<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Engadget - Comments for RFID chips can spread viruses</title>
<link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link>
<description>Engadget Comments for RFID chips can spread viruses</description>
<image>
<url>http://www.engadget.com/media/feedlogo.gif</url>
<title>Engadget</title>
<link>http://www.engadget.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2012 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[I always knew you had a sweet tooth Marc. ;)]]></description><dc:creator><![CDATA[slash]]></dc:creator><pubDate>Mar 15th 2006 4:01PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Hmm. So the chip itself has firmware that can be reprogrammed and then, infected? Sounds like a PROM rewrite. Given the audience and the necessity of physical access (I'm guessing), it sounds like a true low-frequency event.  ]]></description><dc:creator><![CDATA[Poopmaster]]></dc:creator><pubDate>Mar 15th 2006 4:21PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Mmm...cheap ice cream. Now I'm ready to jump on the RFID bandwagon. Screw unsecured personal information potentially leading to identity theft. I wants me some $.25 peanut butter cup.]]></description><dc:creator><![CDATA[Saffy]]></dc:creator><pubDate>Mar 15th 2006 4:28PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[NO! NOT THE ICECREAM!<br><br>anything but that!<br>WHAT HAS THIS WORLD COME TO?]]></description><dc:creator><![CDATA[Mike]]></dc:creator><pubDate>Mar 15th 2006 4:29PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA['except in the supermarket, where they're expected to allow tampering so that they can continue getting cheap ice cream.' I like it, it looks like you guys took some good prase and embraced it (I think you should give that person the computer!)You know what i am talking about!]]></description><dc:creator><![CDATA[JJ]]></dc:creator><pubDate>Mar 15th 2006 4:31PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Remember the Passport post with the RFID from the other day?  What if you got an "I'm a terriorist" virus on your passport that alerted customs that you were a terriorist?  That would make for some interesting vacations.]]></description><dc:creator><![CDATA[Josh]]></dc:creator><pubDate>Mar 15th 2006 4:37PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[would that imply the contents of the RFID chip gets executed somewhere?  huh?  maybe utilising buffer overflows in the supermarket's database?]]></description><dc:creator><![CDATA[russ]]></dc:creator><pubDate>Mar 15th 2006 4:47PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Dude, it is ICED CREAM or ICECREAM, but not ICE CREAM.]]></description><dc:creator><![CDATA[Billy]]></dc:creator><pubDate>Mar 15th 2006 4:51PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[The class of vulnerabilities they're talking about are data validation flaws (SQL injections, buffer overruns, shell codes).  Most of these problems can be stopped by just validating your input (and 'safing' it as necessary) before sending it willy-nilly through your program.  <br><br>Of course, this presupposes that most developers can actually design software for the real world.]]></description><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mar 15th 2006 5:15PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[David (currently #7) is right. This is basically your run-of-the-mill data validation flaw that seems to plague every new technology before it gets widespread use. Basically, software that reads RFID chips should tread the RFID response as untrusted, validating it just like they would an HTML form input. <br><br>Say it looks for a numeric ID on the chip and then queries a DB with "SELECT * FROM `groceries` WHERE `id` = '$RFID' " and someone malicious has coded the chip to return " '; DELETE FROM `groceries` WHERE '' = ' " ... instead of a numeric value. Poof - no more inventory database.]]></description><dc:creator><![CDATA[Ethan]]></dc:creator><pubDate>Mar 15th 2006 5:37PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Considering that most tags are 64 bit and 96 bit, 8 and 12 bytes respectively, there's not many SQL commands you can execute.  Although in theory possible, your a moron if you name your table with a single character or something.<br><br>Plus as said, if you just verify the data read from the tag, you will be fine.  I am currently working on a RFID solution, and while possible, in practice I doubt you will see something like this occurring except in rare circumstances.]]></description><dc:creator><![CDATA[Ian]]></dc:creator><pubDate>Mar 15th 2006 6:17PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Also, I forgot to add that not all tags can be re-written.  I would suspect that important things like passports will be read only, so someone cannot override your information.]]></description><dc:creator><![CDATA[Ian]]></dc:creator><pubDate>Mar 15th 2006 6:23PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[';INS [overflow code]'<br><br>Also, who says that an RFID reader is limited to reading only those bits? Could someone provide a brief explanation of the physical limits for particular RFID tokens and readers, and why those limits exist?]]></description><dc:creator><![CDATA[Siege]]></dc:creator><pubDate>Mar 15th 2006 6:26PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[it's poor for security. Because many security systems are use it for exam. airline, metro etc.]]></description><dc:creator><![CDATA[RFID teknolojisi]]></dc:creator><pubDate>Mar 15th 2006 7:06PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Siege:<br><br>The only bits that exist are 0 and 1.  A tag can only hold as much data as memory on the chip.  The standard values are 64 (transitional), 96 (will be the most used), and 128 (needed for companies with many products/many serial numbers).<br><br>Depending on the encoding, the bits are arranged in specific ways.  There are many websites that describe the different encodings.  For SGTIN 96 bit, the first 8 bits are the header, the next 3 bits are the object type, the next 3 are the partition, the next 20-40 bits are the Company prefix, the next 24-4 are the item reference (SKU), the next 38 bits are the serial number.  The barrier between the the company prefix and item reference can be changed.<br><br>A would be hacker could ignore the encoding, and just arrange every 8 bits in to a byte, and encode a string within the tag.  This string could be used in a malicious way if the software that interfaces with the reader does not verify the data.<br><br>The easy solution in software is to verify that the tag conforms to a specific encoding.  The encoding being used should be known in advance, so you can hard code it in to your program.]]></description><dc:creator><![CDATA[Ian]]></dc:creator><pubDate>Mar 15th 2006 8:11PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[God help us all if there is ever a Bird Flu to RFID mutation...<br><br>To #7 - You are wrong. Go to Ben & Jerry's website: <a href="http://www.benjerry.com">http://www.benjerry.com</a> - they make "Ice Cream" - not any of the wackedout variations you said were correct. ]]></description><dc:creator><![CDATA[Ryan Gardner]]></dc:creator><pubDate>Mar 15th 2006 9:53PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Thank God for the Ians and Sieges and Ryan Gardners of the world! They may just save us from the wack-job Billys and RFID hackers out there, so we can enjoy all that cheapo ICE CREAM in dubious safety.]]></description><dc:creator><![CDATA[Hurricane Joy]]></dc:creator><pubDate>Mar 16th 2006 12:05AM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[>>Dude, it is ICED CREAM or ICECREAM, but not ICE CREAM<br><br>Not according to <br><a href="http://benjerrys.com">http://benjerrys.com</a><br><a href="http://breyers.com/products/ind_product.asp?UPC=77567-25450&brand=Breyers&pageFrom=pickproduct">http://breyers.com/products/ind_product.asp?UPC=77567-25450&brand=Breyers&pageFrom=pickproduct</a><br><a href="http://haagendazs.com/segice.do">http://haagendazs.com/segice.do</a><br><br>All of them say ice cream. But what would they know, right, dude?<br><br>-p-]]></description><dc:creator><![CDATA[p-diddy]]></dc:creator><pubDate>Mar 16th 2006 4:43AM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[fixed link: <a href="http://benjerry.com">http://benjerry.com</a><br><br>while I'm at it:<br><br><a href="http://www.hphood.com/products/prodList.aspx?id=25">http://www.hphood.com/products/prodList.aspx?id=25</a><br><a href="http://kemps.com/products/ice_cream.shtml">http://kemps.com/products/ice_cream.shtml</a><br><br>None of which call it "iced cream" or "icecream." If you're going to correct someone, maybe you should try being correct first.<br><br>-p-]]></description><dc:creator><![CDATA[p-diddy]]></dc:creator><pubDate>Mar 16th 2006 5:09AM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[p-diddy is right. There's no iced cream or whatever. Check your dictionary first.]]></description><dc:creator><![CDATA[brenda]]></dc:creator><pubDate>Mar 16th 2006 5:19AM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[<a href="http://www.imakethings.com/2006/03/10/getting-chipped-interviews-with-rfid-pioneers/">http://www.imakethings.com/2006/03/10/getting-chipped-interviews-with-rfid-pioneers/</a>]]></description><dc:creator><![CDATA[Bre]]></dc:creator><pubDate>Mar 16th 2006 2:43PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[Why do people feel a need to correct words on a website that is read internationally.  Mabye where Billy comes from it is ICED CREAM, but here in the US its not.  People speak differently, and correctly, all over the world.  I'm not going to call out someone from England because they say chips and I say french fries.  Lets try to have insightful comments instead.]]></description><dc:creator><![CDATA[TMoney]]></dc:creator><pubDate>Mar 17th 2006 9:40AM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[@22, couldn't agree more.. and it's [tom-ah-to], not [tom-ay-to]. :-p<br><br>BTW any fool that doesn't make sure to include simple security measures like data verification should be shot.]]></description><dc:creator><![CDATA[Ti]]></dc:creator><pubDate>Mar 17th 2006 12:42PM</pubDate></item><item><title><![CDATA[Comments on RFID chips can spread viruses]]></title><link>http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</link><guid isPermaLink="true">http://www.engadget.com/2006/03/15/rfid-chips-can-spread-viruses/</guid><description><![CDATA[what does ice cream have to do with any of this again?]]></description><dc:creator><![CDATA[windows]]></dc:creator><pubDate>Mar 18th 2006 8:38PM</pubDate></item></channel></rss>
