<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Engadget - Comments for Oyster Cards vulnerable to RFID hack, lots of other systems too</title>
<link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link>
<description>Engadget Comments for Oyster Cards vulnerable to RFID hack, lots of other systems too</description>
<image>
<url>http://www.engadget.com/media/feedlogo.gif</url>
<title>Engadget</title>
<link>http://www.engadget.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2008 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[This worries me, especially since the Oyster card technology has been integrated into a Barclaycard...<br><a href="http://www.barclaycard.co.uk/personal-home/cards/onepulse-hero/index.html" rel="nofollow">http://www.barclaycard.co.uk/personal-home/cards/onepulse-hero/index.html</a>]]></description><dc:creator><![CDATA[chandler3224]]></dc:creator><pubDate>Mar 14th 2008 1:55PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[If this hits BBC news, its all over for the oyster card in London.<br>Of course it probably wont.]]></description><dc:creator><![CDATA[ReggieXuk]]></dc:creator><pubDate>Mar 14th 2008 1:58PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Over here in Boston we definitely have wide spread RFID mass transit use. But what I'm wondering is if one of our cards can be hacked to put unlimited access to mass transit..lol. <br><br>But on a serious note, buildings here in the financial  district all use RFID cards for secure access, including buildings such as the Federal Reserve Bank so I'm hoping no one really begins to exploit these cards. ]]></description><dc:creator><![CDATA[Eric M.]]></dc:creator><pubDate>Mar 14th 2008 2:00PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Are you sure it's RFID? The company I work for uses cards that don't need a bar code because they have to be close enough for a magnetic field to trigger the lock.]]></description><dc:creator><![CDATA[Kris]]></dc:creator><pubDate>Mar 14th 2008 2:10PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[@Kris<br><br>I know that its probably half and half. Older companies seem to be using RFID, but seems as if some companies do use the strip. The company I work for though uses RFID because when its together in my wallet with my Mass Transit card they conflict with one another on occasion. ]]></description><dc:creator><![CDATA[Eric M.]]></dc:creator><pubDate>Mar 14th 2008 2:46PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[I believe Marta in Atlanta uses Mifare.  At least, my card reader is able to read the CSN of the cards, but not the data... wish some more info was released on this so I could learn how to break the encryption. :)]]></description><dc:creator><![CDATA[Azureice]]></dc:creator><pubDate>Mar 14th 2008 2:01PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Sweet, someone else from Atlanta that though "Gee, I bet I could do this..."<br><br>I don't use marta much, and I'm sure the temporary cards are worthless, but if you find someone that has the plastic cards, then you can probably cheat and use their account so long as they aren't on the rail.  I say this because my friend had to buy two cards when he and his wife were going to travel, he thought he could get away with just swiping the card twice!]]></description><dc:creator><![CDATA[John McDole]]></dc:creator><pubDate>Mar 14th 2008 5:41PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[It's time for a technology upgrade.  Good thing these hackers are honest.  ]]></description><dc:creator><![CDATA[James Cameron]]></dc:creator><pubDate>Mar 14th 2008 2:01PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[no technology for the people will be safe, were not that special]]></description><dc:creator><![CDATA[ReggieXuk]]></dc:creator><pubDate>Mar 14th 2008 2:02PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[I wonder what type of RFID my school ID has in it (Drexel)... If it's similar, I might have to try and clone it... Free lunch at the dining hall, hell yeah.]]></description><dc:creator><![CDATA[Mike S.]]></dc:creator><pubDate>Mar 14th 2008 2:02PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Well, we had people showing how you could crack RFID via a typicall cell phone. Why anyone would use this in an actual product, I have no idea.<br><br>RFID is a cool concept but its specifications and implementations leave a lot to be desired.]]></description><dc:creator><![CDATA[Kris]]></dc:creator><pubDate>Mar 14th 2008 2:09PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[there's a big difference between RFID itself (an extremely broad specification for identification over radio frequencies), which has no security whatsoever, and applications of RFID, which almost always include security measures of some sort.<br><br>True, most of these suck, but they can be very secure. The problem is any kind of major encryption technology requires some pretty beefy computation capability for a device with no internal power source and severely limited real estate. Asymmetric ciphers, for example, require both parties to store and work with three very large numbers (their public key, their private key, and the other party's public key), and the initial handshake (in which session keys are exchanged over the asymmetric cipher so faster, symmetric ciphers can take over) requires a mathematically complex operation (dividing, exponentiating, and calculating the modulus of these extremely large numbers).]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 4:13PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Mifare is a proximity card. Sniffing it "wirelessly" needs to be done with no interference (ie no metal near the card) in a range under 5cm. It also takes a couple seconds to do, I doubt that you could do it by just walking by...<br><br>I've built a 14443 stack, it's easy to hack but it's security lies in it's limited range. It's almost as easy to just steal the card as it is to sniff it.]]></description><dc:creator><![CDATA[JR]]></dc:creator><pubDate>Mar 14th 2008 2:09PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Isn't the level of security provided by "proximity" determined by the quality of the hackers' antenna and transceiver? <br><br>With a better transmitter, receiver, and antenna - and a longer time to collect samples then the "swipe" time envisioned by the system designers, I believe the hackers have an advantage.]]></description><dc:creator><![CDATA[pat]]></dc:creator><pubDate>Mar 14th 2008 3:07PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Nah, proximity devices aren't read with a normal antenna. They're read with magnets, which have a strength that degrades exponentially with increasing distance. A magnet capable of reading a proximity card at more than a few inches' distance would also be capable of lifting a car (and scrambling the proximity card's data, for that matter).]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 3:57PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[The exponent is based on the size of the antenna.  A ring antenna the size of a backpack can read prox cards several feet away.  A ring antenna the size of a desk can read them yards away.  If you can put the antenna in a kiosk or sign enclosure adjacent to a driveway or corner where vehicles slow down, you can sniff cards in vehicles as they drive by. ]]></description><dc:creator><![CDATA[catbear]]></dc:creator><pubDate>Mar 14th 2008 6:09PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[The Oyster system is used for more than just underground. It's used on the whole London Public Transport System, buses, trains, etc.]]></description><dc:creator><![CDATA[Shadowise]]></dc:creator><pubDate>Mar 14th 2008 2:14PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[They should have used the DreamStream encryption. From my research, it is the only solution to the RFID problem.]]></description><dc:creator><![CDATA[Diff]]></dc:creator><pubDate>Mar 14th 2008 2:18PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[DreamStream isn't anything special. It's just a typical encryption scheme using a typical encryption method. And "military-grade" encryption doesn't really mean much. You can get this exact same level of encryption on any desktop, laptop, or cell phone for free -- download gpg (GNU Privacy Guard) and pgp (Pretty Good Privacy) and you can generate 2048-bit asymmetric encryption keys all day long. SSL uses RSA and DES(2), and banks use SSL. GPG/PGP can use RSA or ElGamal along with DES(2), IDEA, and other symmetric 'session' key ciphers.]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 4:07PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Just another "check" in the PRO column of spending $100 to fast track my U.S. passport just before RFID implementation. ]]></description><dc:creator><![CDATA[Timothy Sottek]]></dc:creator><pubDate>Mar 14th 2008 2:23PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[I thought RFID implementation went in in January of last year?]]></description><dc:creator><![CDATA[Kris]]></dc:creator><pubDate>Mar 14th 2008 2:28PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Kris: <br><br>Thats correct. I nabbed mine Fall, 2006. ]]></description><dc:creator><![CDATA[Timothy Sottek]]></dc:creator><pubDate>Mar 14th 2008 2:29PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[my building uses these... wont tell you where, but yah... aint technology grand?]]></description><dc:creator><![CDATA[fuma]]></dc:creator><pubDate>Mar 14th 2008 2:25PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[where?]]></description><dc:creator><![CDATA[Jordan]]></dc:creator><pubDate>Mar 14th 2008 4:14PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Ah the wonderful cat and mouse game of technology.  First the scare about your house getting broken into because of primitive key techonology.  Now transit systems and possibly US federal buildings being compromised due to the failure of a digital key.  <br><br>Though one standard does hold true.."Three men can keep a secret if two of them are dead."  Hopefully such drastic actions will never be taken to keep encryption techonology as secure.]]></description><dc:creator><![CDATA[kal326]]></dc:creator><pubDate>Mar 14th 2008 2:41PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[I wonder what system the Visa Wave and Pay and MasterCard PayPass use, I can live with issues with Oyster but with the Banks in London trying to ram through the wireless payment systems it could be interesting. When they sent me details about it I rang instantly and asked for a card without it. The call centre people couldn't understand why I wouldn't want this excellent technology!]]></description><dc:creator><![CDATA[Peter]]></dc:creator><pubDate>Mar 14th 2008 2:52PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[The systems used by Visa and MasterCard are proximity-based, like the security cards used for access to my work. To put that into context, the door these cards unlock has two armed guards and a number of security cameras behind it, and the building has large panoramic cameras outside.]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 3:55PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[I called and asked for my bank to replace my PayPassed Mastercard and they told me they wern't making the regular cards anymore... so mine met a hammer :)]]></description><dc:creator><![CDATA[athousandleaves]]></dc:creator><pubDate>Mar 15th 2008 4:00AM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Believe it or not they are not using any security.  I have a reader that I hook into my pc and run hyperterminal.  I wave my Chase blink card by and presto, my name, account number, and expiration date appear on the screen.  The UVA researcher said as much in his interviews.<br><br>You can however easily block someone from doing this by keeping your card in a Secure Sleeve(tm).  It is a shielded card sleeve.  You can buy them for a couple bucks a piece at www.idstronghold.com]]></description><dc:creator><![CDATA[Walt]]></dc:creator><pubDate>Mar 19th 2008 2:14PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[If a man can make it, it can always be counterfeited and/or compromised. I don't think there will ever be a fully secure system because someone will always find a way to get around it. And this is just another example of that. ]]></description><dc:creator><![CDATA[Eric M.]]></dc:creator><pubDate>Mar 14th 2008 2:56PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[That's true, but there's a difference between "hard to clone" and "easy to clone."  When you use stuff in the latter category for sensitive information, that's when bad things start to happen frequently.]]></description><dc:creator><![CDATA[fanguad]]></dc:creator><pubDate>Mar 14th 2008 3:02PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Suer, if it can be done by one person, it can be done by another... but shared secrets of sufficient granularity are enough. It's possible for two people to generate the same 4096-bit encryption key, but it's not likely.<br><br>It's also possible to convert a public key into a private key, but it requires significantly more time than the expected life of the Sun at 4096 bits.<br><br>Why don't these things just use RSA? You could flash a 1K ROM with a 4096-bit keypair at construction time and require a handshake with the authenticating device. It's not rocket science. (But it is computer science! Luckily, that I know!)]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 3:44PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[The attacker collects data.]]></description><dc:creator><![CDATA[John]]></dc:creator><pubDate>Mar 14th 2008 3:11PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[So you company it with a human system.  Pop up on screen a picture of the person.  Take a picture as card is scanned.  Have guard compare them.  Heck, have facial recognition compare them.  Even poor facial recognition can detect if two are significantly different [easier to do than decide they are the same].]]></description><dc:creator><![CDATA[Maztec]]></dc:creator><pubDate>Mar 14th 2008 3:45PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[false alerts would become problematic. How upset would a worker be if he was approached by a guard who is at full alert. ]]></description><dc:creator><![CDATA[polak]]></dc:creator><pubDate>Mar 14th 2008 4:00PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[And while we're at it, you could use the public key as the RFID id since it'd be unique anyway.]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 3:47PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Er, oops, this was supposed to be in reply to Eric's comment three comments up!]]></description><dc:creator><![CDATA[Katie]]></dc:creator><pubDate>Mar 14th 2008 3:48PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[??? Shoes? someone ban this guy, Ryan? Peter? Nilay?]]></description><dc:creator><![CDATA[mikey]]></dc:creator><pubDate>Mar 14th 2008 4:24PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[RE: WholesaleShoescn reply to the first post.]]></description><dc:creator><![CDATA[mikey]]></dc:creator><pubDate>Mar 14th 2008 4:25PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Gah, we're on it. Thanks for the reminder!]]></description><dc:creator><![CDATA[Nilay Patel]]></dc:creator><pubDate>Mar 14th 2008 4:49PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[All the public transport in Santiago de Chile uses the same RFCard system.]]></description><dc:creator><![CDATA[Cristian Riveros]]></dc:creator><pubDate>Mar 14th 2008 4:26PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Couldn't be Happier!!!<br>Personally, I hate RFID in relation to personal info and money transfers.  There are things that should NEVER be wireless.  Passports, Credit Cards, medical history, social security numbers.  If it's related to me, I don't want it wireless.  Leave RFID to inventory control.]]></description><dc:creator><![CDATA[newgalactic]]></dc:creator><pubDate>Mar 14th 2008 4:55PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Woops, that's what I get for taking a liquid lunch, forgot to mention my "point".<br><br>...hopefully RFID being hacked will jog some certain individuals "common sense" enough that they may reconsider placing that technology into the items I mentioned above.]]></description><dc:creator><![CDATA[newgalactic]]></dc:creator><pubDate>Mar 14th 2008 4:57PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[the way corporate america and republicans looks at it... humans=inventory]]></description><dc:creator><![CDATA[fuma]]></dc:creator><pubDate>Mar 14th 2008 5:27PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Wow fuma, +1 "Insightful"]]></description><dc:creator><![CDATA[newgalactic]]></dc:creator><pubDate>Mar 14th 2008 5:42PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[A little perspective may help. I doubt anyone is going to have the time or the opportunity in the London tube network to hang around a swipe station with a laptop as demonstrated. <br><br>To be even more frank we have far more serious things to worry about dealing with terror attacks, if anyone is callous enough to waste the time of the TFL staff and the security forces trying to make a quick buck with this scam they are pond life.]]></description><dc:creator><![CDATA[mymaclife]]></dc:creator><pubDate>Mar 14th 2008 5:39PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Sure it's a computer now, but given a few weeks/months it will be an "ipod" that someone sets on the reader for a second or two as they look for their card. This is just a concept hack right now. Given enough time and will, someone will make it faster/stronger/better. ]]></description><dc:creator><![CDATA[Tim]]></dc:creator><pubDate>Mar 17th 2008 3:21AM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[There's plenty of opportunity on the little used stations, such as the Overground network for example. Little to no staff means that someone equipped with the gear could easily extract the Oyster system encryption key with no disturbance...]]></description><dc:creator><![CDATA[Ian]]></dc:creator><pubDate>Mar 20th 2008 7:08AM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[RFID, contactless or contact card chips are like your computer systems, either in your offices or at homes. Just because the computer systems are hackable, does THAT fact stops you from using your computer systems? No...you just build your security surrounds it...that's all. There is no need to cry baby that these are my personal infos that I won't want them to be hacked. Ask yourself, how many personal infos you keep in your computer systems?]]></description><dc:creator><![CDATA[StopSpamming]]></dc:creator><pubDate>Mar 14th 2008 11:55PM</pubDate></item><item><title><![CDATA[Comments on Oyster Cards vulnerable to RFID hack, lots of other systems too]]></title><link>http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/14/oyster-cards-vulnerable-to-rfid-hack-lots-of-other-systems-too/</guid><description><![CDATA[Uh, Hong Kong's Octopus card system is based on Felica, not Mifare. ]]></description><dc:creator><![CDATA[Jamar]]></dc:creator><pubDate>Mar 15th 2008 12:27AM</pubDate></item></channel></rss>