Slashdot Mirror


Smart Cards Vulnerable to Photo-Flash Attacks?

belphegor writes "Researchers at the University of Cambridge have found a way to use a camera flash and microscope to extract data from smart cards. " Notable because its apparently relatively simple to do and really throws a monkey wrench into a variety of businesses that use smart cards to store important data.

8 of 214 comments (clear)

  1. smartcards have always been lacking by Lumpy · · Score: 5, Informative

    there is very little tamper protection on smartcards due to their flimsy construction. you cant make a rapid zeroization system on something that isn't rigid and tough enough to be driven over repeatedly by a car or take the huge amount of abuse the human carrier provides every day.

    except... dallas semiconductor long ago created the ibutton that is more secure and better than any smartcard..

    (I know I sound like a broken record, but ibuttons are way better and cooler than any smartcard, and you as a home hacker can use them!)

    --
    Do not look at laser with remaining good eye.
    1. Re:smartcards have always been lacking by Jon+Peterson · · Score: 5, Interesting

      OK, so smart cards are not tamper resistant. I don't see that any attack based around stealing a smart card is anything to worry about, assuming the card itself only stores dumb information like a sum of money or an id number.

      Guess what?! Criminals can read the information from a credit card using nothing more sophisticated than their eyes! Does this render credit cards an appalling security risk? No, because when it gets stolen you report it and cancel the card.

      Now, if someone figures out a way to _write_ to the smart card to people can top up sums of money or whatever, that's a problem. Also, if the smartcard stores data that's useful in itself - say your real naem and address, or other bank account numbers, or what have you, then you certainly don't want that being read by someone else.

      --
      ----- .sig: file not found
  2. No worries, we'll just pass more laws... by Dimensio · · Score: 5, Insightful

    All that needs to happen is for makers of smart cards to send money to Congresscritters to pass laws against smart card "circumvention devices" and have anyone making, selling or posessing a flash-based camera arrested.

    Remember, when a security technology is comprimised you don't improve the technology, you outlaw anything that exposes its weakness.

    1. Re:No worries, we'll just pass more laws... by nolife · · Score: 5, Interesting

      This happened in the past with the padding of the cell phone industry. Analog mode cell phones send clear audio over the air in roughly the 868-890 MHz range. To protect the cell phone industry, the government passed a law in 1994 to prevent the sale of consumer radio scanners from receiving these frequencies. That worked for a while but many scanners were easily 'hacked' to get this region back. In 1997 the law was modified/changed to make it illegal to modify a scanner and companies had to produce scanners that were tamper proof.

      These air bands were open to public ears for decades before the cell phone industry came to life. They chose to use "plain text" audio for analog transmissions to save money with no regard for your privacy. The government stepped in to bail them out when scanning these frequencies became popular and to give the public a false sense of security so they would buy more of them and keep the cell phone industry going strong.

      It is also illegal to listen to analog cordless phones (46-49MHz/900MHz) but there is no law preventing the scanners from receiving these bands. I guess the cordless guys could not drum up enough soft money to get that through.

      --
      Bad boys rape our young girls but Violet gives willingly.
  3. So let me get this straight, by Civil_Disobedient · · Score: 5, Interesting

    Lemme see if I understand right. Reverse engineer hardware to show its inherit ineffectualness -- that's ok. Reverse engineer software to show its inherit ineffectualness -- that's illegal.

    Ok, just making sure.

  4. Re:They should have used the iButton by arkanes · · Score: 5, Funny

    Yeah, because I have this pressurised N2 atmosphere sitting over here in my basement...

  5. it's sad this springs to mind. by BreakWindows · · Score: 5, Funny

    A team of researchers from I.B.M.'s Thomas J. Watson Laboratory in Yorktown Heights, N.Y., said they would present a report at the conference based on their discovery ...

    Dmitri called. He said if you see any guys in cheap suits applauding on stage right, exit stage left.

  6. Re:They should have used the iButton by Tackhead · · Score: 5, Funny
    > Yeah, because I have this pressurised N2 atmosphere sitting over here in my basement...

    I tried building that. I'm 70% of the way there.