By Jay Lyman TechNewsWorld Part of the ECT News Network
01/31/05 1:38 PM PT
The Johns Hopkins researchers said that the RFID system they studied was designed to thwart car thieves and provide fast and convenient payments via safeguarded wireless transactions. The group found, however, that the TI tags were susceptible to attacks using mathematics and low-cost processors.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Technology researchers at Johns Hopkins University have found that radio frequency identification (RFID)
technologies used for automobile locks and easy-pay gasoline systems are sorely lacking in
protection, warning that opportunists could easily exploit the weakness for ill deeds.
The researchers, led by Avi Rubin, technical director of the Johns Hopkins Information Security Institute, cited poor encryption and inadequate protection from wireless hacking, which could allow access to automobiles or accounts that rely on the small, wireless-capable chips used for RFID.
The researchers claimed that the Texas Instruments (NYSE: TXN) system it cracked -- a low-power, radio frequency security system used worldwide by top car manufacturers and for more than 6 million key chain
tags used to purchase gasoline -- could allow easy access to tech-savvy thieves.
"I think this sets back vehicle security about a
decade," lead researcher Rubin told TechNewsWorld.
Ease of Use
The Johns Hopkins researchers said that the RFID
system they studied was designed to thwart car thieves
and provide fast and convenient payments
via safeguarded wireless transactions. The
group found, however, that the TI tags -- already in use around the
world -- were susceptible to attack using mathematics
and low-cost processors.
"Millions of tags that are currently in use by
consumers have an encryption function that can be
cracked without requiring direct contact," Rubin said
in a statement. "An attacker who cracks the secret key
in an RFID tag can then bypass security measures and
fool tag readers in cars or at gas stations."
The researchers said that they alerted TI and
demonstrated the security breach to the company, which
is among a number of different RFID system makers.
The Hopkins researchers, who teamed with RSA Security (Nasdaq: RSAS)
on the study, are putting other RFID systems to the test, Rubin said.
Early Disclosure
Ari Juels, RSA Laboratories principal research scientist, told TechNewsWorld the research was intended to
head off more widespread distribution of the faulty RFID technology.
"Our aim is to uncover weaknesses like this in RFID
devices before it becomes widespread and costly,"
Juels said. "This points to the importance of
implementing good security from the get-go."
While the research does not
indicate a general security problem with RFID, Juels said,
additional research is expected to reveal more
vulnerabilities.
"We are looking at other systems and there are
other RFID devices in widespread use that we believe
may have security weaknesses," Juels said.
Hardening RFID
RFID systems are being rapidly deployed in manufacturing and
distribution, with companies such as Wal-Mart requiring
the technology from suppliers.
Juels said the researchers are still assessing the parameters of the RFID weakness, indicating that factors
such as wireless range and other circumstances have yet to be investigated.
Jules said Texas Instruments, for example, was on
the right track by including encryption in its RFID
solution, but needed to harden it further.
"In cars as in commerce, RFID is becoming a
linchpin for security in day-to-day life," he said in
a statement. "It is important that RFID devices offer
a level of security commensurate with the value of the
assets they protect."
Sun Microsystems' Mike Green Analyzes E-Commerce in 2005 January 31, 2005
Mike Green, vice president of retail industry for Sun Microsystems, believes that retailers who have made smarter technology investments in four key areas -- lead-time optimization, supply chain management, mark down optimization and labor force management -- will likely have an advantage over their competitors.
Related Stories
Solutionary's Earle Humphreys on Managed Security November 04, 2004
Solutionary bases its managed services offering on ActiveGuard, the company's proprietary security software. The solution continuously monitors and checks networks for changes and vulnerabilities, examines messages for irregularities and implements countermeasures.
IBM To Roll Out Integrated RFID September 27, 2004
Vendors such as IBM are promoting RFID as the next big thing, to be used not only for tracking goods and shipping, but also for overall business operations, said Yankee Group analyst Mike Dominy. While some companies realize the need for broader application of the technology, many are limited to dipping their toes in the RFID river.
Managed Security Services: A Hedge Against E-Mail Attacks May 25, 2004
Threat prevention from phishing attacks is one of the most crucial defenses that managed security firms can provide, Craig Sprosts, product manager at IronPort Systems, told TechNewsWorld. Phishing is an Internet scam that sends unsuspecting users official-looking e-mail. The text in the e-mail messages is designed to fool recipients into disclosing online passwords, user names and other personal information.
Sun and Capgemini Launch RFID System May 06, 2004
"Our codeveloped system is part of an ongoing effort to deliver the most secure RFID systems to the market," said Julie Sarbacker, director of the Auto-ID business unit at Sun Microsystems. "We understand the pain points in the transition and process for retailers and distributors, and we're designing end-to-end systems with our partners to reduce the complexity and costs from the equation."
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.