Hackers crack new biometric passports

Hi-tech biometric passports used by Britain and other countries have been hacked by a computer expert, throwing into doubt fundamental parts of the UK's £415m scheme to load passports with information such as fingerprints, facial scans and iris patterns.

Hi-tech biometric passports used by Britain and other countries have been hacked by a computer expert, throwing into doubt fundamental parts of the UK's £415m scheme to load passports with information such as fingerprints, facial scans and iris patterns.

Speaking at the Defcon security conference in Las Vegas, Lukas Grunwald, a consultant with a German security company, said he had discovered a method for cloning the information stored in the new passports. Data can be transferred onto blank chips, which could then be implanted in fake passports, a flaw which he said undermined the project.

The revelation also casts another shadow over the government's plan for a national ID card, which would contain much of the same information.

"The whole passport design is totally brain damaged," Mr Grunwald told Wired.com. "From my point of view all of these [biometric] passports are a huge waste of money - they're not increasing security at all." Since March anyone applying for a UK passport has been issued with a biometric version, which contains physical identification information.

Mr Grunwald said his discovery was made within two weeks of first attempting to copy the data, and the equipment used cost $200 (£105). It is believed the hacking principle could be applied to any new passport issued in Britain, the US and other countries. But the findings do not mean that all biometric information could be faked or altered by criminals. Although the data held on a passport chip is not encrypted, it is not yet possible to change the cloned data without alerting the authorities.

The Home Office said yesterday that the UK biometric passport was one of the most secure in the world and while it might be possible to copy the chip data it was not possible to modify or manipulate any of the data. Last week the House of Commons' science and technology committee called on the government to reconsider the technology behind the biometric ID scheme.

Contributor

Bobbie Johnson, technology correspondent

The GuardianTramp

Related Content

Biometric scans for passports from April
· ID card vote paves way for detailed national database
· Start of £5.8bn computer procurement project

Alan Travis, home affairs editor

14, Feb, 2006 @1:31 AM

Recall demand after cloning of new biometric passports
The government was facing demands to recall 3m micro-chipped biometric passports last night after a Guardian investigation which found that they could be electronically attacked and cloned with a £174 microchip reader.

Steve Boggan

17, Nov, 2006 @10:09 AM

Foreigners living in Britain face compulsory biometric ID cards
· Photo and fingerprint scheme for 700,000
· Visitors to be screened before flying to UK

Alan Travis, home affairs editor

20, Dec, 2006 @12:12 AM

Hackers jailed for worm that caused £5.5m damage across internet

· Ingenious program hijacked US defence site
· Virus exploited known weakness in Microsoft

Owen Bowcott

08, Oct, 2005 @9:30 AM

Letters: Fears of biometric identity blunders
Letters: The Liberal Democrat home affairs spokesman, Nick Clegg, who is demanding a recall, clearly does not understand much about passport security (Recall demand after cloning of new biometric passports, November 17).

22, Nov, 2006 @12:19 AM

Hackers crack Microsoft software codes

Hackers have broken into Microsoft's computer network and gained access to blueprints of its latest software, the company admitted yesterday. Initial investigations suggest that the hackers could have links with, or be based in, St Petersburg, Russia.

Duncan Campbell in Los Angeles

28, Oct, 2000 @12:02 AM

Letters: ID cards trigger biometric alert
Letters: In your FAQ What now? section (Bio-metric scans for passports from April, February 14) the question is posed: "Won't ID cards be forged like all the other plastic? Your answer says: "Anyone trying to register twice with the same biometric will trigger an alert." But no such information about the responsiveness of the system has been provided by the government.

17, Feb, 2006 @1:48 AM

Article image
How tiny Estonia stepped out of USSR's shadow to become an internet titan

The European country where Skype was born made a conscious decision to embrace the web after shaking off Soviet shackles
Eesti keel | Estonian language version

Patrick Kingsley

15, Apr, 2012 @5:51 PM

Ben Goldacre: Now for ID cards - and the biometric blues

Ben Goldacre: Sometimes just throwing a few long words about can make people think you know what you're talking about

Ben Goldacre

24, Nov, 2007 @12:05 AM

Strike to delay issue of biometric passports
People applying for new biometric passports will face delays after a decision by thousands of civil servants to stage a 24-hour strike and week-long work to rule over pay.

David Hencke

10, Oct, 2006 @11:18 AM