Live data from Hacker News

MIFARE Classic: exposing the static encrypted nonce variant [pdf]

eprint.iacr.org

21–30 of 103 posts

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#21
post #16
post #14

Earlier quoted context omitted.

The idea is that by spending a few minutes with your card, someone can now clone it and impersonate you. Yes, they could already steal your card, but you might notice that. But if you leave it on your desk for a few minutes in your wallet, or IT “borrows” it to re-encode it, or any thousand of other ways to get a hold of your RFID card… it can be dumped, cloned, and you can be impersonated. That’s the threat vector.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

From experience, more places than you'd expect only have you badging in one direction and not both.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#22

Earlier quoted context omitted.

They could have licensed the IP from the same company.

Possibly so. It just means that based on the report's findings, even if you'd decided to play it safe and buy exclusively from NXP directly (the creators of this ecosystem and owners of the MIFARE trademark), it looks like you could still end up with backdoored hardware.

NXP would probably want to steer you away from mifare classic in the first place, wouldn't they?

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#23

Earlier quoted context omitted.

The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.

They could have licensed the IP from the same company.

I think it's more likely those NXP/Infineon parts are counterfeits. Look at A.12, there are early cards that don't NACK $F000 but claim to be NXP or Infineon, behavior counter to legit parts. It looks like the Chinese copies started to chameleon that behavior later as well.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#24
post #21
post #16

Earlier quoted context omitted.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

From experience, more places than you'd expect only have you badging in one direction and not both.

Probably fire safety laws

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#25
post #14

Earlier quoted context omitted.

The idea is that by spending a few minutes with your card, someone can now clone it and impersonate you. Yes, they could already steal your card, but you might notice that. But if you leave it on your desk for a few minutes in your wallet, or IT “borrows” it to re-encode it, or any thousand of other ways to get a hold of your RFID card… it can be dumped, cloned, and you can be impersonated. That’s the threat vector.

In the case of this attack, somewhere between 40s and 30min of physical access, depending on how the card was set up. In the case of a hotel, the spicy card to clone would be the cleaning staff's, which conveniently also admits a reasonable explanation for the card going temporarily missing (e.g. abandon it one corridor over, oops must have dropped it while doing the rounds). Depending on the specifics of a deploymen…

> But I don't know nearly enough about how these cards get used to know how much flexibility you get there.

A lot of systems still just use the UID.

Physical security/door access control is still completely disconnected from IT security, despite these systems relying on software for the last 20 years. As such, there is generally no knowledge in the buyers of such systems as to the risks and how to test for any vulnerabilities.

I bet systems which rely on the UID only (something even the card manufacturer specifically warns against in their datasheet) are still being sold, and lots are definitely still out there. This is trivial to clone and requires only a single read of the card, no cracking needed because the UID isn’t designed to be private to begin with.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#26
post #10

could somebody ELI5 the threat vector here? I'm not skeptical, I just don't know what to imagine. backdoor implies somebody can "get in" to my rfid, but rfid's spend most of their time "off the grid". So when my rfid powers up, does the "host" who powered it up also need to be insecure or on an insecure/compromised net? then... what capabilities would suddenly become possible; unlocking the door is already unlocked,…

Backdoor root access to instantaneously clone any affected RFID card with one of the chipsets listed on the second to last page.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#27
post #9

The problem is pretty serious, not an esoteric theoretically exploitable vulnerability, but a gaping hole. From the abstract: > Through empirical research, we discovered a hardware backdoor and successfully cracked its key. This backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards without prior knowledge, simply by accessing the card for a few minutes. Additionally, our…

[deleted]

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#28
post #24
post #21

Earlier quoted context omitted.

From experience, more places than you'd expect only have you badging in one direction and not both.

Probably fire safety laws

Yes, locking people into buildings (which is what you are doing if you need a key to get out, whether it's an RFID badge or a skeleton key) has been illegal since the Triangle Shirtwaist Factory Fire

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#29
post #21
post #16

Earlier quoted context omitted.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

From experience, more places than you'd expect only have you badging in one direction and not both.

But places that actually take access control seriously do implement bidirectional badging, and just opening the door to leave without badging out will send a group of people bearing guns in your direction right away.
Post reply on HN