Risk
2/9/2009
11:40 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Sleeve Protects IDs From 'War Cloning'

Identity Stronghold's solution shown to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve

There are numerous recent news reports about passport card cloning or "war cloning". The reports describe how a security researcher mounted an RFID reader and antenna in his car and drove around San Francisco capturing via radio waves the ID codes of several people's passport cards and enhanced drivers licenses. This is definitely a security and privacy issue. What many do not know is that federal and state officials were aware of this possibility. This very privacy issue is why the US State Department and state motor vehicle departments send out a Secure Sleeve' with every passport card or enhanced drivers license shipped. The enclosed instructions urge card holders to keep their passport cards in the protective privacy sleeve when not in use. This not only protects the sensitive electronics in the cards but blocks distance reading of any data contained on the RFID chip inside the cards.

The Secure Sleeve has been certified by the U.S. Government as an electromagnetically opaque sleeve and shown in testing by multiple, independent organizations to be effective in preventing communications with RFID or contactless smart cards contained within the sleeve. Based on these test results and the experience of having millions of Secure Sleeves in the market, Identity Stronghold believes the cards reportedly cloned by the researcher were not in the Secure Sleeve provided with the card. Had the cards been contained within the sleeve, they would not have been detected during the experiment.

Contactless and RFID technologies are being productively used in passports, credit cards, passport cards, government identification cards, company identification cards, enhanced drivers licenses, student identification cards, transit cards, TWIC cards and a growing list of other applications. However, this experiment is the latest in a list of events that demonstrate how the information stored within a card may be compromised if not protected with the appropriate layers of digital and physical security. The U.S. Government and many State Governments have taken a lead role in specifying the use of the Secure Sleeve or Secure Badgeholder as a physical security measure to complement the digital security measures incorporated into the cards. Other issuers of contactless and RFID enabled credit, payment, and identification cards such as banks, commercial security integrators, businesses, and international governments are beginning to follow the U.S. Government's proactive lead by providing their customers and citizens with protective sleeves as well. Further, many security-savvy consumers have taken the step of buying their own Secure Sleeves online at www.idstronghold.com.

The reported cloning of the passport cards should be viewed as a reminder that each entity involved in development, issuance, and use of such cards must take the proper steps to secure the information held within the card.

About Identity Stronghold Identity Stronghold (www.IDstronghold.com), based in Sarasota, Florida, is the leading supplier of physical security products for RFID and contactless smart cards. The Company's Secure Sleeve and Secure Badgeholder product lines combine innovative design and advanced materials to deliver the highest levels of form, function, and security.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.