Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

RFID credit card hacked (time to wrap your wallet in tin foil?)
techradar.com ^ | 3/20/08 | Audley Jarvis

Posted on 03/20/2008 8:15:59 AM PDT by LibWhacker

Hacker gives live video demonstration

Following on from last week’s story about how the MIFARE Classic’s RFID chip, as used in London Transport’s Oyster card, had been compromised, BoingBoing has gone a step further. It gave a video demonstration of a hacker demonstrating how easy it is to extract details from a RFID-equipped credit card.

In the video, the hacker Pablos Holman boasts that he is able to “decrypt the data” using an “eight dollar reader from eBay”. One quick swipe of the reporter’s American Express card later and he appears to have done just that, with the cardholder’s name and expiry date both visible.

“You’ll get that from most cards,” explains Holman, before adding “now we can go online and start shopping”.

Holman then offers his explanation as to why the use of RFID technology is spreading despite its obvious security flaws. “The credit card industry understands that creating a secure system isn’t really the priority; creating a system that feels secure to the user is. In reality it’s easier for me to get numbers now than it was before.”

Security risk

Mr Holmon then shows how RFID card carriers could protect themselves from readers with the aid of a metal wallet, before offering his views on how much of a security risk RFID-equipped credit cards really pose:

“I don’t expect this to be a major threat for a while. People are stealing credit card numbers from websites and that’s still pretty easy,” he says, before adding, somewhat more ominously “with a bigger antenna hooked up to this I can go into Starbucks and get the name of everyone in there”.


TOPICS: News/Current Events
KEYWORDS: card; credit; hacked; rfid; risk; security
Navigation: use the links below to view more comments.
first previous 1-2021-25 last
To: LibWhacker
Solutions:
RFID-blocking passport billfold
RFID-blocking wallet

Personally, I'd go for one of those if I had anything with RFID in or on it - they're not badly priced either.
21 posted on 03/20/2008 9:16:07 AM PDT by Hyzenthlay (I aim to misbehave.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibWhacker

You wanna opt out of RFID? You better contact your Congressman about the Federal Real ID then... they want to make the “advanced” IDs RFID readable to “facilitate increased western hemisphere travel” (immigration)


22 posted on 03/20/2008 9:17:38 AM PDT by underground (Viva la Socialisme Wall Street /s)
[ Post Reply | Private Reply | To 4 | View Replies]

To: BGHater

What’s the world coming to when your wallet needs shielding?


23 posted on 03/20/2008 9:58:24 AM PDT by Red in Blue PA (Truth : Liberals :: Kryptonite : Superman)
[ Post Reply | Private Reply | To 2 | View Replies]

I called AmEx and they said they don’t offer an alternative. They offered to turn it off remotely, but how do I know really and what’s to stop them from turning it on again.

9/11 1984 aigh!


24 posted on 09/05/2008 8:29:32 PM PDT by startswithj
[ Post Reply | Private Reply | To 7 | View Replies]

To: startswithj

It’s easy to disable RFID yourself, and detecting the chip is fairly trivial as well.

http://wvp.diablops.com/component/content/article/67-braindead/37-bad-paypass-bad.html


25 posted on 12/09/2010 6:16:39 AM PST by braindead0
[ Post Reply | Private Reply | To 24 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-25 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson