Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 23 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow RFID's Security Problem - Are New Passports and Drivers Licenses Secure?
Ethical Hacker Community Forums
January 08, 2009, 09:46:47 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: RFID's Security Problem - Are New Passports and Drivers Licenses Secure?  (Read 1038 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2439


Editor-In-Chief


View Profile WWW
« on: December 22, 2008, 11:04:48 AM »

Nice read in MIT's Technology Review by Erica Naone:

Quote

Are U.S. passport cards and new state driver's licenses with RFID truly secure?

Starting this summer, Americans will need passports to travel to Canada, Mexico, Bermuda, and the Caribbean--unless they have passport cards or one of the enhanced driver's licenses that the states of Washington and New York have begun to issue.

Valid only for trips by land and sea, these new forms of identification are a convenient, inexpensive option for people who don't need to travel by plane. U.S. passport cards, which were introduced in July, cost about half as much as a full passport, and the extra cost of getting an enhanced driver's license rather than a regular one is even lower. Enhanced licenses have been available in Washington since January 2008 and in New York since September; other border states, including Michi­gan, Vermont, and Arizona, intend to offer them as well.

But not everyone is convinced that the new IDs are a good idea. The passport card and the enhanced licenses contain radio frequency identification (RFID) tags, which are microchips fitted with antennas. An RFID reader can radio a query to the tag, causing it to return the data it contains--in this case, an identification number that lets customs agents retrieve information about the cardholder from a government database. The idea is that instant access to biographical data, a photo, and the results of terrorist and criminal background checks will help agents move people through the border efficiently. RFID technology, however, has been raising privacy concerns since it was introduced in product labels in the early 2000s.

Meanwhile, although experts say that some RFID technologies are quite secure, a University of Virginia security researcher's analysis of the NXP Mifare Classic (see Hack, November/December 2008), an RFID chip used in fare cards for the public-­transit systems of ­Boston, London, and other cities, has shown that the security of smart cards can't be taken for granted. "I think we are in the growing-pains phase," says Johns Hopkins University computer science professor Avi Rubin, a security and privacy researcher. "This happens with a lot of technologies when they are first developed."

Borderline Security

The first of the new ID cards to be introduced, the federal passport cards and the Washington driver's licenses use similar technology, which has been reviewed and approved by the U.S. Department of Homeland Security. The cards' RFID devices, called electronic product code (EPC) tags, are much like bar codes. The tags are inexpensive and can, in ideal conditions, be read from about 150 feet away--an unusually long range for RFID, says Ari Juels, director and chief scientist at RSA Laboratories in Bedford, MA, which collaborated with researchers from the University of Washington to evaluate both cards.


For complete article:
http://www.technologyreview.com/computing/21842/?a=f

Don
Logged

CISSP, MCSE, CEH, Security+ SME
jason
Sr. Member
****
Offline Offline

Posts: 366


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #1 on: December 22, 2008, 10:08:25 PM »

Two seconds in the microwave = problem solved. This tends to leave the tiniest of burn marks in some cases, but nothing visible without very close inspection.
Logged
jason
Sr. Member
****
Offline Offline

Posts: 366


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #2 on: December 26, 2008, 08:32:39 PM »

Or you could do the anti-RFID wallet:

Buy one http://www.thinkgeek.com/gadgets/security/8cdd/

or build your own http://www.rpi-polymath.com/ducttape/RFIDWallet.php

I'm personally dreading arrival of the IED tuned to American passports.
Logged
ElCapitan
Newbie
*
Offline Offline

Posts: 9


Unanimous FTP: the #1 threat to copyrights!


View Profile
« Reply #3 on: December 26, 2008, 10:24:26 PM »

I would be careful with using a microwave to disable the RFID. Wired had a good article on this, recommending "blunt force" to disable the chip:

http://www.wired.com/wired/archive/15.01/start.html?pg=9
Logged
jason
Sr. Member
****
Offline Offline

Posts: 366


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #4 on: December 26, 2008, 10:27:42 PM »

One of my co-workers just did the microwave bit. He said it made a huge spark and left the tiniest of pinhole burns in the cover. Nothing noticeable without very close inspection.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.041 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.