Keys Not Included: recovering the signing keys for US driver's license barcodes
Summary
This article discusses methods to recover the signing keys for US driver's license barcodes, potentially highlighting security vulnerabilities in the identification system.
Similar Articles
America's Driver's License Breach Is a National Security Disaster
A dark web service named Nexus is offering access to over 153 million U.S. and Canadian driver's licenses, likely from a breach at identity verification company IDScan, raising national security concerns due to potential use in espionage and identity theft.
FBI Probes Service Selling 153M+ Drivers Licenses
The FBI is investigating a dark web service called Nexus that sells digital scans of over 153 million U.S. and Canadian drivers licenses, potentially sourced from a breach at a major identity verification company.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
This Unit 42 research discloses three novel attacks against passwordless authentication using Google's synced passkey ecosystem, showing how malware can take over passkey-protected accounts, bypass user verification, and extract private keys.
Your Passport Scan Is a Liability: Moca Network on Identity for Humans and AI Agents
Repeated passport scans pose privacy and security risks, and reusable, user-controlled credentials can reduce these risks while extending verifiable authority to AI agents.
New Pass-ta-key attack reveals all the things we didn't know about passkeys
A new attack called Pass-ta-key shows that passkeys stored in Google Password Manager on Windows can be extracted by malware, revealing that passkeys are generally stored locally rather than in TPM hardware. The article clarifies that this is not a novel attack and that the Windows platform is the main exception.