Home > Security News > RFID cloning presentation moves forward despite legal threats
Security News:
EMAIL THIS

RFID cloning presentation moves forward despite legal threats

By Dennis Fisher, Executive Editor
01 Mar 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

ARLINGTON, Va. -- A security researcher who said he was pressured by radio frequency identification (RFID) chip maker HID Corp. to scrap his demonstration of a device that could clone RFID enabled proximity badges, ended up delivering a modified version of his talk anyway, albeit one without any details specific to HID's products.
Facility managers are making purchase decisions and in many cases IT is not involved therefore these vulnerabilities and issues never raise to the surface.
Paul Proctor,
vice president, Gartner Inc.

Despite HID's legal threats, Chris Paget, director of research and development at Seattle-based IOActive spoke mainly about the science behind RFID tags and readers and the inherent security problems the architecture includes. He also showed several slides with excerpts from the letter that HID sent him, refuting claims by the company that it did not try to prevent him from speaking.

The device clones RFID-enabled access badges used by many companies and government agencies to gain access to offices. Made with just $20 worth of technology that could be purchased online, an attacker only has to be in close proximity of a person holding an access badge to succeed in developing a clone, Paget said.

Irvine, Calif.-based HID sent a letter to Paget citing intellectual property concerns. Paget said that the presentation would open up IOActive to litigation on the grounds that some of the device technology is patented.

In part, the letter read, "[HID] hereby demand that you refrain from publishing any info at any public forum including the upcoming Black Hat convention," relating to HID's patented technologies. The letter also said that if Paget refused, "we will have no recourse but to pursue all avail remedies against you and IOActive."

Paget said he and IOActive decided not to discuss anything specific to HID's products because "the defense costs alone would put us out of business. HID have certainly put us in a position in which we are unable to present regardless of other circumstances."
RFID tag cloning:
Black Hat presenter nixes RFID cloning demo under pressure: A demonstration of a device that could easily clone radio frequency identification (RFID) badges, was pulled from a conference presentation under pressure from a chip maker.

RFID dispute: Vendors still hostile toward full disclosure: Many vendors still believe that security by obscurity is still the best policy and make it a priority to silence vulnerability researchers.

RFID privacy, security should start with design: Companies planning to deploy radio frequency identification technology (RFID) must demand that privacy and security issues are addressed in the design and procurement phases of an implementation.

Panel says privacy legislation too premature for RFID: A group of public policy and technology experts at the RSA Conference 2007 said legislation could make radio frequency identification technology too costly for enterprises and hamper its innovation.

In a press conference following the presentation, Mike Davis, director of intellectual property at HID disputed Paget's claims, even after seeing the excerpts of the letter, and said that the company only sought to prevent him from publishing schematics and the full source code of HID's proximity cards. Davis said it is disingenuous and not proper to teach someone how to compromise the security of a product.

"I believe it's disingenuous to say that HID wasn't targeted," he said. "It was really about the issue of full disclosure. We believe that using full source code and schematics would be an inducement of an attack. ... In the end it was really a non issue."

Davis said companies continue to buy RFID proximity cards after weighing the risks or combining the cards with other authentication technologies such as pin-pad access or smart card technology. He also demonstrated a plastic protective cover that could easily protect a proximity card from the cloning vulnerability.

"There's a whole bunch of solutions and at the end of the day this is sometimes what the customer wants," Davis said.

The second half of the session consisted of a panel comprising Paget, an attorney from the American Civil Liberties Union, a representative from US-CERT, Joe Grand, a well-known hardware hacker, and Dan Kaminsky, a noted security researcher. All criticized HID for its actions and said that the incident was representative of a larger problem in the industry.

"The technology is different, but a lot of the problems are the same. I'm a designer and I break things. It's just really frustrating to see this, because I see both sides," said Grand, a former member of the L0pht and now president of Grand Idea Studios in San Diego.

Nicole Ozer, technology and civil liberties policy director for the American Civil Liberties Union of Northern California, said that HID's actions and those of other vendors who seek to limit the availability of information on the security of various systems, should be a major concern for security researchers as well as individuals.

"This leaves all of us unsafe because the government and the industry don't have the information we need to make this secure," she said.

Paul Proctor, vice president in the security and risk practice at research firm, Gartner Inc. said the issues raised by the presentation should concern customers who use RFID proximity cards for access to sensitive areas. The spat between HID and IOActive raises the issue of full disclosure, he said. Customers want to know when vulnerabilities exist so they can fix the technology or put proper security protections in place.

"The problem is organizations are buying the wrong technology," Proctor said. "Facility managers are making purchase decisions and in many cases IT is not involved therefore these vulnerabilities and issues never raise to the surface."

News Editor Robert Westervelt contributed to this report.

Tags: Emerging Information Security ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Emerging Information Security Threats
New attack code targets Microsoft ActiveX zero-day vulnerability
Adobe ColdFusion websites being compromised
Antispyware buying guide for Indian enterprises
ATM malware lets attackers take over machines
FTC shutters rogue ISP for hosting malicious content, botnets
The failing war against cybercriminals
White House cybersecurity czar faces major hurdles
Cybercrime and threat management
The Pipe Dream of No More Free Bugs
Face-off: Who should be in charge of cybersecurity?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DNS rebinding attack  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
phlashing  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts