The E-Passport Paradox: How a Security Upgrade Creates Deeper Risks
Abhishek Baxi
5 minutes ago
The e-passport is neither free of security vulnerabilities nor is focussed on protecting the privacy of the person from the world.
Illustration: Pariplab Chakraborty.
The Government of India has initiated a significant modernisation of its travel documentation system with the introduction of the chip-based electronic passport, or e-passport. This move, part of the government's Passport Seva Programme 2.0, began in April 2024 and is already rolling out in select cities.
This move places India among more than 120 nations that have adopted this International Civil Aviation Organisation (ICAO)-compliant technology. The idea is to offer enhanced security, faster immigration processing and seamless global travel.
But behind the glossy pitch of digital convenience – and a gold chip symbol below the national symbol – lies a bigger concern: privacy without protection and innovation without oversight.
What's on the chip?
Each e-passport is equipped with a radio-frequency identification (RFID) chip embedded in the back cover. This chip securely stores biometric information such as facial data and fingerprints, and personal details, all encrypted with advanced security protocols like Basic Access Control (BAC; which restricts chip access to authorised scanning devices) and Extended Access Control (EAC; which adds an extra security layer for sensitive biometric information).
When an immigration officer scans the e-passport, the chip's digital signature confirms authenticity; a live biometric scan then matches the data on-chip to the traveller. According to India's Passport Seva FAQ, 'the underlying technology supporting the security of the e-passport is the Public Key Infrastructure solution, which is the foundation for safeguarding sensitive information and confirming the integrity and origin of the personal and biometric data stored on the chip'.
But the FAQs stop short of outlining who beyond immigration authorities – if anyone – may lawfully scan or store this data.
Can e-passports be scanned without consent, transparency or oversight – can private entities like airlines or banks access this information? Which devices qualify as certified readers? Are there limits on how long the scanned data may be retained?
When MP R. Dharmar raised a question in the Rajya Sabha asking for 'the steps being taken to ensure the security and privacy of personal data stored in chip-based e-passports', the response from Kirti Vardhan Singh, minister of state for external affairs, on April 3, 2025 focused on the security aspect of e-passports, skipping the privacy question.
'The main benefit of the e-passport,' the minister said, 'is its enhanced ability to maintain the integrity of its data'. He added: 'Since the e-passport has the data in printed form on the booklet, as well as encrypted in the chip, it makes it harder to forge.'
On other occasions too, responses to related questions have been unsatisfactory.
Chinks in the armour
The government's public messaging and parliamentary statements have consistently framed the e-passport initiative around two primary benefits: enhanced security and greater convenience.
Beneath the surface of official assurances lies a complex and troubling landscape of technological vulnerabilities. The very features that deliver the e-passport's promised convenience are also the source of its most significant privacy risks.
The use of RFID technology for contactless communication is the e-passport's primary architectural weakness. This design choice exposes the passport to several well-documented attack vectors, including skimming (the clandestine reading of the chip's data by using a concealed RFID reader), eavesdropping (a passive attack where an adversary intercepts the wireless communication between a legitimate immigration reader and the e-passport during an official inspection), and cloning (creating a perfect, bit-for-bit digital copy on a blank RFID chip).
The vulnerabilities are not limited to the hardware but extend to the very protocols mandated by the ICAO 9303 standard, which India's e-passport adheres to. A 2021 research paper – titled ' Discovering ePassport Vulnerabilities using Bisimilarity ' – points out significant privacy flaws in the standard's core authentication protocols, BAC and its more advanced successor, Password Authenticated Connection Establishment.
These protocols are meant to ensure "unlinkability", meaning an adversary should not be able to track a passport holder by linking their presence at different checkpoints. However, the research demonstrates that these protocols fail to meet this requirement.
Then there's the biometric paradox. The inclusion of biometric data is marketed as a definitive security enhancement, tying the document irrevocably to its owner. This perception, however, is dangerously flawed.
Biometric identifiers are immutable: once compromised, they cannot be reset like passwords. And as public-facing attributes, they can be captured without an individual's consent. Storing these unchangeable biological traits on a cloneable RFID chip creates a permanent and high-value target for identity thieves.
The security posture of the e-passport is further weakened by its long operational lifespan. Indian passports for adults are valid for ten years. A ten-year validity period creates a substantial window for advances in cryptanalysis.
Encryption algorithms considered secure at the time of the passport's issuance may become vulnerable to being broken by more powerful computers and new analytical techniques before the passport expires. The data that is secure today may not be secure five or ten years from now, yet it will remain on the chip for the document's entire lifecycle.
Gaps in the data protection regime
The government's narrative strategically conflates two distinct security concepts: data integrity and data confidentiality. The heavy emphasis on ensuring data integrity (the idea that the data can be neither hacked nor copied) effectively sidesteps the more critical privacy question of who can read this authentic, unaltered data (ensuring data confidentiality).
This focus on thwarting counterfeiters creates a public perception of a holistically secure document, while leaving the more subtle but profound risks of surveillance and unauthorised data access largely unaddressed.
And there's the question of who the ultimate controller of an Indian citizen's e-passport data is.
In theory, the Digital Personal Data Protection (DPDP) Act, 2023 designates the citizen as the "data principal", the owner of their personal data. In practice, however, the e-passport system sets up the state as the de facto controller with ultimate and overriding power – essentially, the "data fiduciary". Moreover, the vast exemptions under the DPDP Act mean it can process this data without the consent or knowledge of the citizen.
In the event that a citizen's e-passport data is misused – whether it is cloned by a criminal organisation, shared improperly with a foreign government or collected for domestic surveillance by a national agency – the path to legal recourse is unclear and likely non-existent.
Such systems expose citizens to new forms of digital harm with no effective means of holding the powerful to account. Writing for The Statesman, consumer rights advocate Shrey Madaan calls it 'paternalism, packaged in a chip'.
(As an aside, a widely appreciated move is the decision to remove key personal information like the residential address (to safeguard privacy) and parents' names (to accommodate diverse family situations) from the physical booklet. This too serves to concentrate power. The citizen loses the ability to passively share their details from the document and becomes entirely dependent on the state's infrastructure to verify their own information.)
Citizen vs the state
In a way, the e-passports mark a paradigm shift in the relationship between the Indian citizen and the state. A traditional passport is a static document, a piece of property over which the citizen exercises near-total control, revealing its contents only when they choose to physically present it. An e-passport can be queried and tracked silently.
When combined with a legal framework that grants the state sweeping powers to access its data, the passport is transformed from a tool of the citizen into an instrument of the state.
The system's architecture is overwhelmingly focused on proving the authenticity of the document to the state, not on protecting the privacy of the person from the world. It is engineered to stop someone from altering the data on the chip, but not to stop them from copying it wholesale or tracking its movements.
This prioritisation of state-level verification over individual privacy transforms the passport from a private document owned by the citizen into a trackable digital token controlled by the state.
The transition to e-passports is an irreversible global trend, and India's participation is not misplaced. The issue lies in the implementation. The current approach has created a system where the promise of convenience is overshadowed by the peril of unchecked surveillance and unmitigated security risks.
The absence of clear privacy rules, oversight mechanisms and citizen rights threatens to erode trust in the new system. Without sufficient guardrails, the promise of secure e-passports risks giving way to a surveillance architecture invisible to the very individuals it's meant to protect.
Abhishek Baxi is an independent technology journalist exploring the intersection of technology, culture and society. He writes on consumer tech and enterprise innovation, analyses Big Tech, unpacks technology policy and shares unsolicited opinions on X as @baxiabhishek.
The Wire is now on WhatsApp. Follow our channel for sharp analysis and opinions on the latest developments.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


India Gazette
11 hours ago
- India Gazette
All panchayats will have high-speed fibre network within 3 years: Telecom Secretary
New Delhi [India], July 14 (ANI): Telecom Secretary Neeraj Mittal on Monday said that all Indian villages will have a high-speed fibre network within the next three years. The central government had launched an ambitious BharatNet programme to connect the villages. The primary objective is to provide unrestricted access to broadband connectivity to all telecom service providers. 'Government of India is spending Rs 140,000 to connect every gram panchayat with 1 gigabit per second connectivity. As we speak, roughly 50,000 panchayats have 1 gigabit per second connectivity with an SLA of more than 98 per cent,' the secretary said, speaking at the CII Global Capability Centers (GCCs) Summit. 'There's a long way to go, and we hope that within 3 years we will have all the village panchayats, which is roughly about 2.5 lakhs, plus the villages associated with it, which is roughly about 6 lakh, will get connected to a high-speed fibre network,' the secretary said. Speaking about GCC infrastructure in India, the telecom secretary said enablers of GCC are very well established in India, referring to the talent pool. 'Be it connectivity, the capability to innovate, the rule of law, or strong IPR protections. All these things make India a very attractive destination,' the secretary continued. Connecting telecom with GCCs, he said internet data costs in India is very low in India against the global average. Data costs are a key component of GCCs. 'We are about 9 cents per GB... USD 2.6 is the global average,' the secretary said. 'India saw one of the largest and fastest 5G expansions. We covered over 99 per cent of the districts. Only there are only two districts in the country where there is no 5G,' he added. Further, the secretary put special emphasise on security aspects, noting that India is amongst the top nations where the cybersecurity infrastructure, policies, response mechanisms, mitigations are top class. Going by definition, GCCs are offshore facilities set up by multinational corporations to manage a variety of business functions and processes for their parent organisations. (ANI)


The Print
12 hours ago
- The Print
Sriharikota, start-ups to space cities: Naidu govt aims for the cosmos with ambitious space policy
The policy, which leverages Sriharikota's strategic location on Andhra Pradesh's southern coast, aims to attract investments worth Rs 25,000 crore in the sector over the next 10 years, and create 5,000 direct and 30,000 indirect jobs in high-technology, space-linked sectors. The Chandrababu Naidu government's Andhra Pradesh Space Policy (4.0), unveiled Sunday, seeks to build on the country's progress and plans in satellite constellation, next-generation technology missions, planetary and interplanetary exploration, and human spaceflight and space station development. Hyderabad: Andhra Pradesh, home to India's only operational spaceport at Sriharikota, has unveiled an ambitious space policy aimed at attracting massive investment and creating thousands of jobs in the state. The five-year policy's strategic goals include the establishment of an enabling eco-system by developing indigenous research and testing infrastructure to reduce dependency on external agencies, and fostering international collaborations and partnerships in critical space technologies, satellite applications and launch logistics. The policy outlines plans to build an enabling ecosystem by developing indigenous research and testing infrastructure to reduce reliance on external agencies, while promoting international collaboration in critical areas, such as space technology, satellite applications, and launch logistics. For the purpose, the government is planning two dedicated Space Cities at Lepakshi (close to Bengaluru), and Tirupati (close to Sriharikota), to make them hubs for space tech, R&D and manufacturing. To implement the policy, the state government will establish a dedicated Special Purpose Vehicle called Andhra Pradesh Space City Corporation, according to government orders issued Sunday. 'The corporation serves as the central agency to coordinate infrastructure development, raise startup funds, attract investments, facilitate industry partnerships, build partnerships to attract global demand and liaise with all Government of India entities for domestic demand. It will also facilitate investors to ensure streamlined execution of space-related projects,' N. Yuvaraj, the industries and commerce department secretary, said while issuing the policy. Operating under the Department of Space, the three key organisations responsible for research, regulatory functions and commercial operations in the space sector are the Indian Space Research Organisation (ISRO), IN-SPACe (Indian National Space Promotion and Authorization Center) and the NewSpace India Limited (NSIL). Also Read: What's next as ISRO pulls off short-duration 'hot tests' for Gaganyaan module propulsion system Financial incentives The policy offers several incentives to encourage start-ups and attract investors in the fast-expanding sector. Start-ups could get a grant of up to Rs 15 lakh in a phased manner, an interest subsidy and seed funding with equity of up to Rs 50 lakh, based on an equity sharing model. Large enterprises are eligible for 15 percent of the eligible fixed capital investment with a maximum cap of Rs 75 crore, disbursed over three years. Enterprises successfully entering technology transfer agreements with national or international organisations are eligible for a technology transfer subsidy and can receive 50 percent of the technology acquisition cost, up to a maximum of Rs 1 crore. The state is offering other incentives, such as rebate on land cost, net SGST reimbursement payable on the sale of final products for five years, a de-carbonisation subsidy and stamp duty reimbursement. However, the overall incentive claim should not exceed 100 percent of the fixed capital investment in the state. Micro, Small and Medium Enterprises (MSMEs) can also claim these benefits, along with power subsidies, skill development assistance, branding and marketing support, although the the overall incentive claim cannot exceed 75 percent of the fixed capital investment. Geographical advantage Officials say Andhra Pradesh has a geographical advantage in the national space ecosystem, being home to the Satish Dhawan Space Centre at Sriharikota—India's only operational launch site. With over 90 successful launches to date, the facility anchors the state's strategic relevance in the country's space programme. 'The development of a third launch pad at Sriharikota further reinforces Andhra Pradesh's role in supporting future strategic, commercial, and crewed space missions. Additionally, the State's proximity to key aerospace hubs such as Bengaluru and Chennai offers significant logistical and technical advantages for component sourcing, talent access, and cross-sector collaboration,' the policy says. The Lepakshi Space City in Sri Satya Sai District (along the Hyderabad-Bengaluru Industrial Corridor) would be situated close to Bengaluru, home to the Indian Space Research Organisation's (ISRO) R&D hub and prominent aerospace clusters. The Tirupati Space City could boast of direct road access to the Satish Dhawan Space Centre (SDSC-SHAR) launch pad, facilitating efficient launch operations. 'Both locations have vast land banks available, providing ample scope for development and growth,' the policy says. Recognising the need to target distinct sub-sectors within the space industry, the policy is categorised into two broad areas. The first focuses on design and development, including spacecraft and payload design, avionics and embedded systems, space applications and downstream services. The second covers manufacturing and launch logistics, such as the production and assembly of launch vehicles, propulsion systems, satellites, mechanical and precision components and support infrastructure. India's space sector accounts for about two percent ($8-$10 billion) of the global space economy valued at over $500 billion. The policy notes that the Centre has set an ambitious target to raise this share to $44 billion by 2030. The domestic space ecosystem comprises more than 700 firms supporting ISRO missions, in addition to over 200-250 space-focused startups that contribute to a vibrant and rapidly evolving innovation landscape. The Indian Space Policy 2023 marks a pivotal shift by liberalising access to space technologies and infrastructure, while permitting 100 percent Foreign Direct Investment (FDI) under the automatic route for satellite component manufacturing and related services. (Edited by Sugita Katyal) Also Read: Elon's Starlink gets nod from India's space regulator but data privacy, space debris concerns abound
&w=3840&q=100)

Business Standard
15 hours ago
- Business Standard
Govt to give best of attention to promote GCCs: FM Nirmala Sitharaman
The government would back the development of India's Global Capability Centres (GCCs) whether it was through taxation, legislative support or state administration, Finance Minister Nirmala Sitharaman said on Monday. Speaking at the Confederation of Indian Industry's GCC Business Summit, the FM said, 'There's a lot of work to do. Equally, there is great opportunity for us. So together, with all heads put together, we'll be able to get some concrete steps on which I assure you the best of attention will be given by the Government of India.' Stressing that India should not lose the advantage it has, Sitharaman said that while taxation was one issue being faced by GCCs, there was a need to lubricate the entire administrative and governing mechanism top down to make sure that the advantages are there for everyone to capture across the country. Sitharaman in her Budget 2025 had announced that a national framework would be formulated as guidance to states for promoting GCCs in emerging tier 2 cities. 'This will suggest 16 measures for enhancing availability of talent and infrastructure, building bye-law reforms, and mechanisms for collaboration with industry,' the FM had said in her Budget speech. The FM said that some work had been done on advance pricing and tax-related rulings in the last Budget. Highlighting that the set-up rate of engineering, research and development GCCs had been 1.3 times faster than the overall GCC set-up rate over the last five years, Sitharaman said there was a clear shift towards high value-added work in India. 'India's unique strength lies in its immense talent pool, accounting for 28 per cent of the global Science, Technology, Engineering, and Mathematics (STEM) workforce and 23 per cent of the global software engineering talent,' the FM said, stressing that over 32 per cent of global GCC talent is currently based in India. Sitharaman also said that India's talent is more cost-effective compared to other countries, costing 30–50 per cent less than the US, UK and Australia. Global roles within India GCCs, the FM said, were expected to increase from 6,500 today to over 30,000 by 2030 through robust in-house training programmes that nurture globally ready leadership. 'Over the past decade, India's GCC ecosystem has matured significantly, moving beyond execution to become centres of strategic leadership and transformation. Many GCCs now house high-end roles, including product managers, architects, data scientists and global function heads,' the FM said. Sitharaman highlighted that on average, one new GCC per week was set up in the year 2024, with approximately 50 per cent of Fortune 500 companies establishing their GCCs in India.