Live data from Hacker News

Why the Mythbusters won't do RFID (2008)

youtube.com

21–30 of 66 posts

Re: Why the Mythbusters won't do RFID (2008)

#21
post #11
post #7

Earlier quoted context omitted.

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

Imagine how many you could collect on your way to and from work each day in heavy traffic?

Re: Why the Mythbusters won't do RFID (2008)

#22
post #16
post #10

Well Adam has stated in at least one interview that he reads Hacker News regularly so maybe we'll have a nice anonymous reply :)

I was curious about the validity of your statement so I did a little digging. It's true, he even mentions that he reads it on a daily basis. Source: http://www.youtube.com/watch?v=J8jqea8R-bE [edit] if you don't want to watch the whole 3 part video: http://www.youtube.com/watch?v=fFcVaFhKd_4#t=08m32s

You could use (also on HN front page) http://speakertext.com for linking to that. Just thought it was a neat instance!

Re: Why the Mythbusters won't do RFID (2008)

#23

Thankfully with a community named 'HackerNews' hopefully somebody here will be inspired to look into it deeper and see if they can do the show that networks can't do. What's required to figure out how to hack these chips which are clearly readily available?

This is actually an active research area so a google scholar search can turn up interesting stuff from various security conferences. Here's a summary of what I've read and heard about:

If a chip has unecrypted personal data stored on it an attacker can easily gain access to it by stealing the device. If encryption is used throughout the chip then side channel attacks can usually break the encryption. This requires something like an oscilloscope, some resistors, and a soldering iron. The danger of this attack to a consumer depends upon what's stored on the RFID chip since the consumer will notice if someone has stolen their device and will have it disabled in short order.

To clone a tag that doesn't use encryption, for instance a tag that just sends an ID, you'd need a reader to query the tags and some device to copy the responses. This is probably the easiest attack but the reader, which needs to transmit a strong radio pulse and then listen for a response, either needs to be very large or in very close proximity and you could protect a card in your wallet by surrounding it in a metal mesh (which forms a faraday cage) so it's not clear how dangerous this could be in the wild.

If the communcation channel is encrypted then an attacker could listen to the query and response from a legitimate reader and RFID tag and could then replicate the legitimate response later. However, if there is any timestamp or counter involved this won't work.

Re: Why the Mythbusters won't do RFID (2008)

#26
post #12

Earlier quoted context omitted.

Wonderful. Which account do we believe now?

This was discussed on No Agenda recently as an example of why corporate advertising is bad for media that does this kind of work (although Mythbusters rarely broaches subjects that run against corporate culture). It seems odd Adam would have made up his original account, but only he knows the real story at this point.

[deleted]

Re: Why the Mythbusters won't do RFID (2008)

#27
post #12

Earlier quoted context omitted.

Wonderful. Which account do we believe now?

This was discussed on No Agenda recently as an example of why corporate advertising is bad for media that does this kind of work (although Mythbusters rarely broaches subjects that run against corporate culture). It seems odd Adam would have made up his original account, but only he knows the real story at this point.

Found this: http://www.youtube.com/watch?v=vmajlKJlT3U&feature=relat...

Re: Why the Mythbusters won't do RFID (2008)

#28
post #15
post #11

Earlier quoted context omitted.

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

> I'd love to take a massive dish (say, 20 foot > diameter) & see how many can be captured from > inside a neighboring building. Are you talking about active or passive RFID? I was under the impression that most RFID in use is passive. In that case, you'd have to transmit something to get a response, unless you're talking about camping out in an area where lots of cards are going be activated by various things other…

So say a 5-foot range. Find a group of employees out for lunch together and I walk past the table with a backpack on. Hardly suspicious, and I've probably got most of their building access cards.

Re: Why the Mythbusters won't do RFID (2008)

#29
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

They don't want you to know that the microchips in their cards can be reprogrammed so that you can wave it at reader and emulate somebody else's CC#, or that you can program any compliant RFID chip to communicate with those wavey card readers to the same effect, or that you can plant an RFID reader on an ATM or similar point and "skim" CC info without needing the user to explicitly swipe their card. That's just a few…

You thought credit-card skimming was bad when the skimmer had to be physically attached to the ATM? http://krebsonsecurity.com/2010/01/would-you-have-spotted-th... Now imagine trying to find something that concealable anywhere in a 5 or 10-foot radius of the ATM itself. Hiding the card inside a metal wallet won't help you there.

Re: Why the Mythbusters won't do RFID (2008)

#30
post #4

Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote) Here's the link: http://news.cnet.com/8301-13772_3-10031601-52.html September 3, 2008 10:59 AM PDT 'MythBusters' co-host backpedals on RFID kerfuffle

Adam Curry argued convincingly that the hasty follow-up was b.s.
Post reply on HN