6 ms·
ePassports use public key cryptography to sign them. I don't know if the picture is in the ePassport data, but I believe that there's an approximation of a low
by sargun 3y ago
ePassports use public key cryptography to sign them. I don't know if the picture is in the ePassport data, but I believe that there's an approximation of a low resolution version.
The ICAO even maintains its own sort-of-PKI system: https://www.icao.int/Security/FAL/PKD/Pages/default.aspx https://www.icao.int/Security/FAL/PKD/Pages/default.aspx
I believe that the standard can be adopted by anyone (national IDs, etc...).
- lxgr 3y agoIt's definitely possible. The picture is statically signed, and the smartcard chip in the passport can perform dynamic authentication on top of that, proving physical possession. What's missing for this to be an actual remote ID scheme is checking the passport for being reported as stolen, as well as authentication of the person presenting it (e.g. using a PIN or local biometry). Otherwise, anybody could wave your passport over a reader and open a bank account etc. in your name. For example, Germany does have a (national) remote/online ID scheme on top of an ICAO-compliant (in-person identification only) smartcard-based ID card using a 6-digit PIN.