Risk
2/9/2009
11:40 AM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

Sleeve Protects IDs From 'War Cloning'

Identity Stronghold's solution shown to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve

There are numerous recent news reports about passport card cloning or "war cloning". The reports describe how a security researcher mounted an RFID reader and antenna in his car and drove around San Francisco capturing via radio waves the ID codes of several people's passport cards and enhanced drivers licenses. This is definitely a security and privacy issue. What many do not know is that federal and state officials were aware of this possibility. This very privacy issue is why the US State Department and state motor vehicle departments send out a Secure Sleeve' with every passport card or enhanced drivers license shipped. The enclosed instructions urge card holders to keep their passport cards in the protective privacy sleeve when not in use. This not only protects the sensitive electronics in the cards but blocks distance reading of any data contained on the RFID chip inside the cards.

The Secure Sleeve has been certified by the U.S. Government as an electromagnetically opaque sleeve and shown in testing by multiple, independent organizations to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve. Based on these test results and the experience of having millions of Secure Sleeves in the market, Identity Stronghold believes the cards reportedly cloned by the researcher were not in the Secure Sleeve provided with the card. Had the cards been contained within the sleeve, they would not have been detected during the experiment.

Contactless and RFID technologies are being productively used in passports, credit cards, passport cards, government identification cards, company identification cards, enhanced drivers licenses, student identification cards, transit cards, TWIC cards and a growing list of other applications. However, this experiment is the latest in a list of events that demonstrate how the information stored within a card may be compromised if not protected with the appropriate layers of digital and physical security. The U.S. Government and many State Governments have taken a lead role in specifying the use of the Secure Sleeve or Secure Badgeholder as a physical security measure to complement the digital security measures incorporated into the cards. Other issuers of contactless and RFID enabled credit, payment, and identification cards such as banks, commercial security integrators, businesses, and international governments are beginning to follow the U.S. Government's proactive lead by providing their customers and citizens with protective sleeves as well. Further, many security-savvy consumers have taken the step of buying their own Secure Sleeves online at www.idstronghold.com.

The reported cloning of the passport cards should be viewed as a reminder that each entity involved in development, issuance, and use of such cards must take the proper steps to secure the information held within the card.

About Identity Stronghold Identity Stronghold (www.IDstronghold.com), based in Sarasota, Florida, is the leading supplier of physical security products for RFID and contactless smart cards. The Company's Secure Sleeve and Secure Badgeholder product lines combine innovative design and advanced materials to deliver the highest levels of form, function, and security.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.