Earlier quoted context omitted.
> Outside of physical tricks like this (and various physical anti-deduplication tricks that are surprisingly limited), duplication is really not something you can ever control. This type of control is the point of smart cards. The card contains a private key which can't be extracted (or at least is difficult to extract and may involve destroying the card) and a processor that can do signing operations which prove to…
Smart cards are super cool! The number of real applications is pretty limited, though, with computer authentication being almost all of them (payment cards, yes, but the fallback to 'conventional' processing negates a lot of the advantage). I think that challenge-response NFC authentication will make this kind of technique more practical for physical access control applications.
Re: Hacking Oklahoma State University's Student ID
#51My view is that the scenarios described in the paper basically amount to "computer authentication", and smartcards would be completely warranted (and not at all unreasonable to implement) here.