Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Report: Credit Cards With Rfid Are Easily Hacked
10-24-2006, 01:51 PM
Post: #1
Report: Credit Cards With Rfid Are Easily Hacked
Report: "contactless" credit cards with RFID are easily hacked

In today's NYT, a story by John Schwartz on a demonstration of serious security vulnerabilities with RFID-enabled "contactless" credit cards. Snip:

They call it the “Johnny Carson attack,” for his comic pose as a psychic divining the contents of an envelope. Tom Heydt-Benjamin tapped an envelope against a black plastic box connected to his computer. Within moments, the screen showed a garbled string of characters that included this: fu/kevine, along with some numbers.

Mr. Heydt-Benjamin then ripped open the envelope. Inside was a credit card, fresh from the issuing bank. The card bore the name of Kevin E. Fu, a computer science professor at the University of Massachusetts, Amherst, who was standing nearby. The card number and expiration date matched those numbers on the screen.

The demonstration revealed potential security and privacy holes in a new generation of credit cards — cards whose data is relayed by radio waves without need of a signature or physical swiping through a machine. Tens of millions of the cards have been issued, and equipment for their use is showing up at a growing number of locations, including CVS pharmacies, McDonald’s restaurants and many movie theaters.

The card companies have implied through their marketing that the data is encrypted to make sure that a digital eavesdropper cannot get any intelligible information. American Express has said its cards incorporate “128-bit encryption,” and J. P. Morgan Chase has said that its cards, which it calls Blink, use “the highest level of encryption allowed by the U.S. government.”

But in tests on 20 cards from Visa, MasterCard and American Express, the researchers here found that the cardholder’s name and other data was being transmitted without encryption and in plain text. They could skim and store the information from a card with a device the size of a couple of paperback books, which they cobbled together from readily available computer and radio components for $150.

Reg-free link to "Researchers See Privacy Pitfalls in No-Swipe Credit Cards."

And here is a related post from the guys who did the hack on RFID-cusp blog.

[Image: absurditiesvoltaire300oh0.gif]
------------------
&I've come to the conclusion, after having spent many years in politics, is that our presidential elections turn out to be more of a charade than anything else, and I think that is true today. It is a charade,& - Ron Paul, Sept 2008.
------------------
We're in a lot of trouble, watch this - http://www.youtube.com/v/3L3QVn4JyYA
------------------
[Image: guns250x200dw9.jpg]
[Image: armiw4.gif]
------------------
You cannot tax someone's labor because that is slavery
- Ed Brown, June 18 2007
------------------
The world's &freeest& country has the highest number in prison.
- arundhati roy
------------------
The crisis of modern democracy is a profound one. Free elections, a free press and an independent judiciary mean little when the free market has reduced them to commodities available on sale to the highest bidder.
- arundhati roy
------------------
The era of manufacturing consent has given way to the era of manufacturing news. Soon media newsrooms will drop the pretense, and start hiring theater directors instead of journalists.
- arundhati roy
------------------
The structure of capitalism is flawed. The motor that powers it cannot but vastly increase the disparity between the poor and the rich globally and within countries as well. Parecon is a brave argument for replacing that flawed machine and offers a much needed -- more equitable, democratic, participatory -- alternative economic vision.
- arundhati roy
------------------
[The choice between John Kerry and George Bush] is not a real choice. It's an apparent choice. Like choosing a brand of detergent. Whether you buy Ivory Snow or Tide, they're both owned by Proctor & Gamble.
- arundhati roy
------------------
No government's condemnation of terrorism is credible if it cannot show itself to be open to change by nonviolent dissent
- arundhati roy
[Image: sigterrorgj3.jpg]
------------------
Dr. Hermann Oberth who pioneered rocket design for the German Reich during World War II and later advanced rocket technology for the American manned space launches, cryptically stated: "We cannot take the credit for our record advancement in certain scientific fields alone; we have been helped."

When asked by whom, he replied: "The people of other worlds."
Find all posts by this user
Quote this message in a reply
11-21-2006, 08:43 PM
Post: #2
Report: Credit Cards With Rfid Are Easily Hacked
nice find there
thanks for the reg-free link!

Truth sets you free. Lies enslave you. Spread the truth, spread freedom!
Find all posts by this user
Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 1 Guest(s)