


The second design flaw that is favourable for attackers is that the Digital Driver Licence data is never validated against the back-end authority which is the Service NSW API/database. The problem here is that an attacker who has access to the encrypted licence data (whether that be through accessing a phone backup, direct access to the device or remote compromise) could easily brute-force this 4-digit PIN by using a script that would try all 10,000 combinations…. This file is encrypted using AES-256-CBC encryption combined with Base64 encoding.Ī 4-digit application PIN (which gets set during the initial onboarding when a user first instals the application) is the encryption password used to protect or encrypt the licence data. You will undergo an eye test at the testing centre or you can have an eye test done by qualified optometrist and submit the form at the testing centre.The New South Wales digital driver’s license has multiple implementation flaws that allow for easy forgeries.Complete the notification of change of address or particulars of person or organisation (NCP) form.Complete the Application for a driving licence (DL1) form.Gauteng residents should apply online:.

You must first confirm with the DLTC how many photos they require before you have photos taken. Four identical black-and-white photographs.

