Live data from Hacker News

MIFARE Classic: exposing the static encrypted nonce variant [pdf]

eprint.iacr.org

1–10 of 103 posts

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#3
post #2

"Should we buy a Chinese knockoff of MIFARE Classic" strikes me as a self-answering question, but I guess that's why I still haven't been promoted to CISO.

The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#4
post #2

"Should we buy a Chinese knockoff of MIFARE Classic" strikes me as a self-answering question, but I guess that's why I still haven't been promoted to CISO.

The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.

They could have licensed the IP from the same company.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#5

Earlier quoted context omitted.

The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.

They could have licensed the IP from the same company.

Possibly so. It just means that based on the report's findings, even if you'd decided to play it safe and buy exclusively from NXP directly (the creators of this ecosystem and owners of the MIFARE trademark), it looks like you could still end up with backdoored hardware.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#6
post #2

"Should we buy a Chinese knockoff of MIFARE Classic" strikes me as a self-answering question, but I guess that's why I still haven't been promoted to CISO.

The end users of such cards are often not aware of the source, there's usually resellers that supply them who are always trying to save a buck here or there.

We have customers who use smartcards and we often need to read or write to them, during on-boarding they often have no clue what version or spec they are using and it often results in trial-and-error after they send us a few cards with little-to-no markings on them.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#7

Earlier quoted context omitted.

They could have licensed the IP from the same company.

Possibly so. It just means that based on the report's findings, even if you'd decided to play it safe and buy exclusively from NXP directly (the creators of this ecosystem and owners of the MIFARE trademark), it looks like you could still end up with backdoored hardware.

Sorry if I was being unclear with my compound snark, but using a MIFARE Classic of any provenance would be a firing offense for the CISO of my daydream company.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#8
post #2

"Should we buy a Chinese knockoff of MIFARE Classic" strikes me as a self-answering question, but I guess that's why I still haven't been promoted to CISO.

You might get promoted to CISO if you can come up with a creative way to quantify the risk. Risk management frameworks can communicate how the impact, likelihood, and possible responses would play out in dollar amounts. With a few proposed ideas for how different risk mitigations would affect the resulting residual risk, non-technical people may be able to adopt your vision for securing the enterprise.

Yes, it also means doing basic things like saying "security is important", "vulnerabilities are bad", and "supply chain risk should be addressed", etc. The more informed you are, the more of a pain this is, at least in my experience (disclaimer: I'm not a CISO).

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#9
The problem is pretty serious, not an esoteric theoretically exploitable vulnerability, but a gaping hole. From the abstract:

> Through empirical research, we discovered a hardware backdoor and successfully cracked its key. This backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards without prior knowledge, simply by accessing the card for a few minutes. Additionally, our investigation into older cards uncovered another hardware backdoor key that was common to several manufacturers.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#10
could somebody ELI5 the threat vector here? I'm not skeptical, I just don't know what to imagine.

backdoor implies somebody can "get in" to my rfid, but rfid's spend most of their time "off the grid". So when my rfid powers up, does the "host" who powered it up also need to be insecure or on an insecure/compromised net?

then... what capabilities would suddenly become possible; unlocking the door is already unlocked, my credit card is already all ready to spend...

or does it simply allow people passing me on the sidewalk to make a copy of my card?

Post reply on HN