mail2web.com Blog

Security Analysis of RFID Devices


January 30th, 2005


By GadgetManiac

Security Analysis of a Cryptographically-Enabled RFID Device is the bland-sounding title of an article describing how to crack the security behind the Speedpass payment system, and some of those RFID-based immobilizer key fobs used by auto makers. The article caught my attention because I’m a user of both devices.

The authors describe some of the steps they followed to reverse engineer the codes. They attribute the weakness of the architecture to the use of (far-too-short) 40-bit keys, and describe some steps end users can follow to improve security slightly…e.g. wrap the transponder in aluminum foil when not in use.

The authors also have an article with videos detailing their approach, including how to read an RFID tag while its still in the victim’s pocket:
Reading a DST tag from a short distance

Funny … transponder sniffing, and its concomitant countermeasure of wrapping the key in tin foil, are not mentioned in Edmund’s article:- “Top 10 Ways to Steal a Car (and how to defend against them) “.

Share and Enjoy:
  • TwitThis
  • Digg
  • StumbleUpon
  • del.icio.us
  • Slashdot
  • Facebook
  • Technorati
  • Google Bookmarks
  • LinkedIn
  • FriendFeed
  • Sphinn
  • SphereIt
  • NewsVine
  • Reddit

Related posts:

  1. Bump Keys open Most Locks
  2. Ambient Devices
  3. 3M Security Glass
  4. Loc8tor Gadget-Finding-Gadget
  5. Gone in 1200 Seconds

Categories: General ~ ~ Trackback

Leave a Reply

Microsoft Gold PartnerBlackBerry AllianceClick to verify BBB accreditation and to see a BBB report. RatePoint Site Seal