| Image: Unsplash |
The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You'd like to open a bank account? Please come in to our office.”
For this
blog I can still draw on notes I took earlier this year during Security (b)log
LIVE, during our internal ‘Love for Your Profession’ week. The scenario above
was sketched out there too. I sometimes say I get paid to think up doom
scenarios – but you all contribute your fair share too…
Let's
see whether this is actually a realistic scenario. The Netherlands has the
Basisregistratie Personen (the Personal Records Database, kept per
municipality). A copy of that data goes to the Rijksdienst voor
Identiteitsgegevens (RvIG, the national Identity Data Agency). So yes, all the
data you need to produce a passport sits in one place.
That
data is included in the passport in two ways: optically and digitally. The
first is what you see and can read; the second sits on a chip embedded in the
document. That digital data is digitally signed by the government. That
guarantees authenticity and means the data can't be altered without it being
noticed.
Whether
the leaked passport data can actually be used for identity fraud depends on the
purpose. A criminal with the right resources and enough dedication will
undoubtedly manage to produce a document convincing enough to, say, rent a car
– especially if a scan of the original document has also leaked. Checks for
that kind of application tend to be fairly superficial: no one looks at the
security features of the document.
For more
serious applications, such as opening a bank account online, the data on the
chip is checked. That happens via Near Field Communication (NFC). The bank's
app reads the chip directly when you hold your phone against the document. As
the name NFC suggests, this only works over a (very) short distance. As
mentioned, the data on the chip is digitally signed. A forged chip lacks that
signature, so the document fails the check. That effectively debunks the
scenario sketched above. But there is still “room” for abuse wherever checks
rely on the naked eye alone.
Could
you board a plane with such a forged document? That depends on where you're
headed. Within most of Europe (the Schengen countries) you don't pass through
passport control at all; for flights outside that area, the Royal Marechaussee
(the Dutch military police responsible for border control) does check every
traveller's passport. They do that with their own eyes, backed up by an optical
scanner that reads the two lines of text at the bottom of the document and
checks the security features. If you go through an automated gate instead of a
desk, the chip gets read, and the gates also use facial recognition. The odds
of someone slipping through with a fake Dutch passport are probably not that
high.
After
that you reach the gate, where your boarding pass is scanned and ground staff
give your travel document a quick glance. I suspect they're mainly checking
whether the name on both documents matches and whether the photo looks enough
like you. The odds of getting away with a forged document there seem considerably
higher to me.
Would
the Netherlands grind to a halt if the RvIG had a data breach? Probably not
immediately, but it would cause a lot of hassle – both for (legitimate)
passport holders and for the authorities doing the checking: the former group
would feel distrusted, the latter would need to deploy extra capacity for more
thorough checks. At least in places where correctly establishing someone's
identity actually matters. Fortunately, they know that all too well over at the
RvIG.
And in the big bad world…
- a similar leak recently took place in North America.
- banks aren't immune to cybercriminals either.
- you can, of course, also hack an oil tanker.
- police released the audio recording
of the call between Odido and the hacker. ShinyHunters is having a laugh about
it. [DUTCH]
- that voice recording has already yielded 120 tips. [DUTCH]
- Nigerian scammers get spiritual support.
- ChatGPT, Reddit and Roblox now fall under the Digital Services Act, meaning they must comply with EU rules on matters such as the spread of illegal content.
No comments:
Post a Comment