Live data from Hacker News

MIFARE Classic: exposing the static encrypted nonce variant [pdf]

eprint.iacr.org

71–80 of 103 posts

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#71

I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you r…

"carding" is also colloquially used to refer to people involved in credit card fraud online. Just FYI in case you get weird looks when you say that.

To an Australian, the only allowable response is "that'll buff out".

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#73

Earlier quoted context omitted.

Possibly so. It just means that based on the report's findings, even if you'd decided to play it safe and buy exclusively from NXP directly (the creators of this ecosystem and owners of the MIFARE trademark), it looks like you could still end up with backdoored hardware.

NXP would probably want to steer you away from mifare classic in the first place, wouldn't they?

Maybe for greenfield deployment… but there’s all the existing infrastructure to support.

I still see classic being installed for door/gate systems in American apartments that are under active construction in 2024. Presumably that’s because resellers either don’t know better or they just have a massive inventory.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#74
post #16
post #14

Earlier quoted context omitted.

The idea is that by spending a few minutes with your card, someone can now clone it and impersonate you. Yes, they could already steal your card, but you might notice that. But if you leave it on your desk for a few minutes in your wallet, or IT “borrows” it to re-encode it, or any thousand of other ways to get a hold of your RFID card… it can be dumped, cloned, and you can be impersonated. That’s the threat vector.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

The term behind enabling prevention for this is ‘anti pass back’. It exists but is not commonly implemented outside of high/very high security areas.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#75

I've been involved with carding for 10+ years and issues with MIFARE Classic cards have been around and known for at least that long. Anyone in the carding industry will (should at the very least) tell you not to use them and move on to DESFire or some other newer safer chips. The introduction even says as much "By 2024, we all know MIFARE Classic is badly broken." If you're still deploying MIFARE Classic cards you r…

These cards have hardware backdoors. Their generation or type doesn't matter.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#76
post #69
post #62

Earlier quoted context omitted.

Yup… the vending machines at my university used to use mifare classic tokens with credit on such tokens… in like 2014 i was a student and ran out of money in the middle of july and barely had the money to buy a train ticket to go home for vacation… but thanks to mommy mifare i managed to survive on sandwiches from said vending machines for like two weeks. Oh, to be young again.

The main point from that is that you should never do a system with stored value on a smart card. The vendors will show you various methods for that, but well it is 2024, just do that online (and the card is just an ID, which optionally can produce ECC signature of some challenge).

having a pos in places without a reliable internet connection is enough of a reason for stored value cards to be a thing. Some things shouldn't require the mothership to be alive and reachable to work.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#77
post #55
post #29

Earlier quoted context omitted.

But places that actually take access control seriously do implement bidirectional badging, and just opening the door to leave without badging out will send a group of people bearing guns in your direction right away.

You'd think that, but, as someone who did a phyiscal pentest on a prison recently, that's 1000% not the case. You can set up your access controllers for anti-passback, but, most folks don't, because companies don't want to pay the costs associated for an 'in' reader and and 'out' reader and implement that level of security.

Not to mention having to train your people on why it matters. In most places, that's going to... never happen.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#78
post #76
post #69

Earlier quoted context omitted.

The main point from that is that you should never do a system with stored value on a smart card. The vendors will show you various methods for that, but well it is 2024, just do that online (and the card is just an ID, which optionally can produce ECC signature of some challenge).

having a pos in places without a reliable internet connection is enough of a reason for stored value cards to be a thing. Some things shouldn't require the mothership to be alive and reachable to work.

You're not wrong, but that is precisely the tradeoff: stored-value is more reliable but also more vulnerable.

It's reminiscent of the old NASA saying: "faster, better, cheaper: pick any two".

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#79
post #16
post #14

Earlier quoted context omitted.

The idea is that by spending a few minutes with your card, someone can now clone it and impersonate you. Yes, they could already steal your card, but you might notice that. But if you leave it on your desk for a few minutes in your wallet, or IT “borrows” it to re-encode it, or any thousand of other ways to get a hold of your RFID card… it can be dumped, cloned, and you can be impersonated. That’s the threat vector.

Super curious to know how many common access control solutions flag unbalanced entries/exits. E.g. if "John" badges in... and then 10 minutes later "John" badges in again... Will most systems complain?

I know many companies I worked for in CA and CO did that at least for their parking garage gates but NOT for their building control readers, even though it was the same badge.

Re: MIFARE Classic: exposing the static encrypted nonce variant [pdf]

#80
post #55
post #29

Earlier quoted context omitted.

But places that actually take access control seriously do implement bidirectional badging, and just opening the door to leave without badging out will send a group of people bearing guns in your direction right away.

You'd think that, but, as someone who did a phyiscal pentest on a prison recently, that's 1000% not the case. You can set up your access controllers for anti-passback, but, most folks don't, because companies don't want to pay the costs associated for an 'in' reader and and 'out' reader and implement that level of security.

I was talking more SCIF, less prison.
Post reply on HN