Categories: Technology

“Tough to forge” digital driver’s license is… easy to forge

[ad_1]

“Tough to forge” digital driver’s license is... easy to forge“Tough to forge” digital driver’s license is... easy to forge

In late 2019, the government of New South Wales in Australia rolled out digital driver’s licenses. The new licenses allowed people to use their iPhone or Android device to show proof of identity and age during roadside police checks or at bars, stores, hotels, and other venues. ServiceNSW, as the government body is usually referred to, promised it would “provide additional levels of security and protection against identity fraud, compared to the plastic [driver’s license]” citizens had used for decades.

Now, 30 months later, security researchers have shown that it’s trivial for just about anyone to forge fake identities using the digital driver’s licenses, or DDLs. The technique allows people under drinking age to change their date of birth and for fraudsters to forge fake identities. The process takes well under an hour, doesn’t require any special hardware or expensive software, and will generate fake IDs that pass inspection using the electronic verification system used by police and participating venues. All of this, despite assurances that security was a key priority for the newly created DDL system.

“To be clear, we do believe that if the Digital Driver’s Licence was improved by implementing a more secure design, then the above statement made on behalf of ServiceNSW would indeed be true, and we would agree that the Digital Driver’s Licence would provide additional levels of security against fraud compared to the plastic driver’s licence,” Noah Farmer, the researcher who identified the flaws, wrote in a post published last week.

A better mousetrap hacked with minimal effort

“When an unsuspecting victim scans the fraudster’s QR code, everything will check out, and the victim won’t know that the fraudster has combined their own identification photo with someone’s stolen Driver’s Licence details,” he continued. As things have stood for the past 30 months, however, DDLs make it “possible for malicious users to generate [a] fraudulent Digital Driver’s Licence with minimal effort on both jailbroken and non-jailbroken devices without the need to modify or repackage the mobile application itself.”

DDLs require an iOS or Android app that displays each person’s credentials. The same app allows police and venues to verify that the credentials are authentic. Features designed to confirm the ID is authentic and current include:

  • Animated NSW Government logo.
  • Display of the last refreshed date and time.
  • A QR code expires and reloads.
  • A hologram that moves when the phone is tilted.
  • A watermark that matches the licence photo.
  • Address details that don’t require scrolling.

Surprisingly simple

The technique for overcoming these safeguards is surprisingly simple. The key is the ability to brute-force the PIN that encrypts the data. Since it’s only four digits long, there are only 10,000 possible combinations. Using publicly available scripts and a commodity computer, someone can learn the correct combination in a matter of a few minutes, as this video, showing the process on an iPhone, demonstrates.

ServiceNSW Digital Driver’s Licence proof-of-concept: Brute-forcing PIN.

Once a fraudster gets access to someone’s encrypted DDL license data—either with permission, by stealing a copy stored in an iPhone backup, or through remote compromise—the brute force gives them the ability to read and modify any of the data stored on the file.

From there, it’s a matter of using simple brute-force software and standard smartphone and computer functions to extract the file storing the credential, decrypting it, changing the text, re-encrypting it, and copying it back to the device. The precise steps on an iPhone are:

  • Use iTunes backup to copy the contents of iPhone storing the credential the fraudster wants to modify
  • Extract the encrypted file from the backup stored on the computer
  • Use brute-force software to decrypt the file
  • Open the file in a text editor and modify the birth date, address, or other data they want to fake
  • Re-encrypt the file
  • Copy the re-encrypted file to the backup folder and
  • Restore the backup to the iPhone

With that the ServiceNSW app will display the fake ID and present it as genuine.

[ad_2]
Source link
Admin

Recent Posts

How to Remove Burnt-on Grease from Your Oven

Burnt-on grease isn't just an eyesore. It stinks up the kitchen and makes cooking a…

4 weeks ago

Air India: A Journey Through Time

Hey there! Ready to embark on a historical journey with Air India? Whether you're a…

1 month ago

The Rise of Smart Altcoins: How 2025 Is Reshaping the Crypto Hierarchy

In 2017, altcoins were seen as experimental side projects to Bitcoin. By 2021, they became…

2 months ago

5 Services That Can Transform Your Shopping Center in Las Vegas into a Must-Visit Destination

Shopping centers in Las Vegas have a unique opportunity to stand out by offering not…

2 months ago

Levitra Dosage: Guidelines for Safe Use

Levitra, a widely recognized medication for treating erectile dysfunction (ED), has proven to be a…

3 months ago

Practical Tips for Carpet Cleaning on a Budget

Have you ever looked down at your carpet and wondered if there’s a budget-friendly way…

4 months ago