3 ms·
> Seems doubtful! I expect the forgers used a real signature from another card instead, so it has the right key but the wrong data. Reverse engineering the proc
by Ryan5453 11d ago
> Seems doubtful! I expect the forgers used a real signature from another card instead, so it has the right key but the wrong data. Reverse engineering the process as the author did and making up their own key wouldn't be of any value to the forgers.
This was just bad wording. I meant to say "someone else's key" in the context that it was a key generated by the forgers rather than the state DMV, will update to make it more clear!
> This is not wrong, but should come with a little warning. A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card.
Correct, but simply checking that it matches the front is likely not enough to deter fraud. You could extract the barcode data from a real ID and put it on a physically different (fake) ID with a different photo and it would still return as valid. To detect this you generally would need a higher end solution (IDScan.net/VeriScan's ID authentication solution (yes... the one that just leaked everyone's data), TokenWorks' IdentiFake, IDScience, amongst others) that does the same high resolution UV/IR checks TSA does. But the forgers are good enough now to be able to sometimes pass those scanners too.
- miki123211 11d agoThis is why chip-based IDs are superior, esp. with phones and NFC being ubiquitous. ID chips can't be cloned, so you don't even need photo auth (unless you want to protect against stolen but real IDs).
- simoncion 11d ago> ID chips can't be cloned... ID chips can be manufactured, so they can obviously be cloned. Thinking like yours leads to the asinine situation we saw ten, fifteen years ago where insurers were refusing to pay out vehicle theft claims because "There's no way to clone an RF keyfob or RF immobilizer chip!". Spoiler alert: There were many, many ways to do that.
- SoftTalker 11d agoThere are also many ways to steal a car without having a key at all.
- rcxdude 10d agoYeah, it's more that they can, if designed correctly, be made very difficult to clone. (and that if in the middle is pretty important!)
- amluto 11d agoHow about having the signed data contain a hash of the photo and having some way for the verifier to access the photo (perhaps via an API)? An actual hard-to-clone chip to contain the authority to access the photo would be even better.