German "secure" ID cards compromised on national TV, gov't buries head in sand

A German TV programme showed hackers from the Chaos Computer Club using off-the-shelf equipment to extract personal information from the government's new "secure" ID card, which stores scans of fingerprints and a six-digit PIN that can be used to sign official documents and declarations.
In an interview with the show, Interior Minister Thomas de Maizière said he saw no immediate reason to act on the alleged security issue.

Meanwhile on Tuesday the Federal Office for Information Security (BSI) rejected the Plusminus' criticism of the new ID card. The agency's personal identification expert Jens Bender said the card was secure and called the combination of an integrated chip with a PIN number a "significant security improvement compared to today's standard process of user name and password."

But a classic Trojan horse program that logs keystrokes remained a threat, he admitted, because users must use keyboards in addition to the scanners.

New government ID cards easily hacked (via /.)

Read more 

Cory Doctorow

Upcoming appearances

* Feb 9, 2012, DeKalb, IL: Day of Doctorow, NIU
* Feb 10-12, 2012, Chicago, IL: Capricon 32
* Feb 13, 2012, Arlington, TX: UT Arlington College of Engineering Distinguished Speaker Series
* Feb 16, 2012, Victoria, BC: 13th Annual Privacy and Security Conference

Recent books:
* Context (essays)
* With a Little Help (short stories)
* For the Win (YA novel)
* Makers (adult novel)

Where not otherwise specified, this work is licensed under a Creative Commons License permitting non-commercial sharing with attribution. Boing Boing is a trademark of Happy Mutants LLC in the United States and other countries.