S'pore: Biometric passports are secure

By Vivian Yeo, ZDNet Asia
Tuesday, August 15, 2006 08:12 PM

SINGAPORE--The country's immigration authority, which has started to issue biometric passports, says fears that e-passports can be hacked are unfounded.

Commenting on a recent report that a German researcher had demonstrated that passports equipped with radio frequency identification (RFID) tags could be cloned, an ICA spokesperson noted in an e-mail that the claims "have not been supported by other experts".

She added: "The Singapore Biometric Passport complies with the recommendations and requirements laid down by the International Civil Aviation Organization. These include security standards established to ensure the integrity of passports."

Smart card vendor Gemalto has also urged governments not to worry about the security features of e-passports.

"The contactless smart card technology chosen for electronic passports is very different from the RFID technology used for inventory tracking, which do not require high levels of security and privacy protection," noted Martin McCourt, president of South Asia at Gemalto, in an e-mail response to queries from ZDNet Asia.

Gemalto supplied the contactless smart card technology for Singapore's e-passport rollout, and more recently secured a win with the U.S. Government Printing Office, which will on behalf of the U.S. Department of State incorporate the contactless technology in all new U.S. passports issued in 2007.

According to McCourt, the passport information in an e-passport cannot be changed. This means that immigration control authorities reading the information stored on the chip can determine the wrongful use of another person's chip information by verification through physical scrutiny. In addition, because information on the chip is digitally signed by the issuing country's passport authority, any attempts to create fake passport credentials will be detected, he pointed out.

New features, higher price
According to a statement issued on Jul. 25 by Singapore's Immigration and CheckPoints Authority (ICA), the country's new biometric passport or BioPass will cost S$80 (US$50.15) for walk-in applications at ICA's office, and S$70 (US$43.88) for online and mail applications. The new rates represent an increase of about 33.3 percent for applications in person, and 40 percent for applications via post or the Internet.
The increase in Singapore's passport price is almost comparable to the fare hike in the U.K. adult e-passport, which crept from 42 pounds (US$76.74) to the current 51 pounds (US$93.19), and is slated to rise again to 66 pounds (US$120.60) on Oct. 5.
In line with ICAO requirements, ICA will not allow for changes to the holder's particulars, including the photograph, once the BioPass is issued. The BioPass holder will have to apply for a new passport if he needs to update any of his personal particulars.

McCourt's views echo that of Randy Vanderhoof, executive director of the Smart Card Alliance, a non-profit association representing over 100 organizations from various sectors. In a statement last week, Vanderhoof called reports of the so-called vulnerability "untrue and demonstrate a lack of understanding" of how the multiple security layers in place work in the new e-passport system.

"Even if someone could copy the information on your e-passport chip, it doesn't achieve anything because all of the information is locked together in such a way that it can't be changed," he said. "It's no different than someone stealing your electronic passport and trying to use it. No one else can use it because your photo is on the chip and they're not you."

Even as experts argue that an e-passport cannot be cloned in its entirety, a Japan-based researcher has voiced out concerns about the risk of data security breaches. Achmad Rully, research associate at the Waseda University Media Network Center, said in an e-mail interview with ZDNet Asia that it appears to be "too early" to introduce e-passports, as "research about privacy protection is not yet adequate".

Rully plans to speak on this topic at the Bellua Cyber Security Asia 2006 conference in Jakarta, Indonesia, later this month. He will also demonstrate, using the Indonesia e-passport launched in February 2006, how a bearer's privacy can be compromised.

Said Rully: "How can we assume that someday government data protection cannot be breached? If government protection is breached, then our non-revocable private data will be in the wild. And somebody could pretend to be [any of] us using their sophisticated fake ID. "[Taken to] the extreme, if a government introduces biometric passports with our non-revocable private data inside the passport, it means that the government is making a time bomb for us," he added.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Beyond the identity risk, what about the risk of targetted assasination as showcased in this video story? www.zdnetasia.com... isn't this a big enough risk? I dont hear any comments from any governments, be it US or Singapore on this matter.. Maybe the journalist can do us a moral favour by posing this question to the relevant authority. I'm really interested to know what is the answer.
Posted by Kim on Wednesday, August 16 2006 10:57 AM


Tech Jobs Now!

Search for your ideal tech job:

Create your own yum repository

Open Source

Learn how to create your own yum repository with the createrepo tool. One thing it allows you to do is distribute specialized packages within an organization.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web