Risk
2/9/2009
11:40 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Sleeve Protects IDs From 'War Cloning'

Identity Stronghold's solution shown to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve

There are numerous recent news reports about passport card cloning or "war cloning". The reports describe how a security researcher mounted an RFID reader and antenna in his car and drove around San Francisco capturing via radio waves the ID codes of several people's passport cards and enhanced drivers licenses. This is definitely a security and privacy issue. What many do not know is that federal and state officials were aware of this possibility. This very privacy issue is why the US State Department and state motor vehicle departments send out a Secure Sleeve' with every passport card or enhanced drivers license shipped. The enclosed instructions urge card holders to keep their passport cards in the protective privacy sleeve when not in use. This not only protects the sensitive electronics in the cards but blocks distance reading of any data contained on the RFID chip inside the cards.

The Secure Sleeve has been certified by the U.S. Government as an electromagnetically opaque sleeve and shown in testing by multiple, independent organizations to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve. Based on these test results and the experience of having millions of Secure Sleeves in the market, Identity Stronghold believes the cards reportedly cloned by the researcher were not in the Secure Sleeve provided with the card. Had the cards been contained within the sleeve, they would not have been detected during the experiment.

Contactless and RFID technologies are being productively used in passports, credit cards, passport cards, government identification cards, company identification cards, enhanced drivers licenses, student identification cards, transit cards, TWIC cards and a growing list of other applications. However, this experiment is the latest in a list of events that demonstrate how the information stored within a card may be compromised if not protected with the appropriate layers of digital and physical security. The U.S. Government and many State Governments have taken a lead role in specifying the use of the Secure Sleeve or Secure Badgeholder as a physical security measure to complement the digital security measures incorporated into the cards. Other issuers of contactless and RFID enabled credit, payment, and identification cards such as banks, commercial security integrators, businesses, and international governments are beginning to follow the U.S. Government's proactive lead by providing their customers and citizens with protective sleeves as well. Further, many security-savvy consumers have taken the step of buying their own Secure Sleeves online at www.idstronghold.com.

The reported cloning of the passport cards should be viewed as a reminder that each entity involved in development, issuance, and use of such cards must take the proper steps to secure the information held within the card.

About Identity Stronghold Identity Stronghold (www.IDstronghold.com), based in Sarasota, Florida, is the leading supplier of physical security products for RFID and contactless smart cards. The Company's Secure Sleeve and Secure Badgeholder product lines combine innovative design and advanced materials to deliver the highest levels of form, function, and security.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7441
Published: 2015-05-29
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

CVE-2014-9727
Published: 2015-05-29
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

CVE-2015-0200
Published: 2015-05-29
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

CVE-2015-0751
Published: 2015-05-29
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

CVE-2015-0752
Published: 2015-05-29
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?