About

Download

  • A free mini-guide on how to blog a conference in detail, by Ethan Zuckerman and Bruno Giussani.

Search LoIP

  • Web LoIP

Get LoIP per email

  • Enter your email address:

Non-profit

Books by Bruno Giussani

« HTML as art, pick your number | Main | Kickoff day »

June 06, 2006

RFID hacking

Annalee Newitz has written a must-read piece for Wired on RFID hacking. RFID tags (Radio Frenquency ID) are small chips with information stored in them, that can be attached to items (or people) and "read" at short distance with a scanner (I'm semplifying here, more details on Wikipedia's RFID article). They are becoming commonplace as replacements for barcodes on products or embedded in smart cards, payment cards, automatic toll collection systems, identity badges, ski passes and much more. I constantly carry three or four of them, and I'm sure most people in Europe and the US do the same - without even knowing it, for the chips are embedded in the "electronic key" that identifies them at the office, or in their bank card, etc. The new US passports will also include a RFID chip - and some humans are getting them implanted under the skin.

But how secure are these chips? Of course the answer is always "it depends" - on the type of the chip (some include encryption, others don't) and the specific implementation. Annalee's article however points out, with real examples, a number of worrysome vulnerabilities. She tells how it is possible to skim the "key" (data) contained in smartcard badges and create a duplicate; how the stored information can be tampered or deleted or overwritten (a researcher shows her how to change the info on tags identifying books in a library; another cuts and pastes the price information from a tag attached to a cheap wine bottle into that identifying an expensive one); how RFID chips used by car antitheft devices (and generally embedded in the rubbery end of the key) can be desabled; or how implantable chips (she got one in her arm for the sake of researching the article) are at risk of cloning.

[tags: ]

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834517e6e69e200d83562fcf269e2

Listed below are links to weblogs that reference RFID hacking:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Upcoming conferences