Special alloy sleeves urged to block hackers?

July 12, 2009 By TODD LEWAN , AP National Writer Special alloy sleeves urged to block hackers? (AP)

Enlarge

In this, April 22, 2009 photo, Ari Juels, chief scientist and director for RSA Laboratories, holds a Massachusetts public transportation card with an RFID (radio frequency identification) security chip imbedded in it at the RSA Security Conference in San Francisco. (AP Photo/Marcio Jose Sanchez)

(AP) -- To protect against skimming and eavesdropping attacks, federal and state officials recommend that Americans keep their e-passports tightly shut and store their RFID-tagged passport cards and enhanced driver's licenses in "radio-opaque" sleeves.

That's because experiments have shown that the e-passport begins transmitting some data when opened even a half inch, and chipped passport cards and EDLs can be read from varying distances depending on reader techonology.
The cover of the e-passport booklet contains a metallic sheathing that can diminish the distances travel, presumably hindering unwanted interceptions. Alloy envelopes that come with the PASS cards and driver's licenses do the same, the government says.

The State Department asserts that hackers won't find any practical use for data skimmed from RFID chips embedded in the cards, but "if you don't want the cards read, put them in an attenuation sleeve," says John Brennan, a senior policy adviser at the Office of Consular Affairs.

Gigi Zenk, a spokeswoman for the Washington state Department of Licensing, says the envelope her state offers with the enhanced driver's license "ensures that nothing can scan it at all."

But that wasn't what researchers from the University of Washington and RSA Laboratories, a company in Bedford, Mass., found last year while testing the data security of the cards.

The PASS card "is readable under certain circumstances in a crumpled sleeve," though not in a well maintained sleeve, the researchers wrote in a report.

Another test on the enhanced driver's license demonstrated that even when the sleeve was in pristine condition, a clandestine reader could skim data from the license at a distance of a half yard.

Will Americans consistently keep their enhanced driver's licenses in the protective sleeves and maintain those sleeves in perfect shape - even as driver's licenses are pulled out for countless tasks, from registering in hotels to buying alcohol?

The report's answer: "It is uncertain ... "

And when the sleeves come off, "you're essentially saying to the world, 'Come and read what's in my wallet,'" says Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington, D.C.

By obliging Americans to use these sleeves, he says, the government has, in effect, shifted the burden of privacy protection to the citizen.

Meanwhile, researchers have raised other red flags.

- In 2006, a mobile security company, Flexilis, conducted an experiment in which the transponder of a partially opened e-passport triggered an explosive planted in a trashcan when a dummy carrying the chipped passport approached the bin. A video of the experiment was shown that year at a security conference.

Flexilis has suggested that the government adopt a dual cover shield and specifically designed RFID tag that would make the e-passport remotely unreadable until it is fully opened.

No changes have been made to the U.S. e-passport in response, according to the State Department.
- Some RFID critics wonder: Could government officials read the microchips in an enhanced driver's license or passport card by scanning people via satellite or through a cell phone tower network?

The short answer is no - because the chips in PASS cards and EDLs are "passive," or batteryless, meaning they rely on the energy of readers to power up. Passive tags are designed to beam information out 30 feet.

However, research is moving forward to make batteries tinier and more powerful, says Ari Juels, director of RSA Laboratories. A "semi-passive" tag that could transmit into the atmosphere when triggered by a reader "may be feasible at some point," he says.

Separately, a system called STAR, that adapts deep-space communications technologies to read passive tags from distances greater than 600 feet, was announced last year by a Los Angeles startup called Mojix, Inc. It uses "smart antennas" and "digital beam forming" to process signals in four dimensions - time, space, frequency and polarization. Mojix, founded by a former NASA scientist, promotes the technology for supply chain management and asset tracking.

©2009 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 5 /5 (8 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • marjon - Jul 12, 2009
    • Rank: 4 / 5 (1)
    Try a stainless steel wallet:
    http://www.thinkg...ar/9964/
  • MorituriMax - Jul 12, 2009
    • Rank: 2 / 5 (1)
    I'll be interested if someone comes up with a wallet that acts like a farraday cage.
  • physpuppy - Jul 12, 2009
    • Rank: 5 / 5 (3)
    I suppose nowadays it's not enough to wear a tinfoil hat - you need a tinfoil wallet as well!

    I like the James-Bondish reference in the article to the test where an explosive went off when a particular passport was opened slightly...

    In 2006, a mobile security company, Flexilis, conducted an experiment in which the transponder of a partially opened e-passport triggered an explosive planted in a trashcan when a dummy carrying the chipped passport approached the bin. A video of the experiment was shown that year at a security conference.
  • waltaugust - Jul 12, 2009
    • Rank: 5 / 5 (1)
    The special alloy sleeves they are talking about are made by Identity Stronghold. They make the sleeve for the US Passport cards, many state enhanced drivers licenses as well as passport books and credit cards. Yes even new credit cards have RFID chips that give out your credit card number and expiration date. You can find them at www.idstronghold.com
  • x646d63 - Jul 12, 2009
    • Rank: 4 / 5 (1)
    I'm seriously considering building an "attenuation sleeve" to live in.
  • frogz - Jul 13, 2009
    • Rank: not rated yet
    RFID's are a bad idea, period.
  • scpsr1 - Jul 13, 2009
    • Rank: not rated yet
    Just don't keep your wallet anywhere near your groin area if you want children.
  • marjon - Jul 13, 2009
    • Rank: not rated yet
    How many of you concerned about RFID remove your cell phone battery to keep from being tracked?
  • jabo - Jul 13, 2009
    • Rank: not rated yet
    you can smash those rfid chips with a hammer to disable them and officials can still scan the bar code to get the info. just play dumb when they ask you why your passport doesn't 'work'.

July 12, 2009 all stories

Comments: 9

5 /5 (8 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • Shortening Boat Trailer
    created Nov 18, 2009
  • Strain Gage Test Advice
    created Nov 17, 2009
  • How Could I do This? Motor to open and close doors on a timer??
    created Nov 17, 2009
  • More from Physics Forums - General Engineering

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 4 hours ago | popularity 5 / 5 (1) | comments 0

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Analysts say AmEx is most interested in the so-called peer-to-peer services of Revolution

American Express takes aim at PayPal with Revolution

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

With its deal to buy Revolution Money, American Express is taking aim at the growing market for online and alternative payments, in a challenge to recognized leader PayPal, analysts say.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created 16 hours ago | popularity 4.4 / 5 (20) | comments 17

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


Ubisoft steps up videogame fitness with virtual coach

Technology / Software

created 5 hours ago | popularity not rated yet | comments 0

French videogame powerhouse Ubisoft will have a virtual fitness coach whipping Wii users into shape starting Tuesday.


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...