Saturday, 11 August 2007 11:00

New passport readers have security issues

Written by 

Wired ran a story describing Lukas Grunwald's Defcon talk on an attack on airport passport readers. After extracting data from the (read-only) chip in a legitimate passport, he placed a version of the data with an altered passport photo (JPEG2000 is used in these chips) into a writable chip. The altered photo created a buffer overflow in two RFID readers he tested, causing both to crash. Grunwald suggests that vendors are typically using off-the-shelf JPEG2000 libraries, which would make the vulnerability common.

Read the article at Wired.com

blog comments powered by Disqus
Read 1085 times Last modified on Sunday, 06 November 2011 22:57