|
|
|
|
|
by mirages
659 days ago
|
|
This is at best another forensic tool (unlocking the TPM of a locked laptop/phone for prosecution) and at worst a red herring for security flag. - Clone a passport -> why cloning if you can issue new ones - getting risked being detected while using a clone (2 entries in 2 different countries, and you also need to look like the person) not to mention you have to destroy the passport - Phone enclaves -> see above - Crypto -> Hardware wallets should be kept on eye as badly as your normal wallet - SIM Cards -> Swapping is faster, or if you're the the gov, just an intercept warrant will do the trick - Laptops -> see above - EMV Chips -> If you have those skills and money, I don't think you'll lose time on cloning credit/debit cards |
|
Well... not really. ICAO compliant passports do not require storing a photo embedded in the chip, as long as you can forge the physical part of the passport (or obtain blanks) you just need the digital certificates from a "donor" passport of John Doe, print "John Doe" and his personal data (birth day/place, nationality, issuance/expiry data) on the human readable and MRZ fields, but crucially the photo of the person using the forgery.
Also, there are no centralized, cross country stores of entry/departure. Lots of places don't even register it for visa-free border crossings.
Some national ID documents, e.g. the Croatian national ID card "osobna iskaznica", do store a photo embedded in the chip, so that indeed restricts a forgery from being used by a non-lookalike.