Prox Card Cloning Update

It has become news that the United States government is planning to use RFID for passports. The ACLU has released several documents authored by GEMPLUS which refer to a security risk known as "skimming". See page 7 of this 12 page document. On page 8 they detail the potential for fraud. GEMPLUS is a large vendor of ID cards. This is an important document as it is the first public vendor statement I am aware of that clearly states RFID can be compromised.

"Skimming" is the technique I discussed earlier as "Bump Cloning" where your access card could be copied without your knowledge. The ACLU is worried about the FBI and violating our privacy by scanning a room for terrorists using this technique. I worry about someone using my electronic credentials to impersonate me.

Is this technology is being incorporated into the diplomatic passports? Just a thought.

The above represents the opinion of George Mallard, P.E.

Copyright 2005, KMS Systems, Inc.
Information current as of April 2, 2005