Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Computer hackers get lesson on cloning passport, cash card tags
AFP ^ | Sun Aug 6, 9:54 AM ET | Glenn Chapman

Posted on 08/06/2006 6:29:12 PM PDT by diverteach

LAS VEGAS, Nevada (AFP) - High-tech passports touted as advances in national security can be spied on remotely and their identifying radio signals cloned, computers hackers were shown at a conference. ADVERTISEMENT

Radio frequency identification technology, referred to as RFID, used in cash cards and passports, can be copied, blocked or imitated, said Melanie Rieback, a privacy researcher at Vrije University in the Netherlands.

Rieback demonstrated a device she and colleagues at Vrije built to hijack the RFID signals that manufacturers have touted as unreadable by anything other than proprietary scanners.

"I spend most of my time making the RFID industry's life miserable," the doctorate student told AFP. "I am not anti-RFID. It has the potential to make people's lives easier, but it needs to be used responsibly."

Rieback and university compatriots expected to have a reliable portable version of their device, RFID Guardian, finished in six months and "had no plans to immediately mass-produce these things."

A cheer rose from the legion of hackers in the conference room when Rieback announced that the schematics and the computer codes for the device would be made public.

"The industry and government needs to not be scared of us," Rieback said. "They need to talk with us and to work with us. Hopefully, together we can come up with some kind of reasonable compromise."

RFID tags consist of a computer chips wrapped with tiny radio antennae. The chips store financial, identity, or other data that can then be sent to scanners by radio signals.

Retail behemoth Wal-Mart about two years ago embarked on a campaign to use RFID to track inventories and shipments from suppliers, and the devices are used on cargo shipped overseas in containers.

RFID tags have been used for decades to track cattle or wild animals.

It has become common in the United States for pet owners to have chips encased in glass, about the size of grains of rice, implanted under the skin of their dogs or cats so they can be identified and returned if they run away.

The European Central Bank has talked of putting RFID technology in euro currency, and such tags were used in World Cup Soccer tickets, according to the researcher.

Smart chips have been crafted into German passports and are being put into US passports. Stores have experimented with using the tags not only to track inventory, but to bill shoppers for purchases invisibly as they leave.

"It has been getting new life, and creating quite a stir," Rieback said of RFID use.

RFID equipment makers would be wise to ramp up encryption and other security while technology is catching on, according to Rieback. Rieback was not the only speaker at the gathering who claimed to have found RFID vulnerabilities.

"If you are using RFID on cows, who cares?" Rieback asked rhetorically. "But, with a passport, it only takes one breach at the wrong time and it could wreck it for the RFID industry."

The potential exists for unauthorized reading of cards, cloning, and tracking people who carry them, Rieback said.

Hacked chips could even be used to launch attacks on software in computers linked to scanning devices, according to the researcher.

RFID Guardian was designed to also block any selected tag from being read by scanners, legitimate or illicit.

"We are being foisted into this world where these tags are all around but we don't know when and how they are there," Rieback said. "The Guardian puts the control back in your hands."


TOPICS: Crime/Corruption; Culture/Society; Government; Miscellaneous
KEYWORDS: bigbrother; defcon; healthypeople; healthypeople2010; idtheft; passports; privacy; rfid; tagging; verichip

1 posted on 08/06/2006 6:29:14 PM PDT by diverteach
[ Post Reply | Private Reply | View Replies]

To: diverteach

Oh...joy...


2 posted on 08/06/2006 6:35:20 PM PDT by TampaDude (If you're not part of the solution, you're part of the PROBLEM!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: diverteach
RFID Guardian was designed to also block any selected tag from being read by scanners, legitimate or illicit.

Doesn't .001 inches of aluminum foil do that too?

3 posted on 08/06/2006 6:41:06 PM PDT by balrog666 (Ignorance is never better than knowledge. - Enrico Fermi)
[ Post Reply | Private Reply | To 1 | View Replies]

To: balrog666
Doesn't .001 inches of aluminum foil do that too?

Only on your head.

4 posted on 08/06/2006 6:46:09 PM PDT by ModelBreaker
[ Post Reply | Private Reply | To 3 | View Replies]

To: PatrickHenry; b_sharp; neutrality; anguish; SeaLion; Fractal Trader; grjr21; bitt; KevinDavis; ...
FWIW, I realize that RFID isn't really future tech. It's been around in some fashion for quite a while in fact - since back in the 50s. I ping it because of novel applications that strike me as significant enough to qualify as 'futuristic' so to speak.

That, and the FT ping list has been slow lately, and RFID is a pet cause (pet peeve) of mine, and last but not least, no one's complained, yet. :)

FutureTechPing!
An emergent technologies list covering biomedical
research, fusion power, nanotech, AI robotics, and
other related fields. FReepmail to join or drop.

5 posted on 08/06/2006 6:47:36 PM PDT by AntiGuv ("..I do things for political expediency.." - Sen. John McCain on FOX News)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ModelBreaker
Only on your head.

Wow, who knew?



6 posted on 08/06/2006 6:51:06 PM PDT by balrog666 (Ignorance is never better than knowledge. - Enrico Fermi)
[ Post Reply | Private Reply | To 4 | View Replies]

To: diverteach

DEFCON rocks. Was too busy to make it this year, but next year I intend to be there.

Note that I am an IT professional, past 50. The information there is like nothing else available in the open.


7 posted on 08/06/2006 6:54:17 PM PDT by Starwolf
[ Post Reply | Private Reply | To 1 | View Replies]

To: diverteach

This research is a good thing. It will be harder for the RFID crowd to push the technology further into our lives as people become aware of the risks to their privacy.


8 posted on 08/06/2006 6:54:23 PM PDT by MediaMole (9/11 - We have already forgotten.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MediaMole

The privacy risks of 'loyalty' cards hasn't stopped their use.

I don't think the general public cares.


9 posted on 08/06/2006 7:00:24 PM PDT by RFC_Gal (It's not just a boulder; It's a rock! A ro-o-ock. The pioneers used to ride these babies for miles!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: diverteach
"The potential exists for unauthorized reading of cards, cloning, and tracking people who carry them, Rieback said."

Wow. This device allows them to clone people.

Maybe he meant unauthorized reading and cloning of cards, and tracking people who carry them.
10 posted on 08/06/2006 7:01:48 PM PDT by unlearner (You will never come to know that which you do not know until you first know that you do not know it.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Starwolf
An interesting talk from Black Hat this year (slides and text). Enough to make someone weak in the knees, if they're sufficiently paranoid.
Matasano
11 posted on 08/06/2006 7:36:39 PM PDT by cryptical (Wretched excess is just barely enough.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: diverteach

>"The industry and government needs to not be scared of us," Rieback said. "They need to talk with us and to work with us. Hopefully, together we can come up with some kind of reasonable compromise."

Translation: "Pay us off."


12 posted on 08/06/2006 7:59:12 PM PDT by MindBender26 (Having my own CAR-15 in RVN meant never having to say I was sorry....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: diverteach

http://www.freerepublic.com/focus/f-news/1563271/posts
Healthy People 2010

>>>>Before Bill Clinton left office, he authorized 2001 an 84% increase in the government's investment in nanotechnology research and development, National Nanotechnology Initiative (NNI) and made it a top priority.<<<<

Too much grant money has been created for any of our corrupt politicos too listen.

Top that with the VeriChip is issued in MLM format. So all that are in position to make decisions on it's sale and use earn multiple income streams from it.


13 posted on 08/06/2006 8:20:25 PM PDT by Calpernia (Breederville.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: diverteach
The article does not support its misleading headline. It merely states that some RFID can be hacked and that RFID will be part of the new passports. It does not say that the RFID as implemented in the passports has been hacked. This is headline grabbing but without substance.
14 posted on 08/06/2006 8:52:22 PM PDT by Wally_Kalbacken
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wally_Kalbacken

The RFID in the new passport has been thoroughly hacked for at least 6 months, though the info on how to hasn't been widely available. The US government and the contractors refuse to acknowledge the hack and make the new passport technology 'more' secure.

Within ten years, every American who carries a passport is a potential victim of identity theft in all unsecure locations the passport is carried. Only wrapping the passport in several layers of signal blocking metallic sheeting will protect the US citizen's identity from being trasmitted 24/7 from the passport. Or breaking the RFID chip by melting it in a microwave or something along those lines.


That is the short of it.


15 posted on 08/06/2006 9:34:10 PM PDT by JerseyHighlander
[ Post Reply | Private Reply | To 14 | View Replies]

To: diverteach

Silly wabbit. As long as RF is involved, it can be intercepted and duplicated. Now if they used spread-spectrum emissions for RFID tags, that would make things a bit more difficult... and expensive.

I remember an incident where an Amateur Radio UHF repeater system had hundreds of dollars worth of equipment to secure it's access to only a few members. The security was broken with a $9 tape recorder. If there's a will, there's a way.


16 posted on 08/07/2006 12:14:42 AM PDT by Outland (Sustainable Horse Puckey)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Outland

I remember an incident where an Amateur Radio UHF repeater system had hundreds of dollars worth of equipment to secure it's access to only a few members. The security was broken with a $9 tape recorder. If there's a will, there's a way.

Yup...a $20 Radio Shack tone dialer modified with a $5 crystal gave you access to AT&T's ACTS system back in the day...unlimited free long distance calls.

There's always a way if you really want to...the trick is to make circumventing the security too expensive for 99.99% of the population. There will, however, always be that .01%...and so the battle rages on...


17 posted on 08/07/2006 4:00:35 PM PDT by TampaDude (If you're not part of the solution, you're part of the PROBLEM!!!)
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson