SoS at Vara's Nieuwslicht
The SoS group has contributed twice (so far) to the national TV-show Vara's Nieuwslicht. This is a Dutch TV program which shines a scientific light over the news of the week. It used to be hosted by Paul Witteman, but this season Menno Bentveld took over.
The main topic for our contribution was the use of contactless chips. In particular the use of such a contactless chip in the new biometric passport. What are the possibilities and dangers of putting biometric information on a chip that might be readable without the owner knowing it? Of course the passport has some countermeasures that should prevent this kind of attack, but are they strong enough? And what about the national database where these biometric features are collected?
Apart from Bart's conversation with Menno on these issues we also did two demo's. The first demo was taped two days before in Nijmegen where Martijn Oostdijk tried to read the RFID chip which was implented some time ago in Bas Haring's left upper arm at the Baya Beach Club in Barcelona. During this demo Bas and Martijn also discussed some of the good points and some of the risks of using RFID chips on a large scale.
The second demo was about the fact that you can really store a picture on a smartcard and as soon as the card is detected by the reader asks for a secret key to unlock the card. This is basically what happens with the new biometric passport.
More details will be added later...
Prof. Bart Jacobs. was one of the guests in this show. Together with the regular panel of the program he talked about flaws in software. In particular about the possibility to implement flaws on purpose. Together with the Vara the SoS group set up an election to visualize problems like these.
How did it work?
The complete show can be viewed on the Nieuwslicht website.
Downloads
Here you can download the programs being used for the test in the studio. They are written in Java, hence if you want to run these programs you will need a J2SE Java Runtime Environment. (Or a J2SE Software Development Kit.) If you don't have this yet, you can download such a JRE or SDK from Sun. We compiled the programs against j2sdk1.4.2_04.
We offer two versions. Both are available as a .zip file.
Unzip the chosen package and read the README.TXT file to get things started. In particular this file contains a list of valid vote numbers; without them, you won't get very far.
The programs were written by Engelbert Hubbers.