Home Office denies ID card hack claims
By Richard Goodwin,
The government’s “unforgeable” ID card was hacked in 12 minutes by security researcher Adam Laurie this week, according to a Daily Mail report.
Laurie was able to make a complete clone of the card using a mobile phone with chip reading capabilities and a basic laptop PC in 12 minutes, said the Daily Mail report.
Once the chip had been breached, Laurie was able to alter the person’s name, physical data, and finger prints, as well as switch the “not entitled to benefits” section to “entitled to benefits”, reported the Mail.
The Mail also reported that Laurie was able to add a security note into the card that said: “I am a terrorist, shoot on sight.”
A spokesperson from the Home Office said: "This story is rubbish. We are satisfied the personal data on the chip cannot be changed or modified and there is no evidence this has happened.”
The ID cards use a radio frequency identification (RFID) chip for data storage.
The government claimed that this technology could never be cloned or faked, despite widespread reports concerning potential vulnerabilities with the technology.
“If the Government is serious about preventing identity theft, then it really has to do better than this,” said Laurie in the Daily Mail report.
"The identity card includes a number of design and security features that are extremely difficult to replicate. Furthermore, the card readers we will deploy will undertake chip authentication checks that the card produced will not pass,” said a Home Office statement.
NO2ID today condemned the Home Office for knowingly making 'ID theft' easier, ignoring dangerous vulnerabilities in the ID card system.
“This shows up the big con. The Home Office doesn't really care about 'ID theft', or it wouldn't be pushing technology that any competent crook can subvert,” said Phil Booth, national coordinator of NO2ID.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
- Sticking security where the sun don't shine
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Virgin remains on top in broadband speed race
- Will someone rid me of these troublesome Macs?
- MPs call for infection detection database
- A data shock warning for Orange customers
- What can Intel bring to the smartphone market?
- T-Mobile announces 'UK's first' fully unlimited deals
- Nokia Lumia 710 review
- Cisco launches turbo-powered wireless access point
- Facebook unveils $10bn IPO plans
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.
![My email address is [CENSORED]](http://cdn.itpro.co.uk/images/front_picture_library_IT_Pro/dir_227/it_photo_113980_36.jpg)





Facts?
Does ITPro have any editorial comment on this story? Not that I don't trust the Mail tho it's interesting that DM chose to change the benefits section. Is the 'expert' a known expert? Is RFID likely to be sufficient protection? How does DM know what was done? Did they have an expert watching the expert? John E
By Ip5_b81abc7d93c on Friday Aug 7
At least hacker seems to exist!
Hi, I was also curious about the hacker so a quick google mentioned he gave a presentation at this year's Black Hat, and has a site on hacking passports and oyster cards, rfidiot dot org, which looks convincing to me but not my field so hey what do i know! I'll leave it to the experts to decide if the claims are true!
By Steve_Bentley on Tuesday Aug 11
US view.
There is an interesting article in Zdnet blogs [url=http://blogs.zdnet.com/storage/?p=565&tag=nl.e550] here[/url] which I feel the government should note.
By Mike_Bear on Tuesday Aug 11