Long Range RFID Hacking Tool To Be Released At Black Hat
msm1267 writes "Next week at the Black Hat Briefings in Las Vegas, a security researcher will release a modified RFID reader that can capture data from 125KHz low frequency RFID badges from up to three feet away. Previous RFID hacking tools must be within centimeters of a victim to work properly; this tool would allow an attacker or pen-tester to store the device inside a backpack and it would silently grab card data from anyone walking close enough to it.The researcher said the tool will be the difference between a practical and impractical attack, and that he's had 100 percent success rates in testing the device. Schematics and code will be released at Black Hat as well."
Plus it's built using an Arduino.
...as in, almost though not quite enough to reach into an American's personal bubble, but totally workable in Japan.
Ezekiel 23:20
I wouldn't necessarily qualify three feet as long range.
But this could still pose a danger to the upcomming mass RFID use...
he's had 100 percent success rates in testing the device
a 100% success rate between 2 failed attempts
You can by commercial products that can read RFID tags from a lot further away. 5 seconds on google and I found long range passive rfid reader for vehicle management that claims 8 to 15 metres.
I suspect that some researchers really don't have a clue as to what state of the art is.
Plus when it comes to reading things via radio waves the most important thing is the antenna and not the computer connected to it. So saying "Plus it's built using an Arduino." is getting almost as bad as patents that are ".. using a computer!!!!!!!!!!"
I am Slashdot. Are you Slashdot as well?
http://www.muji.us/store/aluminum-card-case-thick.html
It blocks your cards from being read, fits nicely in your shirt pocket, and durable and stylish ta boot.
.
Prisencolinensinainciusol. Ol Rait!
How convenient....
I'm wondering now if it's time to buy a RIFD proof wallet. Anyone have experience with them? Do they work?
According to a relative of mine in law enforcement this attack is already in play in several major cities. Generally targeting Apple stores as the cards that are collected are more-likely to have higher limits and available balances. The CC thief generally stands at the entrance to the store with a backpack, and is automatically uploading card details to a central host. Those details are then written to blank cards and used in Casinos in Las Vegas within a matter of hours.
ungggghhhh
"Plus it's built using an Arduino." Not news worthy until it's on the pi!
Once this applies to NFC, things will get interesting as just reading NFC gets you the track2 information of a credit card.
Or take two smartphones and "pay" using the smartphone while you bill it to someone else without having to bump them. (NFC proxy).
Does it work trough the RFID Blocking Wallet?
125KHz is the same freq. that they use in the little rfid pills they inject to your pets...
I'd love to be able to track / control my pets around the house with this
- Sick cat? only give it access to one of the litter boxes.
- Cat with different dietary requirements? Give them each their own bowl that are 5+ feet away from each other and have it with a door / retractable cover.
- Outdoor cat? Have the cat door unlock when it gets close to it, but only for that one cat.
Just light the back of the card up and you'll see the rfid antenna and chip. Sunlight might do the job if the card is thin enough.
--- I am known for the ones who want to find me on the net. Is that a privacy risk or a privilege? One might wonder..