Earlier quoted context omitted.
That would be a terrible user experience. Most places are not diligent about ensuring each employee separately badges past a barrier. Common to hold the door for Bob while he is juggling a coffee. Boom, missed badge swipe and now things are forever imbalanced.
If you care about this at all you’d use a turnstile.
MIFARE Classic: exposing the static encrypted nonce variant [pdf]
61–70 of 103 posts
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#62I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you r…
Oh, to be young again.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#63"Should we buy a Chinese knockoff of MIFARE Classic" strikes me as a self-answering question, but I guess that's why I still haven't been promoted to CISO.
The paper reports that the same backdoor seems to be present in some NXP and Infineon SKUs as well, including some manufactured in Europe.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#64I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you r…
"carding" is also colloquially used to refer to people involved in credit card fraud online. Just FYI in case you get weird looks when you say that.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#65Earlier quoted context omitted.
Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?
That would be a terrible user experience. Most places are not diligent about ensuring each employee separately badges past a barrier. Common to hold the door for Bob while he is juggling a coffee. Boom, missed badge swipe and now things are forever imbalanced.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#66Earlier quoted context omitted.
Probably fire safety laws
Yes, locking people into buildings (which is what you are doing if you need a key to get out, whether it's an RFID badge or a skeleton key) has been illegal since the Triangle Shirtwaist Factory Fire
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#67could somebody ELI5 the threat vector here? I'm not skeptical, I just don't know what to imagine. backdoor implies somebody can "get in" to my rfid, but rfid's spend most of their time "off the grid". So when my rfid powers up, does the "host" who powered it up also need to be insecure or on an insecure/compromised net? then... what capabilities would suddenly become possible; unlocking the door is already unlocked,…
Most RFID card systems in the world uses MIFARE Classic due to its cost and long history. MIFARE (not just the Classic family) have a UID (32 bits) and x blocks of encrypted data (12 for Classic). Each block is protected by a A key and a B key. The earliest card system only uses UID for authentication ie. if the card says the right UID the card passes authentication. Obviously, anyone can forge a card with said UID,…
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#68Earlier quoted context omitted.
Most RFID card systems in the world uses MIFARE Classic due to its cost and long history. MIFARE (not just the Classic family) have a UID (32 bits) and x blocks of encrypted data (12 for Classic). Each block is protected by a A key and a B key. The earliest card system only uses UID for authentication ie. if the card says the right UID the card passes authentication. Obviously, anyone can forge a card with said UID,…
Would you happen to know of a good reference for this? I have a Proxmark and I'd like to learn how the encryption works so I can play around with (and maybe clone) some of my cards.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#69I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you r…
Yup… the vending machines at my university used to use mifare classic tokens with credit on such tokens… in like 2014 i was a student and ran out of money in the middle of july and barely had the money to buy a train ticket to go home for vacation… but thanks to mommy mifare i managed to survive on sandwiches from said vending machines for like two weeks. Oh, to be young again.
Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]
#70Earlier quoted context omitted.
In the case of this attack, somewhere between 40s and 30min of physical access, depending on how the card was set up. In the case of a hotel, the spicy card to clone would be the cleaning staff's, which conveniently also admits a reasonable explanation for the card going temporarily missing (e.g. abandon it one corridor over, oops must have dropped it while doing the rounds). Depending on the specifics of a deploymen…
> But I don't know nearly enough about how these cards get used to know how much flexibility you get there. A lot of systems still just use the UID. Physical security/door access control is still completely disconnected from IT security, despite these systems relying on software for the last 20 years. As such, there is generally no knowledge in the buyers of such systems as to the risks and how to test for any vulner…