaps. The Recap app will list all available recordings in both thumbnail and list views. The former is shown below: And here is how Teams users with a Microsoft 365 Copilot license can select multiple recordings to generate a podcast-style audio recap: Microsoft has emphasized that the Recap app is pre-installed in Teams but it will not be pinned by default. Users will able to navigate to the Teams app store from the left rail, and pin it from the apps section. It will be enabled by default for all users once it becomes available. It's worth noting that while Teams recordings and transcripts can be accessed by all users governed by existing permissions, AI-powered features like intelligent summaries, audio recaps, and video recaps will require a Microsoft 365 Copilot license. The Recap app will be generally available to Teams users on Windows, Mac, and the web by the end of next month, with mobile support coming soon.
    • It's so stupid that you have to "enroll" in these extended updates.
    • Helium Browser 0.13.6.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.6.1 changelog: c6feb7e0 revision: bump to 6 (#2015) 03a16cfa merge: update to chromium 149.0.7827.200 (#2014) d447f889 merge: update ungoogled-chromium to 149.0.7827.200 8f30897f Update to Chromium 149.0.7827.200 1772f7ce bump-platform: check if b/s/chrome exists instead of just b/s/ (#2003) Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Too late for a slightly older computer I had that didn't meet the hardware requirements for Windows 11 but had great hardware. I installed ubuntu on that thing and gave to a friend's kid.
  • Recent Achievements

    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
    • First Post
      Kolakid60 earned a badge
      First Post
    • Week One Done
      xvvxcvv earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      425
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      149
    4. 4
      Steven P.
      72
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!