Pull to refresh
Logo
Researcher recovers hidden verification keys from driver's license barcodes

Researcher recovers hidden verification keys from driver's license barcodes

New Capabilities

ECDSA math exposed public keys New York and Virginia kept proprietary, letting anyone verify barcodes in-browser

Today: Fahey publishes 'Keys Not Included'

Overview

Updated 1 hour ago

New York and Virginia sign their driver's license barcodes cryptographically but never published the verification keys, so only their DMVs could check authenticity. A security researcher just derived both keys mathematically from the signatures themselves. Now anyone can build a verifier without state cooperation.

ECDSA carries a quirk: anyone can recover a public key from a signature and the exact bytes it signed, which made the secrecy pointless. California already publishes its key, documentation, and an open-source verifier. The recovered keys matter more as databases of 153 million license scans surface on the dark web.

Why it matters

Anyone can now verify whether a US driver's license barcode is genuine without DMV cooperation, closing a gap researchers flagged for years.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

3
States with signed license barcodes
California publishes its key; New York and Virginia kept theirs secret until now.
2
Public keys recovered (New York, Virginia)
Derived via ECDSA public key recovery from ordinary card signatures.
90
Bytes in New York's signature field
Field ZNB spans bytes 393-483 of the 484-byte payload, Ascii85-encoded DER signature.
153M
Driver's license scans in dark web dump
IDScan.net breach surfaced September 2026, testing why cryptographic verification matters.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

October 2025 September 2026

5 events Latest: Today
Tap a bar to jump to that date
  1. Fahey publishes 'Keys Not Included'

    Today Publication

    Recovers New York and Virginia barcode verification keys via ECDSA key recovery; ships a browser-based verifier demo.

  2. IDScan.net confirms breach

    Statement

    Louisiana ID-verification vendor links leaked license scans to unauthorized access in its cloud.

  3. Dark web service Nexus lists 153 million license scans

    Data Breach

    Service offers searchable scans of US and Canadian driver's licenses; FBI opens New Orleans investigation.

  4. California publishes verification materials

    Statement

    Releases documentation, public verification key, and open-source verifier, ending roughly six months of unverifiable signatures. (Date approximate.)

  5. California announces barcode signature

    Announcement

    California DMV says it added a digital signature to barcode data, initially without public documentation. (Date approximate.)

Scenarios

1

Independent barcode verifiers ship to market

Likely Resolves by Q2 2027

Discussed by: Fahey's browser demo and California's open-source verifier make direct implementation possible

The recovered keys let bars, landlords, employers, and banks add barcode verification without waiting for DMV cooperation. Fahey's demo already runs entirely in the browser, so a vendor can adopt it quickly. ID-scanning companies may add the feature as a standard offering.

2

New York and Virginia publish their verification keys

Possible Resolves by End of 2027

Discussed by: The secrecy lost its purpose once keys were derivable from any two cards; California already models the public approach

With the keys recoverable from ordinary signatures, withholding them buys nothing. Either state could follow California and publish documentation plus keys. No rule requires them to act, though the keys stay usable regardless.

3

States shift focus from barcodes to mobile driver's licenses

Possible Resolves by Q1 2028

Discussed by: AAMVA's mDL standard and industry advocates who have long pushed app-based licenses

AAMVA's mobile driver's license standard uses public-key infrastructure and a public trust framework, avoiding the proprietary secrecy of PDF417 signatures. States may decide the barcode is legacy and put energy into mDL, despite its own rollout hurdles. The recovered barcode keys would still work but become less central.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

1991-2000

The crypto wars: PGP export controls (1991-2000)

Phil Zimmermann wrote PGP in 1991 and posted it online, making strong encryption available to anyone. The US government treated cryptography as a munition and spent three years investigating Zimmermann for exporting code that was already public.

Then

PGP spread anyway; Zimmermann's team printed the source code as a book to claim First Amendment protection. In 2000 the Clinton administration relaxed export controls.

Now

The episode established that cryptographic capability cannot be meaningfully controlled once the math is out.

Why this matters now

Same logic applies to barcode keys: a key recoverable from public math cannot be kept secret, because the algorithm doesn't require anyone's cooperation.

2008

Mifare Classic reverse engineering (2008)

Researchers at Radboud University and the University of Virginia cracked Mifare Classic, the RFID chip in transit cards and building badges worldwide. NXP Semiconductors kept the cipher proprietary and secret.

Then

NXP downplayed the work and sued to block publication; the paper came out anyway. Transit systems from London to San Francisco began planning upgrades.

Now

A standard case study in why proprietary secrecy fails at scale across millions of credentials.

Why this matters now

Driver's licenses are mass-issued credentials guarded by proprietary signing, the same pattern that drew in a researcher who recovered the keys.

September 2017

Equifax breach (2017)

Attackers stole records on 147 million Americans from Equifax, one of the three major credit bureaus, including names, Social Security numbers, and addresses.

Then

The CEO resigned, Congress held hearings, and Equifax paid more than $1.4 billion in settlements and fines.

Now

Identity data cannot be reset. The breach pushed the industry toward verification, proving who you are rather than protecting static records.

Why this matters now

When 153 million license scans leak, a copied plastic card cannot be trusted by sight. Cryptographic verification of the physical document becomes the remaining check.

Sources

(5)