Live data from Hacker News

Why the Mythbusters won't do RFID (2008)

youtube.com

31–40 of 66 posts

Re: Why the Mythbusters won't do RFID (2008)

#33
post #11
post #7

Earlier quoted context omitted.

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building.

For active RFID, maybe you'd grab quite a bit.

You'd also grab quite a bit of noise. These are very low power signals; restricted by regulations in at least Australia, N.America, but it could still work. It did on 2005: http://blog.makezine.com/archive/2005/07/_defcon_rfid_world_...

Re: Why the Mythbusters won't do RFID (2008)

#34
post #33
post #11

Earlier quoted context omitted.

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. For active RFID, maybe you'd grab quite a bit. You'd also grab quite a bit of noise. These are very low power signals; restricted by regulations in at least Australia, N.America, but it could still work. It did on 2005: http://blog.makezine.com/archive/2005/07/_defcon_rfid_world_...

An important note on the 69-foot record in 2005 you linked: they've just got two antennas, no focusing dish at all.

If someone comes along with a powerful rig, say using some of the techniques astronomers have had for many years to detect far weaker signals, what sort of distance might we be talking? It's not too far-fetched if you include possible corporate / governmental espionage attempts.

Re: Why the Mythbusters won't do RFID (2008)

#35
post #4

Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote) Here's the link: http://news.cnet.com/8301-13772_3-10031601-52.html September 3, 2008 10:59 AM PDT 'MythBusters' co-host backpedals on RFID kerfuffle

I don't think anyone buys that follow-up: the original story sound very authentic and is told in a frank Adam-Savage-like manner. The follow-up: not so much. Of course, this is my characterization of my perception of the stories and may be influenced by, for instance, a predisposition towards believing the first story.

Re: Why the Mythbusters won't do RFID (2008)

#36
post #15
post #11

Earlier quoted context omitted.

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

> I'd love to take a massive dish (say, 20 foot > diameter) & see how many can be captured from > inside a neighboring building. Are you talking about active or passive RFID? I was under the impression that most RFID in use is passive. In that case, you'd have to transmit something to get a response, unless you're talking about camping out in an area where lots of cards are going be activated by various things other…

I vaguely remember an article from around the time RFID passports were a hot issue, in which researchers used multiple capturing devices and were able to square the reading distance. I don't know whether that was specific to the distance they used, the type of RFID, or even an upper limit, but it was an unbelievable improvement.

Re: Why the Mythbusters won't do RFID (2008)

#37
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I wrote an article about the security of passive RFID tags at school about a year ago: http://kimjoar.net/security-passive-rfid-tags.html. There you might find some interesting stuff regarding your question. RFID is very cool, but there are still a lot of (unsolved) security problems with them, especially the passive tags.

Re: Why the Mythbusters won't do RFID (2008)

#38
post #12

Earlier quoted context omitted.

This was discussed on No Agenda recently as an example of why corporate advertising is bad for media that does this kind of work (although Mythbusters rarely broaches subjects that run against corporate culture). It seems odd Adam would have made up his original account, but only he knows the real story at this point.

Found this: http://www.youtube.com/watch?v=vmajlKJlT3U&feature=relat...

I don't really understand the problem to be honest. Maybe someone can explain it to me.

Sure it's mildly inconvenient if your CC number gets stolen. But the CC company is the one that foots the bill. In that sense, they are the ones with the best incentive to keep the number secure. If fraudulent transactions instigated by RFID-scanning thieves ever gets to the point where it is a serious concern, I am certain that the companies will act in their own best interest to curb the behavior. In the mean time, who cares if they lose some money?

Re: Why the Mythbusters won't do RFID (2008)

#39
I'm the founder of a company that sells RFID blocking wallets and passport cases http://www.difrwear.com. I met with Adam briefly back in 2008 at HOPE when he gave this talk and gave him one of our wallets.

I ended up quite dissaponited they couldn't air the show. Would have brought a lot of awareness to the issue. It is really easy to copy RFID credit cards... all you need to do is go buy a point of sale terminal from eBay, poke the little speaker that beeps when it reads a card with a needle and then plug it into a laptop and you've got a skimmer.....

Re: Why the Mythbusters won't do RFID (2008)

#40

Earlier quoted context omitted.

Found this: http://www.youtube.com/watch?v=vmajlKJlT3U&feature=relat...

I don't really understand the problem to be honest. Maybe someone can explain it to me. Sure it's mildly inconvenient if your CC number gets stolen. But the CC company is the one that foots the bill. In that sense, they are the ones with the best incentive to keep the number secure. If fraudulent transactions instigated by RFID-scanning thieves ever gets to the point where it is a serious concern, I am certain that t…

There is a "time wasted dealing with my credit card beign stolen" bit that most folks don't attach too much value to until it happens.
Post reply on HN