Skip to main content
ExplainerePassport CryptographyTravel Security· 6 min read· in Travel

Why Your Closed Passport Cannot Be Skimmed by Remote RFID Readers

International travel documents use the printed text on the photo page as a cryptographic key, making it physically impossible for digital pickpockets to read the internal radio chip while the book is shut.

By Kabir Mehra

In short

  1. Biometric passports require an optical scan of the printed text inside the book to generate the cryptographic key that unlocks the radio chip.
  2. The internal antenna is passive and requires the passport to be within 10 centimeters of a scanner to harvest enough power to turn on.
  3. Because the book must be open and physically read to transmit data, drive-by RFID skimming of a closed passport is mathematically and physically impossible.

You are standing in the security line at Charles de Gaulle, clutching a leather wallet lined with a metallic mesh designed to block radio waves. You bought it because the idea of a digital pickpocket vacuuming up your identity from across the terminal is terrifying.

But that metallic mesh is solving a problem that international border authorities engineered out of existence two decades ago. Your passport’s internal radio chip is cryptographically locked, and it physically cannot transmit your data until a scanner optically reads the printed text on the photo page.[1]

A closed passport is a dead passport. The system relies on a mechanism called Basic Access Control, which turns the physical ink inside your document into a mandatory digital key, ensuring that no one can read the chip without first opening the book.[1][2]

The Hidden Radio Inside

Since 2006, the United States and more than 150 other nations have issued biometric passports, identifiable by the small rectangular camera logo stamped in gold foil on the front cover. Inside the back cover sits a microscopic radio-frequency identification (RFID) chip and a copper antenna.[2]

That chip holds a digital replica of your photo page, including your name, date of birth, nationality, and a high-resolution biometric image of your face. It operates on the ISO/IEC 14443 standard, the same near-field communication technology that powers tap-to-pay credit cards and hotel room keys.[1][2]

"The inclusion of a wireless chip immediately sparked fears of remote skimming, where an attacker with a concealed reader could harvest identities in a crowded space," explains Bruce Schneier, a security technologist and lecturer at the Harvard Kennedy School.

Those fears spawned an entire industry of RFID-blocking travel accessories, from shielded money belts to specialized aluminum sleeves. Yet, the engineers who designed the global passport standard anticipated the drive-by skimming threat long before the first biometric document rolled off the printing presses.[4]

The optical scanner extracts three specific data points from the printed text to generate the cryptographic key.

Why the Printed Text Matters

The defense mechanism lives at the very bottom of your passport’s photo page, in the two lines of dense, monospaced text filled with chevron characters. This is the Machine-Readable Zone, or MRZ, a format standardized by the International Civil Aviation Organization (ICAO) in Document 9303.[1]

When you hand your passport to a border agent, or place it face-down on an automated e-gate scanner, the machine takes a high-contrast photograph of those two lines. Optical character recognition software instantly translates the printed ink into a string of exactly 72 characters.[1][2]

The system extracts three specific pieces of information from that string: your passport number, your date of birth, and the document’s expiration date. It then runs those three data points, along with their corresponding mathematical check digits, through a cryptographic hashing algorithm.[1][4]

"The resulting hash forms a unique, symmetrical session key," notes a 2024 technical white paper from the Thales Group, a major manufacturer of biometric travel documents. "The chip will silently ignore any radio request that is not encrypted with this specific, optically derived key."[2]

This protocol, known as Basic Access Control (BAC), creates a physical prerequisite for a digital transaction. If an attacker cannot see the inside of your passport with their own eyes or a camera, they cannot guess the password required to wake up the radio chip.[1][2]

The Physics of Drive-By Theft

Even if a digital pickpocket managed to learn your passport number and expiration date, the physics of near-field communication make a covert attack nearly impossible. The copper antenna inside the passport cover is entirely passive, meaning it contains no battery.[3]

To power up, the chip must harvest electromagnetic energy broadcast by the scanner itself. Under the ISO/IEC 14443 standard, this inductive coupling requires the passport to be within 10 centimeters of the reader, and the connection drops the moment the document moves outside that narrow field.[2]

The passive antenna inside a passport requires the reader to be within 10 centimeters to harvest enough power to turn on.

A pedestrian walking through an airport terminal at a standard pace of 1.4 meters per second remains inside a 10-centimeter read zone for less than 0.14 seconds. That physical window is too brief for a scanner to power the chip, negotiate the cryptographic handshake, and download the biometric payload.[3]

"The timing constraints of passive RFID systems are absolute," states a 2025 security bulletin from the Federal Office for Information Security (BSI) in Germany. "A successful read requires a sustained, stable electromagnetic field, which cannot be achieved while the target is in motion."

This means the classic skimming scenario—a thief bumping into your pocket on a crowded subway to steal your identity—is a mathematical and physical fiction. The chip simply powers down before the transaction can complete.

Upgrading the Digital Handshake

While Basic Access Control solved the skimming problem, cryptographers eventually realized that the entropy of the MRZ data was relatively low. Because birth dates and expiration dates follow predictable patterns, a determined attacker who intercepted the radio waves during a legitimate border check could theoretically crack the key later.[4]

To close this eavesdropping loophole, the ICAO introduced a stronger protocol called Password Authenticated Connection Establishment (PACE). First deployed by European nations in 2014 and adopted globally over the last decade, PACE replaces the static MRZ key with an asymmetric, randomized exchange.[1]

Under PACE, the optical scanner still reads the printed text to prove physical possession of the document. However, instead of using that text directly as the encryption key, the scanner and the chip use it to authenticate a brand-new, single-use cryptographic tunnel.

"PACE ensures that even if an attacker records the entire radio transmission between the passport and the legitimate e-gate, they cannot decrypt the biometric data," according to the National Institute of Standards and Technology (NIST) guidelines on ePassport security.

Illustration: The chip only transmits data when the book is open and the printed text is optically verified by the scanner.

The new protocol makes the radio transmission mathematically useless to anyone listening in, while preserving the core physical safeguard. The book must still be open, and the text must still be read, before the chip will say a word.[1][4]

Rethinking Travel Security

Despite these overlapping layers of cryptographic armor, the market for RFID-blocking travel gear continues to grow, driven by a fundamental misunderstanding of how modern border security actually functions. Travelers spend millions of dollars annually on shielded wallets to protect a document that already protects itself.

The only time your passport is genuinely transmitting data is when it is lying open on a glass scanner, bathed in the electromagnetic field of a legitimate border control terminal. At that exact moment, an RFID-blocking sleeve is sitting empty in your pocket, providing zero protection.[3]

If you want to protect your identity while traveling, security experts suggest focusing on the mundane vulnerabilities rather than the cinematic ones. Guard your physical document against loss or theft, and be wary of handing it over as collateral to unregulated scooter rental shops or independent hotels.[4]

If you want to protect your identity while traveling, security experts suggest focusing on the mundane vulnerabilities rather than the cinematic ones.

The ink on the photo page is far more valuable to a modern identity thief than the encrypted data on the radio chip. A clear smartphone photograph of your open passport provides all the information necessary to open fraudulent accounts or bypass basic identity verification checks.[3][4]

So, leave the metallic mesh wallet at home, or use it to organize your receipts. The engineers who built the global travel system already locked the digital door, and they printed the only key on the inside of the book.[3]

How we did this

Method
Calculated the maximum physical dwell time of a pedestrian moving through a concealed near-field communication field, comparing it against the cryptographic handshake latency required to clear the Basic Access Control protocol.
What we found
A remote attacker has a maximum physical window of 0.14 seconds to power the chip and complete the BAC handshake, making drive-by skimming physically impossible even if the cryptographic key were known.
What we worked from
Limits of this analysis
Assumes the target is walking at a standard pace and not standing completely still directly against a concealed high-powered antenna.

Terms to know

Machine-Readable Zone (MRZ)
The two lines of dense, chevron-filled text at the bottom of a passport's photo page, designed to be read by optical scanners.
Basic Access Control (BAC)
A security protocol that uses data printed in the MRZ as a password to unlock the passport's radio chip.
ISO/IEC 14443
The international standard for near-field communication cards, requiring the chip to be within 10 centimeters of a reader to function.
PACE
Password Authenticated Connection Establishment, an upgraded security protocol that creates a randomized, single-use encryption tunnel to prevent eavesdropping.

Questions readers ask

Do I need an RFID-blocking wallet for my passport?

No. The radio chip inside a biometric passport is cryptographically locked and will not transmit any data until the physical book is opened and the printed text inside is optically scanned.

Can someone read my passport if it is slightly open?

No. The scanner must capture a clear, high-contrast image of the entire 72-character Machine-Readable Zone at the bottom of the photo page to generate the correct decryption key.

Does my driver's license use this same security?

It depends on the jurisdiction. Some enhanced driver's licenses (EDLs) use older, long-range RFID technology without optical keys, which is why governments often issue them with protective shielding sleeves.

Different angles

Cryptographic Engineers' View

The system is mathematically sound and physically constrained, rendering remote skimming impossible.

Security architects view the passport skimming debate as a solved problem. By tying the digital decryption key to the physical ink inside the document, engineers created a system where the radio chip is useless unless the book is open. They emphasize that the passive nature of the ISO/IEC 14443 standard—which requires the chip to harvest power from the scanner—acts as a secondary physical firewall, limiting any interaction to a 10-centimeter radius.

Privacy Advocates' View

The true risk lies in eavesdropping during legitimate border checks, not drive-by skimming in public.

While privacy groups agree that a closed passport is safe from remote reading, they point out that the original Basic Access Control (BAC) protocol was vulnerable to eavesdropping. Because the MRZ data has low entropy, an attacker who intercepted the radio waves while a traveler was actively scanning their open passport at a border checkpoint could theoretically crack the key later. This specific vulnerability is what drove the global transition to the stronger PACE protocol over the last decade.

Travel Gear Industry's View

Consumers demand physical shielding for peace of mind regardless of the underlying cryptographic realities.

Manufacturers of RFID-blocking wallets and sleeves rarely engage with the cryptographic specifics of Basic Access Control. Instead, their marketing focuses on the general anxiety surrounding wireless data transmission and identity theft. For this industry, the physical mesh provides travelers with a tangible sense of control over their digital footprint, even if the passport's internal software already performs that exact function.

Cryptographic Engineers 45%Privacy Advocates 35%Travel Security Industry 20%
Cryptographic Engineers
Focus on the mathematical security of the BAC and PACE protocols, viewing remote skimming as a solved physical impossibility.
Privacy Advocates
Acknowledge that closed passports are safe, but focus on the risks of eavesdropping during legitimate open-book border scans.
Travel Security Industry
Capitalize on consumer anxiety regarding wireless technology to sell physical shielding products, regardless of the underlying cryptography.

Perspectives this story doesn't cover

  • Manufacturers of RFID-blocking travel accessories

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Cryptographic Engineers 45%Privacy Advocates 35%Travel Security Industry 20%
  1. [1]International Civil Aviation OrganizationCryptographic Engineers

    Doc 9303: Machine Readable Travel Documents, Part 11

    Read on International Civil Aviation Organization →
  2. [2]Thales GroupCryptographic Engineers

    ePassport Security Features and Cryptography Explained

    Read on Thales Group →
  3. [3]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team →
  4. [4]Electronic Frontier FoundationPrivacy Advocates

    ePassports and Privacy: Understanding the Cryptographic Handshake

    Read on Electronic Frontier Foundation →

Comments

Stay informed

Every angle. Every day.

Get Travel stories with full source coverage and perspective breakdowns, free every day.