Storm building over RFID-enabled passports
With just months before full U.S. adoption, a raging debate
Network World - As the U.S. government prepares to complete a conversion to the controversial RFID-based electronic passports, traditional paper-only IDs are still available for a few months to those listening to the raging debate over security and privacy concerns swirling around the electronic documents.
Many security experts are still questioning whether e- passports, which have a 10-year life span, have enough security built in to survive a decade of hackers and technology advancements while protecting e-passports users from data theft, identity theft and other security and privacy intrusions.
"If the government is right, this will be the first time in the history of mankind that a perfectly secure application will be produced. Of course it will be hacked," says Bruce Schneier, the noted security guru, author and CTO of Counterpane Internet Security.
The government thinks otherwise and has already started to issue the cards from two of its regional offices in Colorado and Washington, D.C.
"Let me be blunt," says Frank Moss, deputy assistant secretary for passport services at the Department of State. "We have obviously gone through an elaborate process here, and, I think, with the exception of a relatively small number of people, have addressed most people's security concerns."
Moss, along with other government and military officials, has been using an RFID-enabled passport since last year.
The e-passport is a contact-less smartcard with a secure microprocessor that employs a passive radio frequency to transmit data over an encrypted wireless link to a reader. The passive technology requires a reader to power the chip and is different from an RFID vicinity chip used for tracking items from a distance.
A technology called Basic Access Control (BAC) uses an electronic key, derived from machine-readable data printed on the passport's page, to unlocked the data on the chip, and a digital signature protects the integrity of the digital data.
The chip, which is embedded inside the cover of the passport, contains only a duplicate copy of the passport photograph and the printed data. The digital data is intended to prevent forgeries by allowing inspectors to compare the printed and digital data.
"This is not a security device for you, it is a security device for the government," says Schneier. "As long as you don't benefit from this why should you be a guinea pig?" Schneier recommends people get new passports, which are valid for 10 years, without RFID technology while they are still available. The government does not plan on recalling passports before their expiration date.
But once regional passport offices convert to e-passports, the traditional paper-only versions will not be available. The Colorado office converted on Aug. 4, while the Special Issuance Agency in Washington is completing a conversion. The other 15 offices will convert during the next five to six months.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts