Live data from Hacker News

Why the Mythbusters won't do RFID (2008)

youtube.com

41–50 of 66 posts

Re: Why the Mythbusters won't do RFID (2008)

#41

Earlier quoted context omitted.

Found this: http://www.youtube.com/watch?v=vmajlKJlT3U&feature=relat...

I don't really understand the problem to be honest. Maybe someone can explain it to me. Sure it's mildly inconvenient if your CC number gets stolen. But the CC company is the one that foots the bill. In that sense, they are the ones with the best incentive to keep the number secure. If fraudulent transactions instigated by RFID-scanning thieves ever gets to the point where it is a serious concern, I am certain that t…

If they can convince the judges that the cards cannot be skimmed, than the very existence of a record of a transaction with a skimmed RFID is legal proof that you did in fact authorize that transaction with your authentic card. There is absolutely no risk for the card issuer involved.

It is like it was with debit card PINs here in germany, the banks convinced the judges that the cards are absolutely secure so that any fraud was in fact to blame on the card holder who either didn't protect his PIN or was actively trying to defraud the bank.

Re: Why the Mythbusters won't do RFID (2008)

#42
post #2

This is just begging for a little unaffiliated team to do a professional investigation along with a good amateur video producer.

...and decent legal counsel.

What if they're outside North America or Western Europe? Some place with weaker laws?

Re: Why the Mythbusters won't do RFID (2008)

#43
post #41

Earlier quoted context omitted.

I don't really understand the problem to be honest. Maybe someone can explain it to me. Sure it's mildly inconvenient if your CC number gets stolen. But the CC company is the one that foots the bill. In that sense, they are the ones with the best incentive to keep the number secure. If fraudulent transactions instigated by RFID-scanning thieves ever gets to the point where it is a serious concern, I am certain that t…

If they can convince the judges that the cards cannot be skimmed, than the very existence of a record of a transaction with a skimmed RFID is legal proof that you did in fact authorize that transaction with your authentic card. There is absolutely no risk for the card issuer involved. It is like it was with debit card PINs here in germany, the banks convinced the judges that the cards are absolutely secure so that an…

[citation needed] (out of personal interest)

Re: Why the Mythbusters won't do RFID (2008)

#44
post #43
post #41

Earlier quoted context omitted.

If they can convince the judges that the cards cannot be skimmed, than the very existence of a record of a transaction with a skimmed RFID is legal proof that you did in fact authorize that transaction with your authentic card. There is absolutely no risk for the card issuer involved. It is like it was with debit card PINs here in germany, the banks convinced the judges that the cards are absolutely secure so that an…

[citation needed] (out of personal interest)

Here is a citation (in german legalese, sorry for that): http://www.jurpc.de/rechtspr/20000026.htm

Re: Why the Mythbusters won't do RFID (2008)

#46

Earlier quoted context omitted.

...and decent legal counsel.

What if they're outside North America or Western Europe? Some place with weaker laws?

Personally I would call weaker the laws that don't allow you to produce a video like this.

Re: Why the Mythbusters won't do RFID (2008)

#47
post #7
post #3

Can someone that knows about this stuff explain exactly what it is the CC companies don't want us to know?

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

> d) The only thing that should (ideally) be stored on any RFID chip is a unique number

I disagree. This is basically where RFID has its benefits. Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card. This allows the system to work without the huge point of failure that is a central database and the connections to it. They have millions of people passing though thousands of checkpoints, many of them on moving busses. The infrastructure needed to make sure that every single one of these checkpoints can at any given time instantly run a transaction on the central database vs. having autonomous readers that just needs to upload their log every once in a while is huge.

It's basically the difference between mainframes/dumb terminals and P2P.

The problem is that RFID implementers have been cheap with the security on those chips. It's pretty simple to make a secure setup (famous last words....) tried and true ideas from cryptography (public key infrastructure etc..) but these call for more expensive chips, and when the choice is between expensive crypto that works and cheap security-through-obscurity that works until a grad-student is bored for the summer, you're going to go with the latter, of course.

Re: Why the Mythbusters won't do RFID (2008)

#48
post #7

Earlier quoted context omitted.

I'm guessing it's: a) RFID is readable from further away than they'd like you to think. b) You don't know when your RFID card is being read. c) Points a and b make tracking you really easy... for anyone to do. d) The only thing that should (ideally) be stored on any RFID chip is a unique number... not any history (recent transactions), personal data (name/phone/picture), or payment system (think public transport) whe…

> d) The only thing that should (ideally) be stored on any RFID chip is a unique number I disagree. This is basically where RFID has its benefits. Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card. This allows the system to work without the huge point of failure that is a central database and the connections to it. They have millions of peopl…

Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card.

I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall:

1. Someone comes up with an "infinite balance"-hack.

2. Infinite balance cards are sold on a growing scale.

3. Transport company is forced to apply expensive bandaids to contain the problem.

Moreover I don't understand why they don't simply leverage the device that everyone already has in their pocket - the cellphone. The infrastructure would likely cost an order of magnitude less (barcode scanners like in airports, or bluetooth) and more importantly the system would be rather easy to make cryptographically secure because it's all in software.

"But what if I forgot my cellphone at home" - well, same thing if you forgot your RFID card at home.

Re: Why the Mythbusters won't do RFID (2008)

#49
post #15
post #11

Earlier quoted context omitted.

a) it's a radio signal. However low power it is, it gets transmitted huge distances while still being detectable (especially if you capture it multiple times to read through noise). I'd love to take a massive dish (say, 20 foot diameter) & see how many can be captured from inside a neighboring building. b) I have yet to hear of a single RFID card which has a switch on it to address this. It's a big security problem.…

> I'd love to take a massive dish (say, 20 foot > diameter) & see how many can be captured from > inside a neighboring building. Are you talking about active or passive RFID? I was under the impression that most RFID in use is passive. In that case, you'd have to transmit something to get a response, unless you're talking about camping out in an area where lots of cards are going be activated by various things other…

Most applications of RFID by authentication (think door locks) use only unique ID (address) of the card and nothing else. And the communication protocol used by reader works like this: Is there anyone with address starting with 0? ... Starting with 1? Yes. Starting with 10? ... Starting with 11? Yes. ..... So you only have to listen to reader side of communication and guess the last bit.

Re: Why the Mythbusters won't do RFID (2008)

#50

I'm the founder of a company that sells RFID blocking wallets and passport cases http://www.difrwear.com . I met with Adam briefly back in 2008 at HOPE when he gave this talk and gave him one of our wallets. I ended up quite dissaponited they couldn't air the show. Would have brought a lot of awareness to the issue. It is really easy to copy RFID credit cards... all you need to do is go buy a point of sale terminal f…

I totally want to buy one of your wallets but you are currently out of stock on everything except the garish pink ones..
Post reply on HN