‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. dmurray · · focus · HN ↗
    This is a great investigation but I have two small nits:

    > the ZNB field is not empty and not garbage: it contains a well-formed 71-byte DER ECDSA signature, correctly Ascii85-encoded, with the right prefix and a plausible length. But it fails the cryptographic check instantly, because it was signed with somebody else's key.

    Seems doubtful! I expect the forgers used a real signature from another card instead, so it has the right key but the wrong data. Reverse engineering the process as the author did and making up their own key wouldn't be of any value to the forgers.

    > I built a little demo to check the signatures across California, New York, and Virginia: take a picture of the barcode and check it here.

    This is not wrong, but should come with a little warning. A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card.

    1. jpalawaga · · focus · HN ↗
      most bars have scanners that will warn if the same id is scanned twice. it means that someone producing fake ids would at least need a repository of valid barcodes such that two purchasers wouldn't experience the birthday problem trying to get into a bar.
      1. dataflow · · focus · HN ↗
        What do you mean by scanned twice? Can't someone leave and reenter?
        1. advisedwang · · focus · HN ↗
          Maybe it has a short TTL? So it would catch a group of people that all bought fake IDs from the same place.
          1. moduspol · · focus · HN ↗
            All except the first person to get through. :)
          2. Ryan5453 · · focus · HN ↗
            Generally it's configurable. The one that comes to mind first is TokenWorks's Anti-Passback feature which says "Set your custom timeframe (1 hour to 7 days)"

            <a href="https:&#x2F;&#x2F;www.idscanner.com&#x2F;product-features&#x2F;anti-passback&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.idscanner.com&#x2F;product-features&#x2F;anti-passback&#x2F;

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.