Showing posts sorted by relevance for query rfid. Sort by date Show all posts
Showing posts sorted by relevance for query rfid. Sort by date Show all posts

Tuesday, May 22, 2007

RFID Security In The News Again

Since I took so much time with my EMT class, I'm just now catching up on some news items I bookmarked during the semester. Here are a couple regarding RFID technology, which I regard as a potential security nightmare if not implemented right.

Larry Seltzer has a very good item which was posted to eWeek.com back in March: Uncle Sam's Got an RFID Jones.

Larry hits some very good points both for and against RFID technology using the new, voluntary test program in Washington State where drivers licenses are offered with RFID technology. In the Washington test, the license's RFID chip would only store a unique code which would be linked to the user's personal information stored in a central database. Although using RFID in this way may be safer for those who use it, it's still not a fool proof way to safeguard a persons information. Better implementation? Yes. Totally secure? No way.

I am a realist about computer security. Any data stored anywhere can be exploited given the proper circumstances. Still, I hold my opinion that RFID opens up a security hole big enough to drive a truck through. I agree with Larry on one point: bar codes on licenses can do pretty much the same things RFID can do. Bar codes are not as convenient, but they are a lot easier to safeguard.

Another item I found, also on eWeek.com, was RFID Feared as Possible Terrorist Target by Lisa Vaas. She brings up information on a study by the British Royal Academy which points out that RFID technology could be used to aid terrorists who want to target a particular person or group. In this scenario, the terrorists would plant a bomb somewhere they knew their target would be, set the RFID reader to react when the targeted person came within range of the reader and set off the bomb. In this instance, even if the person's personal data were stored elsewhere and the RFID tag in his/her identification were only encoded with a unique identifier, that unique identifier could be the thing which would set off the bomb.

For now, I'm going to hang on to my opinion that RFID can be useful, but that incorporating it into a system for identification is not a good use for it.

Saturday, February 07, 2009

RFID Passports and Drivers Licenses Compromise Your Personal Data

RFID has great value as it is used today. It also has many excellent potential uses. However, it is totally unsuitable for use in a personal identification system.

Many times I've written about the potential dangers of personal identification cards and passports equipped with Radio Frequency Identification (RFID) technology. You can check them out here. My aim in this is not to bash the technology because it has many excellent applications. My objections are strictly limited to RFID-equipped personal identification.

What the problem with RFID?
The inherent flaw in using RFID in identification cards is the very thing which makes it excellent in other applications: The RFID chip sends out a signal containing a small amount of data which a receiver can detect and pass along to a computer. While this is great for companies like Walmart to track inventory going in and out of a store, it's not good for a person when anyone can grab their personal information out of thin air just by passing near them.

Proof Is In The Pudding
For those who think my opinions alarmist, allow me to point out two studies which I believe prove my point:

University of Washington and RSA Research
On December 1, 2008, the Consumer Warning Network reported on research done by The University of Washington and RSA Security in October of 2008 which showed data from RFID chips implanted in the new Passport Cards and "Enhanced" drivers licenses can be received from over 150 feet away. Data recovered from such reception could be cloned to another card in less than 5 seconds. These tests were done with off-the-shelf equipment, not exotic technology available only to government agencies. 

Receiving data from that far away, a criminal could position a receiver near a large gathering of people and clone cards to steal a large number of identities. It is fair to point out that personal information is not stored on these cards; only a unique ID code. However, this code is all that's needed to create a cloned card. Eventually, there has to be a way to match that number to personal data stored in a database somewhere. If there is enough desire, criminals could get access to such a database and get the personal information contained in it.

A Practical Demonstration
On Feb 2nd, dailywireless.org posted an item showing how easy it is for someone to go about reading these RFID-equipped cards. Chris Paget demonstrated how to set up a system to read the cards as one drives around a city. Like in the above-mentioned study, he used off-the-shelf equipment in his demonstration. Although he didn't scan a large number of cards, I believe it's because they are not yet widely used. As government agencies issue this type of card, though, there will be more and more of them in circulation to scan. I highly recommend watching the short video which is quite telling.

Not Just Identity Theft
Given that these cards are so easy to read from a far longer distance than government agencies care to admit, it's also important to consider another potential way to exploit this technology: stalking and tracking. It's not difficult to put together a relatively cheap, but sophisticated, RF direction-finding system. Amateur radio operators do this in "fox hunt" competitions to find hidden transmitters. It would not be difficult for anyone to put together a direction-finding system to track a person's movements. In the ultimate "big brother" scenario, it would be a simple matter for government agencies to install direction-finding equipment around a city and use it to track anyone and everyone.

"Computer, what is the current location of Captain Picard?"

Shields Up!
There is one thing the person who has this type of ID card can do to prevent its exploitation: shield it. The issuers of these cards are supposed to provide a sleeve in which to store the card, the idea of which is to prevent the RFID from transmitting outside the person's wallet or purse. While this is a good idea, I believe it is not good enough. I question how many people will actually educate themselves on how RFID works and realize the importance of using such a sleeve. How many will lose or damage the sleeve and not bother to replace it? Although laudable, providing a sleeve is hardly practical.

I recommend you do your own research to learn more about RFID. I believe that as you educate yourself, you will realize RFID in personal identification is not a good idea and will let your elected representatives know about it.

Sunday, March 04, 2007

More RFID Security News

Nixed: Black Hat talk on RFID access badge risks

ACLU, Outrage Fill in the Silence at Black Hat RFID Session

I'm glad to see I'm not the only one who has grave concerns about the security of using Radio Frequency Identification (RFID) technology being used as a form of official ID. During a recent conference, IOActive, a small security firm, was to give a talk on the inherent lack of security in an RFID badge system used by the Federal Emergency Management Agency (FEMA). IOActive has its officed in the same building as FEMA and was curious about how good their security using RFID was.

The people at IOActive were quite successful in showing how vulnerable the RFID badges used are. So successful were they, that the company which developed the system used by FEMA, HID Global, threatened legal action against IOActive if they proceeded with their talk under the guise of protecting their intellectual property. IOActive, being a relatively small company which doesn't have access to legions of attorneys, were forced to skip the portion of their talk which directly illustrated the inherent weaknesses in the badge system HID Global markets, and which is used to access the FEMA offices in the building shared with IOActive.

Even the ACLU took note of this incident. They did their own experiments with RFID technology and found that the RFID standards currently planned to fulfill requirements of the Real ID Act are inherently flawed and will cause more problems than it will solve. As I have pointed out before here and here, it would be remarkably easy for someone to build an RFID reader, walk through a crowd of people carrying RFID enabled devices and gather a large amount of personal information which has the potential of enabling the "bad guys" to steal the identities of the people in that crowd.

I highly encourage everyone to educate themselves on RFID; how it works, how it's used now and how it might be mandated for use later. I believe everyone can understand enough about how it works to be as concerned as I am that it is not a good idea to use a means of personal identification.

Saturday, May 28, 2005

RFID And Your Privacy

Federal report warns of RFID misuses | CNET News.com


Ga. credit-card holders 'blink' cards

Radio Frequency Identification or RFID is a very promising technology. RFID consists of a very small, usually flat, radio transmitter which emits a signal that can be received by a special receiver. The receiver displays the data transmitted by the card, and that data can be used to update a package-tracking database, track inventory, open a door, or complete a credit card transaction. RFID has much potential to make our lives a more convenient.

Privacy advocates, however, should be very vocal in their opposition to using RFID technology as "official" or government identification or as credit or debit cards. Among other potential misuses of RFID, such as tracking people's movements, the same technology which merchants or other entities use to "read" the RFID device could be duplicated by criminals to gather information for fraud or ID theft.

Think about this: you lose your purse or wallet through carelessness or theft. It ends up in the hands of a dishonest person who uses your credit or debit card for a shopping spree. You know your cards are missing so you can call your bank and have the card "turned off" rather quickly Your card is as safe and secure as you care to make it.

Your new RFID credit and debit cards will transmit their data outside your purse or wallet. Now, you won't have to physically lose your cards to lose the cards' information. A thief could walk around with a reader in a brief case or backpack and read the data off any cards which stray within RFID range (usually a few inches). Then, the thief could "clone" your cards or devices and you would be none the wiser until you get your next statement, bounce some checks, or (in the case of good banks which take extra care for their customers) get a call asking about unusual activity on your account.

Though the companies who promote RFID assure the public their devices are fraud-proof, given the technical prowess of many of today's criminals, it probably won't be long after these cards come into common use that thieves will devise ways of snatching card and ID information right out of the air.

For now, I'm sticking with the "swipe" card. If forced to use RFID, I'm lining my wallet with aluminum foil!

Monday, January 28, 2008

More RFID Security News

Security Advocates Fight Passport RFID Proposal

The State Department issued a mandate requiring all US passports to be equipped with RFID chips in them. This is a bad thing, not only for reasons I've pointed out in earlier posts (here, here, here and here); but, also because the type of RFID chip they require will be one which can be "vicinity read" rather than the "proximity read." In other words, they want a chip which can be read from a further distance away.

The fact that the State Department will required whoever gets the contract to provide these chips will be required to supply a "protective sleeve." Although not spelled out in the article, I assume this sleeve is meant to protect the passport holder from having his or her information read off the chip.

This is another example of the government wanting to take advantage of a technology without fully thinking through the implications. Yes, I imagine having RFID passports which can be read from some distance away can be a great tool to ease traffic at customs stations and immigration checkpoints. But, the inherent lack of security in this type of scheme screams for it to not be used.

I mentioned in one of my previous posts on RFID that if this technology were mandated I'd wrap my wallet in aluminum foil. I'm not the only one with this idea. While on a recent trip, I spotted an RFID Blocking Passport Wallet in the "Sky Mall" catalog which is made to prevent "sniffing" information off one's RFID-equipped cards and identification. In addition to the one I noticed in the print catalog, the Sky Mall web site offers three other types of ID holders which are made to block RFID readers from getting the information off the chip.

Monday, February 18, 2008

Two Perspectives on Human-Implanted RFID

I ran into two articles on Business Week's web site. They are two in a series of articles which discuss implantable RFID chips in humans. The first was written by Scott Silverman, CEO of VeriChip, maker of the only FDA-approved RFID implant for humans.

As one might expect, Silverman attempts to ease concerns over using RFID by describing certain "misconceptions" about the implants and explaining how those "myths" are unsubstantiated. He does a very good job, but as one who stands to benefit greatly from additional use of those chips, I think we should be leery of his attempt to explain away those misconceptions so casually.

Medical information is private: Yes, I agree with his stance pointing out that the implant alone cannot be used to access anyone's private health records because it only provides a coded number pointing to the person's records. Health records are only as safe as the security surrounding them and chip or no chip the safety of those records are the same.

I also agree with Mr. Silverman in that I don't believe implanted RFID implants are hazardous to health. The implants have been used for many years in animals and there is scarce evidence they cause any health problems.

I disagree with Silverman's claim the chips can't be used to track someone. He is correct in explaining the chips in the implant have no GPS and do not continuously transmit their data like a beacon. Although it is true the implants only transmit their data when activated by a special reader, he fails to mention the fact that someone with just a little bit of technical prowess can make a device to activate the chip and get the data from it.

Although tracking an individual's movements might be impractical, reading the unique ID number could be used in a crime against the person with the implant. Currently, the unique ID number in the implant's chip only links to a health record stored in VeriChip's database. But, what happens in future if that implant's technology is linked to bank accounts or other databases. Like credit and debit cards with RFID chips in them, we have a scenario where those chips can be exploited to the detriment of those who have them.

The second article, titled "Human ID Chips Get Under My Skin" by David Holzman, outlines some of objections to this technology, many of which I have already commented on elsewhere in this blog. I won't go into details, but suggest reading the article. It's short and to the point. I found his comments to be a thoughtful counterpoint to Mr. Silverman's utopian ideals of how these implants can be used.

Tuesday, December 26, 2006

Potential RFID Privacy & Security Problems

A year ago this past May I blogged about some serious security and privacy concerns regarding Radio Frequency Identification (RFID). In the past year-and-a-half, I haven't seen any real public discussion of the concerns I have regarding the use of this technology.

A paper published by the University of Washington Department of Computer Science and Engineering entitled "Devices That Tell On You: The Nike+iPod Sport Kit", outlines a direct example of how an on-the-market RFID technology has the potential to be exploited for bad purposes. The paper is telling in the relatively simple way the RFID technology, used to make a very handy and convenient device, can be used can also be used by the "not so honest" out there with very little technical knowledge. It also demonstrates some possible ways the device could be changed in order to make it far more "privacy friendly."

I highly recommend folks read up on RFID and its potential problems. I hate to call for government action on a problem like this because then it'll just get messed up. I think it's better for everyone to educate themselves so they can make informed decisions about the technology they use, whether purchased or not.