3 ms·
Here's what I think they really did. From this; "Each one of these files is supposed to be protected with a special digital key, so that if anyone attempts to
by stevecooperorg 17y ago
Here's what I think they really did. From this;
"Each one of these files is supposed to be protected with a special digital key, so that if anyone attempts to change it, the card would be identifiable as a fake to any official with a digital chip reader."
The information (name, address, etc) is stored as plaintext, then signed with a private key (http://en.wikipedia.org/wiki/Digital_signature http://en.wikipedia.org/wiki/Digital_signature) to prove it's a real government card.
What the reporter and his friend did was read the plaintext (which is exactly what is intended), then choose some new data and sign it with their own private key, claiming they had 're-locked' the card. But of course they haven't -- the digital signatures will be different. When the cards are used (validated against the corresponding public key) you'd find that the signature was invalid.
I think what they've proved is that plaintext is readable, and that if they had a government private key, they could add a digital signature. And that it's easy to produce cards with new data, so long as no-one verifies the digital signature.