# How safe is the military's new "Common Access Card" or "Smart Card" ID system?

**URL:** https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272
**Category:** Factual Questions
**Created:** [October 24, 2003, 6:38am UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272 "2003-10-24T06:38:19Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![alterego](https://avatars.discourse-cdn.com/v4/letter/a/6bbea6/32.png) [@alterego](https://boards.straightdope.com/u/alterego)
#### Post date: [October 24, 2003, 6:38am UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/1 "2003-10-24T06:38:19Z")

</div>

The new military ID cards are ‘Smart Cards’ as you may have seen. They have a little chip and it contains all your information. Certainly enough to account for identity theft…

I have an ActivCard reader on my desk and after I type in my pin number I can access all the information on the card. So if I lose this thing, and someone finds it how hard would it be for them to get the data off of it? :dubious:

---

<div class="post-metadata">

### Author: ![Ficer67](https://avatars.discourse-cdn.com/v4/letter/f/c57346/32.png) [@Ficer67](https://boards.straightdope.com/u/Ficer67)
#### Post date: [October 24, 2003, 8:55am UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/2 "2003-10-24T08:55:19Z")

</div>

This is right out of the Hitchhiker’s Guide to the Galaxy. In the last book of the series, “Mostly Harmless,” he mentioned Ident-I-Eeze cards, which high ranking executives carried because they could not be bothered with remembering all of their passwords which they needed to get along in their busy lives. I am going out on a limb here, but I imagine that the military’s smart ID cards are just as effective as the ones that Douglas Adams mentioned. IE - If the bad guys get your card, then they can do anything they want with your accounts and/or securities until you get a new card issued to you.

---

<div class="post-metadata">

### Author: ![SmackFu](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@SmackFu](https://boards.straightdope.com/u/SmackFu)
#### Post date: [October 24, 2003, 2:44pm UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/3 "2003-10-24T14:44:35Z")

</div>

Depends on how long your PIN is, eh?

And also how easy it is to get a reader.

---

<div class="post-metadata">

### Author: ![alterego](https://avatars.discourse-cdn.com/v4/letter/a/6bbea6/32.png) [@alterego](https://boards.straightdope.com/u/alterego)
#### Post date: [October 24, 2003, 5:51pm UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/4 "2003-10-24T17:51:19Z")

</div>

the pin is six digits, not terribly long i suppose. i’ve already been reissued my card once after I lost it on a city bus.

not a comforting thought.

---

<div class="post-metadata">

### Author: ![alterego](https://avatars.discourse-cdn.com/v4/letter/a/6bbea6/32.png) [@alterego](https://boards.straightdope.com/u/alterego)
#### Post date: [October 24, 2003, 6:01pm UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/5 "2003-10-24T18:01:48Z")

</div>

**SmackFu** the readers are really friggin easy to get… I have seen the same style of smart cards at LAUNDRY MATS! no joke…

The readers we have are made by ActivCard ([www.activcard.com](http://www.activcard.com))

> [@](#):
>
> The U.S. Department of Defense has adopted ActivCard server and client software to support its smart card-based Common Access Card program for millions of military personnel around the world. Leading enterprises like Microsoft, Hewlett-Packard and Sun Microsystems rely on ActivCard Corporate Access Card solutions to protect their network and  
> building access.
> 
> ActivCard’s comprehensive solutions allow organizations to issue, use and manage trusted digital identities that ensure users are who they say they are. By consolidating user credentials on a single, multi-function smart card, ActivCard eliminates the security risks associated with constant internal and external threats from unauthorized access and identity theft. In addition to protecting the corporate assets from daily attacks, ActivCard solutions reduce the high administration costs associated with static passwords and deliver an accelerated return on investment—through significant and measurable gains in IT department efficiency and employee productivity with a single sign-on experience.
> 
> ActivCard’s solutions are fully interoperable with all major computing platforms, directory services, identity management systems, enterprise applications, public key infrastructures, VPNs, firewalls, and building access systems. ActivCard supports multi-factor authentication technologies through a diversity of physical ID devices including smart cards, tokens, and biometric scanners.

I should add that the pin is not always the same length as you can set it to whatever you want so that does add some variation…

I’m curious as to the encryption that’s used…I hope its tuf =)

---

<div class="post-metadata">

### Author: ![Doomtrain](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@Doomtrain](https://boards.straightdope.com/u/Doomtrain)
#### Post date: [October 24, 2003, 8:43pm UTC](https://boards.straightdope.com/t/how-safe-is-the-militarys-new-common-access-card-or-smart-card-id-system/209272/6 "2003-10-24T20:43:46Z")

</div>

Smart card readers? My motherboard comes with built in support. They can’t be TOO hard to get.
