The NFC seal publishes its own key. What does that actually buy? #122
andrei-chernikov
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
The NFC seal is the strongest binding ODP offers between a passport and a physical object. It is also the part where the specification is least comfortable, and it says so in its own text.
Here is the shape of it. The chip is an NXP NTAG 424 DNA. Its native security is symmetric — chip and phone share a secret key and prove to each other that they both know it. There is no per-chip private key that signs a challenge verifiable against a public key on-chain. So for the check to be public, the key has to be public: ODP publishes the 16-byte EV2 key inside the passport's
nfcanchor, where everyone can read it.Which means a forger who reads the passport can program another NTAG 424 with the same key, and it will pass.
What the check does still buy
That blocks the cheap attacks, which are the common ones. It does not block a forger who is willing to buy chips and program them.
The questions
Nothing here is a settled position. The current model is written down as the best available option, not as a good one — SPEC §6 states the limits in its own text.
All reactions