<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>www.kreslavsky.com &#187; Technology News</title>
	<atom:link href="http://www.kreslavsky.com/category/news/technology-news/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com</link>
	<description>Common IT  solutions. AD &#124; Messaging &#124; Virtualization &#124; Storage &#124; Security</description>
	<lastBuildDate>Thu, 02 Sep 2010 08:07:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Up to one billion RFID access cards could be affected by hack</title>
		<link>http://www.kreslavsky.com/2008/03/up-to-one-billion-rfid-access-cards.html</link>
		<comments>http://www.kreslavsky.com/2008/03/up-to-one-billion-rfid-access-cards.html#comments</comments>
		<pubDate>Mon, 31 Mar 2008 05:58:00 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology News]]></category>
		<category><![CDATA[Access Cards]]></category>
		<category><![CDATA[Additional Security Measures]]></category>
		<category><![CDATA[Bart Jacobs]]></category>
		<category><![CDATA[Dutch Government]]></category>
		<category><![CDATA[German Researchers]]></category>
		<category><![CDATA[Global Problem]]></category>
		<category><![CDATA[Government Institutions]]></category>
		<category><![CDATA[Hack On]]></category>
		<category><![CDATA[Independent Research Teams]]></category>
		<category><![CDATA[Interior Affairs]]></category>
		<category><![CDATA[Laughing Matter]]></category>
		<category><![CDATA[Nohl]]></category>
		<category><![CDATA[Pc World]]></category>
		<category><![CDATA[Pertinent Question]]></category>
		<category><![CDATA[Radio Frequency Identification]]></category>
		<category><![CDATA[Rfid Radio Frequency Identification]]></category>
		<category><![CDATA[Security Risk]]></category>
		<category><![CDATA[Ter Horst]]></category>
		<category><![CDATA[Transit Operators]]></category>
		<category><![CDATA[Unauthorized Entry]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2008/03/up-to-one-billion-rfid-access-cards-could-be-affected-by-hack/</guid>
		<description><![CDATA[On the heels of two independent research teams demonstrating hacks of the Mifare Classic RFID chip algorithm, the Dutch government has issued a public warning about the security of access keys based on it. The minister of interior affairs, in a letter to parliament, wrote that there are plans for government institutions to take “additional [...]]]></description>
			<content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/NW3RGbQTLhE&amp;hl=en" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://www.youtube.com/v/NW3RGbQTLhE&amp;hl=en" wmode="transparent"></embed></object></p>
<p>On the heels of two independent research teams demonstrating hacks of the Mifare Classic RFID chip algorithm, the Dutch government has issued a public warning about the security of access keys based on it. The minister of interior affairs, in a letter to parliament, wrote that there are plans for government institutions to take “additional security measures to safeguard security.”</p>
<p>It is no laughing matter, as the technology is used by transit operators in London, Boston, and the Netherlands. It is also used in access cards in numerous other organizations around the world.</p>
<p>Excerpt from PC World:</p>
<blockquote><p>NXP developed the Mifare Classic RFID (radio frequency identification) chip, which is used in 2 million Dutch building access passes, said ter Horst. One billion passes with the technology have been distributed worldwide, making the security risk a global problem. A spokesperson for the ministry told Webwereld, an IDG affiliate, that it had not yet notified other countries.</p></blockquote>
<ul>
<li>German researchers Karsten Nohl and Henryk Plötz have published a paper on how to crack the chip’s encryption (pdf)</li>
<li>Bart Jacobs, an information security professor, have released the video which I have embedded above.</li>
</ul>
<p>The video demonstrates how cryptography could be retrieved from readers attached to access control infrastructure or even sniffed simply by walking pass a Mifare RFID card holder. Duplicate cards are then cloned to gain unauthorized entry. What is really scary is the ease with which the attacks are successfully executed.</p>
<p>The interesting thing here is that manufacturer, NXP Semiconductors, has quickly announced that there is a new version of the Mifare chip called the Mifare Plus with enhanced security –<span id="intelliTxt"> 128-bit encryption over the original 48-bit, to be exact.</span></p>
<p>The pertinent question here is why wasn’t the Mifare Plus introduced earlier? Now, it is not known how much this enhanced card will eventually cost, but reports say that the original Mifare Classic sold for less than a single dollar. Hence, the low cost of the Mifare Classic might have been a factor here.</p>
<div class='wpfblike' ><fb:like href='http://www.kreslavsky.com/2008/03/up-to-one-billion-rfid-access-cards.html' layout='default' show_faces='true' width='400' action='like' colorscheme='light' /></div><h3  class="related_post_title">Read more</h3><ul class="related_post"><li><a href="http://www.kreslavsky.com/2009/06/tips-and-tricks-for-your-blackberry-device-part-1.html" title="Tips and Tricks for Your BlackBerry Device &#8211; Part 1">Tips and Tricks for Your BlackBerry Device &#8211; Part 1</a> (25)</li><li><a href="http://www.kreslavsky.com/2009/06/making-mega-virus-2008-destroy-windows.html" title="***** MAKING MEGA VIRUS 2008 DESTROY WINDOWS *****">***** MAKING MEGA VIRUS 2008 DESTROY WINDOWS *****</a> (25)</li><li><a href="http://www.kreslavsky.com/2009/06/blackberry-8320-curve-tips-tricks.html" title="BlackBerry 8320 Curve &#8211; Tips &#038; Tricks">BlackBerry 8320 Curve &#8211; Tips &#038; Tricks</a> (25)</li><li><a href="http://www.kreslavsky.com/2009/06/windows-server-2008-hyper-v-demo-on-quad-core-intel-xeon.html" title="Windows Server 2008 Hyper-V Demo on Quad-Core Intel Xeon">Windows Server 2008 Hyper-V Demo on Quad-Core Intel Xeon</a> (24)</li><li><a href="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html" title="W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys">W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</a> (23)</li><li><a href="http://www.kreslavsky.com/2008/11/add-custom-field-to-aduc-employee-id.html" title="Add custom field to ADUC- Employee ID">Add custom field to ADUC- Employee ID</a> (17)</li><li><a href="http://www.kreslavsky.com/2008/08/exchange-2003-interview-questions.html" title="Exchange 2003 Interview Questions">Exchange 2003 Interview Questions</a> (12)</li><li><a href="http://www.kreslavsky.com/2008/08/how-blackberry-email-reconciliation-deleting-emails-works.html" title="How blackberry email reconciliation-(Deleting Emails) works.">How blackberry email reconciliation-(Deleting Emails) works.</a> (12)</li><li><a href="http://www.kreslavsky.com/2009/06/how-to-configure-gmail-imap-for-outlook-2007.html" title="How to configure GMail IMAP for Outlook 2007">How to configure GMail IMAP for Outlook 2007</a> (11)</li><li><a href="http://www.kreslavsky.com/2008/01/integrated-remote-console-is.html" title="&quot;The Integrated Remote Console is unavailable; it is already in use by a different client.&quot;">&quot;The Integrated Remote Console is unavailable; it is already in use by a different client.&quot;</a> (9)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/03/up-to-one-billion-rfid-access-cards.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
