<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Engadget - Comments for Hackers crash e-passport readers -- stage set for exploits</title>
<link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link>
<description>Engadget Comments for Hackers crash e-passport readers -- stage set for exploits</description>
<image>
<url>http://www.engadget.com/media/feedlogo.gif</url>
<title>Engadget</title>
<link>http://www.engadget.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2012 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Next thing you know, people will start running homebrew on those machines.]]></description><dc:creator><![CDATA[Bernhard]]></dc:creator><pubDate>Aug 1st 2007 5:24AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Yes... But Will They Run DOOM?]]></description><dc:creator><![CDATA[L. Cyphre]]></dc:creator><pubDate>Aug 1st 2007 5:50AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Linux is keeping you alive. :o]]></description><dc:creator><![CDATA[AlexP]]></dc:creator><pubDate>Aug 1st 2007 5:32AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Most countries are deliberately intruducing piss poor biometric and other 'protection' so, when they inevitably fail and theres a major incedent, they can introduce even more draconian 'securty measures'.]]></description><dc:creator><![CDATA[Alan Partridge]]></dc:creator><pubDate>Aug 1st 2007 5:50AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[...Need a tinfoil hat?]]></description><dc:creator><![CDATA[L. Cyphre]]></dc:creator><pubDate>Aug 1st 2007 6:27AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[i hear that.<br><br><a href="http://video.google.com/videoplay?docid=7866929448192753501" rel="nofollow">http://video.google.com/videoplay?docid=7866929448192753501</a><br><br>]]></description><dc:creator><![CDATA[pigfister]]></dc:creator><pubDate>Aug 1st 2007 12:03PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Everyone that saw this coming a million miles away, raise your hand.<br><br>**raises hand with every other Engadget reader**]]></description><dc:creator><![CDATA[Rboyett]]></dc:creator><pubDate>Aug 1st 2007 9:12AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[*raises hand*]]></description><dc:creator><![CDATA[Astrosapien]]></dc:creator><pubDate>Aug 1st 2007 10:26AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Didn't Engadget already have a post to counter this?<br><br>...the Hammer picture?]]></description><dc:creator><![CDATA[David]]></dc:creator><pubDate>Aug 1st 2007 1:47PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[I actually work in this field.  The data is encrypted on the chips.  I'm confused on how crashing the reader will prevent the custom agent from looking at the picture and expiration date on the badge?  Also, if you think just a piece of paper is harder to fake than encrypted data, you are a fool.  ]]></description><dc:creator><![CDATA[bird]]></dc:creator><pubDate>Aug 1st 2007 2:33PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[why the hell don't they put a read on/off membrane button on these things?  It would cost nearly nothing compared to all the problems with always readable rfids.]]></description><dc:creator><![CDATA[theotherstevejobs]]></dc:creator><pubDate>Aug 1st 2007 3:22PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[oh - it would also reduce the readable time from 86400 seconds/day to 2 or 3 seconds - and only when you're near a reader.  It would then be simple to beat the shit out of anyone near a point of entry at an airport holding and pointing the reader right at the official reader - because it would be obvious.  You'd have to have some kind of pointable antenna and it would have to be pointed right at the official reader because otherwise - the switch in the RFID in the passport would be defaulted to open - and the circuit in the RFID would be open, and render it unreadable unless the membrane button was pressed, closing the circuit between the antenna and the rest of the RFID's circuits.<br><br>a.k.a.  an on/off button.]]></description><dc:creator><![CDATA[theotherstevejobs]]></dc:creator><pubDate>Aug 1st 2007 3:27PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[PSP got hacked via a jpeg overflow as well...]]></description><dc:creator><![CDATA[Adam]]></dc:creator><pubDate>Aug 1st 2007 3:28PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Thats hackers for ya]]></description><dc:creator><![CDATA[David]]></dc:creator><pubDate>Aug 1st 2007 5:23PM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[RFID is a joke. Smart Cards. It needs to be Smart Cards. ]]></description><dc:creator><![CDATA[Matt]]></dc:creator><pubDate>Aug 3rd 2007 11:33AM</pubDate></item><item><title><![CDATA[Comments on Hackers crash e-passport readers -- stage set for exploits]]></title><link>http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</link><guid isPermaLink="true">http://www.engadget.com/2007/08/01/hackers-crash-e-passport-readers-ready-to-develop-exploits/</guid><description><![CDATA[Um it is SmartCards.  Where there is fear, there is money to be made.  Lukas is a smart guy.<br><br>The trick is to make sure all drivers and applications verify the jpeg before expanding it.  The jpeg image is embedded as a file inside the smart card called DG2.  Alterations of the DG2 can be verified through software signitures and hash values.<br><br>Even with the above not employed, data execution protection has been around since Windows XP SP2.  By default all memory allocated by applications will have non execute restrictions placed on it from a software and hardware level.  Applications wishing to allocate executable memory must explicitly do this.  Application memory space and the heap are separate and protected.<br><br>I believe part of what Grunwald says is true, the rest a good show and makes for good stories to print.  A little more investigative journalism would go a long way here.]]></description><dc:creator><![CDATA[ghostinthemachine]]></dc:creator><pubDate>Aug 13th 2007 4:33PM</pubDate></item></channel></rss>
