Trail of Bits reposted this
Suppose someone records your passport's chip being read at an airport, and a month later gets a copy of your photo page from a hotel that kept a scan. Can they decrypt the recording? If the chip used the older Basic Access Control protocol (BAC), yes. The password that protects the conversation is printed on the page. We modeled this, and twelve other questions about electronic passports, in Verifpal. The models cover BAC and its replacement PACE, the four ways a reader and chip check each other, tracking a passport between two readers, and using a passport to identify yourself to a website. PACE uses the same printed password as BAC, but the session keys also depend on fresh Diffie-Hellman secrets. When we leak the password after the inspection, Verifpal finds no way to decrypt the recording. Passive Authentication shows that the issuing country signed the data. It doesn't show that the data came from the chip in front of the reader. Copy the files and the signature still checks. If a phone asks a passport to sign a challenge from a website, a dishonest site can pass along a challenge it got from your bank. The passport never stays out of your hands, but the chip was never told which service you meant to use. ICAO will require PACE in newly issued passports from 1 January 2027 and exclude BAC from them from 1 January 2028. Passports issued before then will stay in use until they expire. The starting point was Joop van de Pol's article on electronic passports for Trail of Bits. All thirteen models are in the Verifpal repository, with each model's assumptions written at the top. These are bounded searches. https://lnkd.in/ekRTKGvc