Live data from Hacker News

Why the Mythbusters won't do RFID (2008)

youtube.com

1–10 of 66 posts

Re: Why the Mythbusters won't do RFID (2008)

#4
Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote)

Here's the link:

http://news.cnet.com/8301-13772_3-10031601-52.html

September 3, 2008 10:59 AM PDT

'MythBusters' co-host backpedals on RFID kerfuffle

Re: Why the Mythbusters won't do RFID (2008)

#5
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

They don't want you to know that the microchips in their cards can be reprogrammed so that you can wave it at reader and emulate somebody else's CC#, or that you can program any compliant RFID chip to communicate with those wavey card readers to the same effect, or that you can plant an RFID reader on an ATM or similar point and "skim" CC info without needing the user to explicitly swipe their card.

That's just a few off the top of my head...

Re: Why the Mythbusters won't do RFID (2008)

#6
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

Some credit cards use RFID technology to transmit unencrypted data to merchants. I believe PayPass uses RFID tech. Anyone with an RFID scanner can grab your CC info.

Re: Why the Mythbusters won't do RFID (2008)

#7
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I'm guessing it's:

a) RFID is readable from further away than they'd like you to think.

b) You don't know when your RFID card is being read.

c) Points a and b make tracking you really easy... for anyone to do.

d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) where the actual info about how much money is on the card is stored on the card itself... but that's exactly the type of information which is stored on these cards.

e) Nearly all encryption mechanisms are shoddy, either because they're poorly implemented open standards, or developed in-house by the vendor (security through obscurity). Cards that make use of real encryption would be (are?) expensive to make.

Here in the Netherlands the entire public transit system is being switched to an RFID-based system, and even to a non-security expert (me) it's clear that the system is based on an insecure premise (d), and would be very vulnerable to unknown scanning by someone wishing to track you from a decent distance (a-b-c).

I was interested in the security of this system, and found this video (http://events.ccc.de/congress/2007/Fahrplan/events/2378.en.h...) of some hackers who did an amazing job tearing it to shreds. They're pretty adiment that nobody is doing adequate encryption on RFID cards. If you're interested in this at all it's an amazing hack, involving dissolving the cards layer by layer to see the code.

Re: Why the Mythbusters won't do RFID (2008)

#9
post #4

Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote) Here's the link: http://news.cnet.com/8301-13772_3-10031601-52.html September 3, 2008 10:59 AM PDT 'MythBusters' co-host backpedals on RFID kerfuffle

Wonderful. Which account do we believe now?
Post reply on HN