Live data from Hacker News

MIFARE Classic: exposing the static encrypted nonce variant [pdf]

eprint.iacr.org

31–40 of 103 posts

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#31
post #24

Earlier quoted context omitted.

Probably fire safety laws

Yes, locking people into buildings (which is what you are doing if you need a key to get out, whether it's an RFID badge or a skeleton key) has been illegal since the Triangle Shirtwaist Factory Fire

As I mentioned in a sibling comment, you don't lock them in, you just set off major alarms and send an armed response if the door ever opens without badge activation. This presupposes some things about the facility and the facility operator, though.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#33
post #16
post #14

Earlier quoted context omitted.

The idea is that by spending a few minutes with your card, someone can now clone it and impersonate you. Yes, they could already steal your card, but you might notice that. But if you leave it on your desk for a few minutes in your wallet, or IT “borrows” it to re-encode it, or any thousand of other ways to get a hold of your RFID card… it can be dumped, cloned, and you can be impersonated. That’s the threat vector.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

I used to work on such systems in another life, we could setup antipass back for a gate or area. I believe we could also put a temporal restriction but my memory is a bit fuzzy.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#34
post #9

The problem is pretty serious, not an esoteric theoretically exploitable vulnerability, but a gaping hole. From the abstract: > Through empirical research, we discovered a hardware backdoor and successfully cracked its key. This backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards without prior knowledge, simply by accessing the card for a few minutes. Additionally, our…

[deleted]

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#35
I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you reap what you sow.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#38
post #10

could somebody ELI5 the threat vector here? I'm not skeptical, I just don't know what to imagine. backdoor implies somebody can "get in" to my rfid, but rfid's spend most of their time "off the grid". So when my rfid powers up, does the "host" who powered it up also need to be insecure or on an insecure/compromised net? then... what capabilities would suddenly become possible; unlocking the door is already unlocked,…

Most RFID card systems in the world uses MIFARE Classic due to its cost and long history. MIFARE (not just the Classic family) have a UID (32 bits) and x blocks of encrypted data (12 for Classic). Each block is protected by a A key and a B key. The earliest card system only uses UID for authentication ie. if the card says the right UID the card passes authentication. Obviously, anyone can forge a card with said UID,…

> The paper seems to found a hardcoded A/B key A396EFA4E24F for a particular brand of RFID cards (I just skimped the paper and its been years since I worked on RFID. I might be wrong on the detail).

Actually, if I understood the paper well, the same key worked also on older, non-Chinese cards like those produced by NXP. Why, that's a big question.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#39

Earlier quoted context omitted.

The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.

They could have licensed the IP from the same company.

... or used the IP without licensing.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#40
post #11
post #7

Earlier quoted context omitted.

Sorry if I was being unclear with my compound snark, but using a MIFARE Classic of any provenance would be a firing offense for the CISO of my daydream company.

What's a good alternative? How more expensive is it?

MIFARE DESFire is an option. In a genral public reseller, I found 100 DESFire cards sold for 146€ (tax excluded), while 100 of the equivalent versions as MIFARE Classic are sold for 109€ (tax excluded). This is a differnce of 37 cents by card, MIFARE Classic are about 25% less expensive than MIFARE DESFire. I guess the difference increase with the quantity you buy at once.
Post reply on HN