Live data from Hacker News

Why the Mythbusters won't do RFID (2008)

youtube.com

11–20 of 66 posts

Re: Why the Mythbusters won't do RFID (2008)

#11
post #7
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building.

b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem. I saw one hobbyist hook up an OLED pixel, but that's it.

e) I've heard of a couple, very expensive, challenge-response and public-key RFID systems. That is acceptable for authentication, but I've never heard of them actually being used, and one or two were only proofs-of-concept, IIRC. Many (I'd say easily most in use, from what I gather) simply transmit a unique ID, that never changes, which is used to perform X, which is ridiculously insecure.

Re: Why the Mythbusters won't do RFID (2008)

#12
post #4

Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote) Here's the link: http://news.cnet.com/8301-13772_3-10031601-52.html September 3, 2008 10:59 AM PDT 'MythBusters' co-host backpedals on RFID kerfuffle

Wonderful. Which account do we believe now?

This was discussed on No Agenda recently as an example of why corporate advertising is bad for media that does this kind of work (although Mythbusters rarely broaches subjects that run against corporate culture).

It seems odd Adam would have made up his original account, but only he knows the real story at this point.

Re: Why the Mythbusters won't do RFID (2008)

#13
post #7
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

[deleted]

Re: Why the Mythbusters won't do RFID (2008)

#14
post #7
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

Reminds me about a story about a talk at Defcon where someone just setup a scanner and camera and collected photos of all the federal agents at the convention based on their RFID enabled I.D. cards.

http://www.wired.com/threatlevel/2009/08/fed-rfid/

Re: Why the Mythbusters won't do RFID (2008)

#15
post #11
post #7

Earlier quoted context omitted.

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

  > I'd love to take a massive dish (say, 20 foot
  > diameter) & see how many can be captured from
  > inside a neighboring building.
Are you talking about active or passive RFID? I was under the impression that most RFID in use is passive. In that case, you'd have to transmit something to get a response, unless you're talking about camping out in an area where lots of cards are going be activated by various things other than yourself (e.g. entrance to the transit system). But even then the transmitting power of the RFID chip is proportional (?) to the power used to activate it, so something that only expects to read it from 2 feet away isn't going to blast it with enough power to be reliably read from 100 feet away, unless I'm misunderstanding how people do those long distance RFID reading records...

Re: Why the Mythbusters won't do RFID (2008)

#16
post #10

Well Adam has stated in at least one interview that he reads Hacker News regularly so maybe we'll have a nice anonymous reply :)

I was curious about the validity of your statement so I did a little digging. It's true, he even mentions that he reads it on a daily basis.

Source: http://www.youtube.com/watch?v=J8jqea8R-bE

[edit] if you don't want to watch the whole 3 part video: http://www.youtube.com/watch?v=fFcVaFhKd_4#t=08m32s

Re: Why the Mythbusters won't do RFID (2008)

#19
post #15
post #11

Earlier quoted context omitted.

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

> I'd love to take a massive dish (say, 20 foot > diameter) & see how many can be captured from > inside a neighboring building. Are you talking about active or passive RFID? I was under the impression that most RFID in use is passive. In that case, you'd have to transmit something to get a response, unless you're talking about camping out in an area where lots of cards are going be activated by various things other…

Passively camping out. Lots of (questionable) RFID uses I've seen are to unlock doors, often external ones. And if it's in a business park, it could easily be closer to 50 feet or less between buildings.

Re: Why the Mythbusters won't do RFID (2008)

#20
Thankfully with a community named 'HackerNews' hopefully somebody here will be inspired to look into it deeper and see if they can do the show that networks can't do.

What's required to figure out how to hack these chips which are clearly readily available?

Post reply on HN