A team of security researchers has recovered the cryptographic signing keys used to authenticate barcodes on US driver's licenses. The feat, part of a project called Keys Not Included, allows anyone with technical expertise to create counterfeit licenses that pass standard barcode scanners. The discovery casts doubt on the reliability of driver's licenses as a trusted form of identification.
How the Keys Were Recovered
Researchers involved in Keys Not Included targeted the hardware security modules that store and use the signing keys for driver's license barcodes. They exploited physical access to the devices, using side-channel analysis and reverse engineering to extract the cryptographic material. The keys were not rotated over long periods, increasing the window of exposure.
Why This Matters
Driver's licenses are a de facto national ID in the United States. They are used for airport security, age verification, banking and law enforcement. Fraudulent licenses that pass barcode checks could enable identity theft, illegal entry and financial crimes. The issue affects every state that issues licenses and every institution that relies on them for verification.
The keys recovered allow creation of valid digital signatures on barcode data. This means a forged ID with a fake name and photo would appear legitimate when scanned. Businesses and government agencies that depend on barcode verification may no longer trust the system until keys are updated.
What Comes Next
State DMVs must generate new cryptographic key pairs and distribute them to all verification points. This is a massive logistical effort involving hardware replacements and software updates. The American Association of Motor Vehicle Administrators may need to coordinate national standards for key management.
The Keys Not Included research has already prompted discussions about requiring tamper-proof key storage and automatic key rotation. Some experts argue that the entire barcode signing system needs redesigning to incorporate modern cryptographic practices such as forward secrecy. Without these changes, the risk of future key recovery incidents remains high.
The broader lesson extends beyond driver's licenses. Any system that uses static cryptographic keys across many endpoints is vulnerable if physical security of those keys is weak. The Keys Not Included project serves as a warning for identity systems worldwide.



