Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 57 guests online
You are here:
Home
Features
Opinions
Disney and RFID bracelets.....
EH-Net
May 24, 2013, 07:05:56 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Features
>
Opinions
(Moderator:
don
) >
Disney and RFID bracelets.....
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Disney and RFID bracelets..... (Read 8551 times)
0 Members and 1 Guest are viewing this topic.
hayabusa
Hero Member
Offline
Posts: 1633
Disney and RFID bracelets.....
«
on:
January 08, 2013, 03:47:43 PM »
Whose briliant idea is it to put RFID bracelets on hundreds of thousands of 'visitors', linked to credit card info... This can only get worse...
http://news.discovery.com/tech/disney-world-track-fantasy-130108.html#mkcpgn=rssnws1
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: Disney and RFID bracelets.....
«
Reply #1 on:
January 09, 2013, 09:28:25 AM »
Even without the credit card info, I still don't like when companies gather info on my purchases and shopping habits.
But I guess we get monitored all the time now...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Grendel
Full Member
Offline
Posts: 242
Re: Disney and RFID bracelets.....
«
Reply #2 on:
January 09, 2013, 09:59:02 AM »
WANT!
But then again, I'm a HUGE Disneyworld nerd.
FTA: "My Disney Experience that will enable users of MyMagic+ to select three FastPasses for rides" - that's huge for anyone going there.
In short, this would definitely suck me in and give up my CC info / shopping preferences / etc. Shame on me, but a big enough carrot and people will do anything (including me, it seems).
Logged
- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM
Web Site:
http://HackingDojo.com
Author:
Professional Penetration Testing
Ninja Hacking
Penetration Tester's Open Source Toolkit
Metasploit Toolkit for Penetration Testing
Netcat Power Tools
hayabusa
Hero Member
Offline
Posts: 1633
Re: Disney and RFID bracelets.....
«
Reply #3 on:
January 09, 2013, 01:45:18 PM »
Yeah... I can see the 'draw', but I also foresee HUGE issues, liability, and headache in their future...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
chrisj
Hero Member
Offline
Posts: 1163
Re: Disney and RFID bracelets.....
«
Reply #4 on:
January 09, 2013, 03:06:23 PM »
I agree with Haybusa, how hard will it be to clone and rewrite on something else. wear one of those running id holders
like the one here
.
Not like you have to leave the park. If done right, a Crym could charge lots of crap to someone, and it'll be harder to dispute with the company. small enough charges don't have to show id. And think if that Crym was someone working at the park, in that micky costume. Ask little Billy how long they're there for, making small talk, and suddenly know how long he has to use that family's account
I think that this shows that Disney is out of touch slightly. they only think of this from the privacy side. didn't see anything talking about the fraud side.
Logged
OSWP, Sec+
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Disney and RFID bracelets.....
«
Reply #5 on:
January 09, 2013, 03:30:50 PM »
I don't have any further information about how Disney plans to implement this, but fraud within the parks would be very easy to detect. They're using RFID to track visitors. Each RFID chip will be uniquely identifiable, so they would be able to detect you pulling Fast Passes at the Magic Kingdom while simultaneously shopping at Downtown Disney.
The question is, will they implement fraud detection in the system? If the fraud becomes rampant enough that they're losing money, they will.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
hayabusa
Hero Member
Offline
Posts: 1633
Re: Disney and RFID bracelets.....
«
Reply #6 on:
January 09, 2013, 06:33:21 PM »
Agreed that, if done right, they'll hopefully at least minimize their exposure. For instance, a user in line for a ride with a 'quick pass' from their bracelet VERY likely isn't in a store half-way across the park, at the same moment. Still, with the sheer number of the bracelets that could potentially be in use, daily, it's a guarantee that someone WILL exploit things, somehow.
Perhaps a required passphrase if in the stores, etc, to go with the bracelets, so that, at least then, there's MUCH less chance of excess abuse / spending. At least that way, they'd really need to both 'drive by' scan the rfid AND shoulder surf, to get the passphrase.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
chrisj
Hero Member
Offline
Posts: 1163
Re: Disney and RFID bracelets.....
«
Reply #7 on:
January 09, 2013, 08:49:29 PM »
I think it would depend how how they set the system up to begin with. The biggest thing I can think of, one family all using the same card. So that could mean that some are in one area, some in other buying at the same time. think Dad and son on the rides, mom and daughter shopping.
So, how much information do they need to actually make the sale. How much do they read. And what parts could be re-written.
If I knew more about rewriting the stuff, I'd love to get my hands on a couple just to see.
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: Disney and RFID bracelets.....
«
Reply #8 on:
January 10, 2013, 08:30:15 AM »
We don't know how they will implement this system. It would be nice to get more details on their implementation.
Suppose they do something like this:
1) Only adults can have credit card info on their bracelets
2) 2 factor authentication: You need the bacelet and a 5 digit pins (for example)
3) There is a fraud detection mechanism in place
4) Once your holiday at Disney is over, the bracelet doesn't work anymore (so you couldn't buy anything with it at Disney Marketplace for example)
5) You can only allow a max of $500 per day (to limit the damages)
6) You are still protected by the credit card company insurance
We also have to keep in mind that the bracelet will only have an ID with it. So a potential thief couldn't use this information outside Disney's walls.
I believe that all these combined wouldn't be too bad. And don't forget, there are still pick pockets that can easily still your wallet while you wait in line...
What do you guys think?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
chrisj
Hero Member
Offline
Posts: 1163
Re: Disney and RFID bracelets.....
«
Reply #9 on:
January 10, 2013, 02:36:48 PM »
I'm still wondering if you could just over write the cc info and go from there. All your other data matches, but charging to someone else's card.
As for the pickpockets, those are still around. Like anything else, you have to worry about the hotel staff, card skimmers, child abductors, etc. I just think that Disney is looking at weakening their security posture by chasing something easy to use.
Personally, and this is just my opinion, I don't think the magic kingdom bracelets will last long.
Logged
OSWP, Sec+
Grendel
Full Member
Offline
Posts: 242
Re: Disney and RFID bracelets.....
«
Reply #10 on:
January 10, 2013, 06:34:52 PM »
Quote from: H1t M0nk3y on January 10, 2013, 08:30:15 AM
We also have to keep in mind that the bracelet will only have an ID with it. So a potential thief couldn't use this information outside Disney's walls.
All the relevant information will indeed be in the system, not on the RFID. Yes, you can replicate the RFID signal, but unless it interacts with Disney's computers, the RFID info will be useless. It does look like they stamp a first name on the actual bracelet, but no last name.
There is also a pin required for purchases over $50, and if you don't want the RFID associated with a CC, you don't have to have them include it (similar with the room keys for those staying in a Disney resort). In fact, you don't have to have any information on it - in which case you just use it for fastpass+.
Logged
- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM
Web Site:
http://HackingDojo.com
Author:
Professional Penetration Testing
Ninja Hacking
Penetration Tester's Open Source Toolkit
Metasploit Toolkit for Penetration Testing
Netcat Power Tools
hayabusa
Hero Member
Offline
Posts: 1633
Re: Disney and RFID bracelets.....
«
Reply #11 on:
January 10, 2013, 09:30:30 PM »
That sounds much more thought out.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.