Blots of Info

Protecting A Passport RFID Signal

Today I picked up my new Dutch passport, which includes an RFID chip. This chip contains sensitive information about the owner (or rather user, since the official owner is the Dutch government) of the passport, in this case me. The information can be read in a contactless way, i.e. from a distance, without a need to insert the passport in some kind of machine.

Although secure messaging is used to protect the wireless communication between RFID tag and scanner, it is still a wireless signal. This means the tag can always be attacked by a wireless signal. All you need is to be in close proximity to the passport. A simple attempt to contact and read the chip doesn't succeed in actually reading or deciphering the contents, it is still a major risk. With an old fashioned passport, I could easily determine who I gave access to the information contained therein. I would lock up the physical passport, I would only willingly open it to people so they could see the information. And if someone took my passport for a while (to make a photo copy or whatever), I would know. With the new chip, I have no way of knowing if someone managed to access my data. So what to do about this?

I sent a mail to ask my local passport office for help on this and I wonder if I will hear about any way to protect the chip from being read. The information leaflet that comes with the passport did not contain any information on this. There are some manufacturers selling special wallets or cages that are supposed to block access to the chip, such as the one by DIFRwear. $18 doesn't sound too bad to give it a try. It seems there are locations in the Netherlands where one can read the contents of the chip. Perhaps I can use one of those to see if the case actually works.

posted at 21:46:34 on 11/22/06 by RB - Category: Security - 1 Trackback - karma: 3 [+/-]

item rate
Total Votes: 3 - Rating: 3.00

Please rate this item (0=bad, 5=very good):

Previous 5 posts This post was displayed 4573 times. back

Trackback

Blots of Info
E-Passport Cloning: In the continuing story of worrying about the risks of electronic passports, there are some minor developments. I actually had access to a passport/rfid reader over the weekend. That is, I went...
18/12/06
Use this TrackBack url to ping this item (right-click, copy link target). If your blog does not support Trackbacks you can manually add your trackback by using this form.

Comments

EK wrote:

You could prolly make an envelope that
the passport and be slipped into/out of from aluminum foil that would
protect it from unwanted scanning. Now,
that's not as glamorous as a leather
wallet with the electro-magnetic wave
disrupting material built into it, but
it is a potential alternative.

11/23/06 16:28:03

RB wrote:

I haven't been able to find out for certain whether aluminum foil is enough to block the signal, but it's certainl worth a shot. I did read about someone who made a duct tape wallet, including the foil version, but that seemed too difficult to me. An envelope might be something I can actually manage.

11/24/06 21:48:23

Enter email address to subscribe to comment on this item
Click here to manage subscription

Add Comments

Comments must be approved before being published. Thank you!

HTML tags will not be parsed. Type URLs just as "http://www.golb.org".

Note: Comments that I consider to be spam will be removed. The same goes for comments that I consider to be insulting (by my own standards) to other participants.