Slashdot Log In
RFID Personal Firewall
Posted by
samzenpus
on Thu Dec 07, 2006 10:52 AM
from the just-for-you dept.
from the just-for-you dept.
JanMark writes "Prof. Andrew Tanenbaum and his student Melanie Rieback (who published
the RFID virus paper
in March) and 3 coauthors have now published a
paper on a personal RFID firewall called the RFID Guardian. This device
protects its owner from hostile RFID tags and scans in his or her
vicinity, while letting friendly ones through. Their work has won the
Best Paper award at the
USENIX LISA Conference."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Popups. (Score:5, Funny)
Re:Popups. (Score:5, Funny)
Parent
Well do you.... punk (Score:2)
"would you like Macy's to have no idea you're stealing their stuff? [yes][no][im-feeling-lucky]"
Re: (Score:2)
so what do the RFID tags tell Macy's that can't be extracted from a video scan?
age, sex, style of dress, etc. since the beginning of time, salesmen have known what to look for in a prospect.
Well... (Score:4, Interesting)
Condoms, anyone? (Score:2, Funny)
Demo Video (Score:5, Informative)
Tin foil (Score:2, Funny)
Re: (Score:3, Funny)
Faraday Cage (Score:2, Insightful)
Re:Faraday Cage (Score:4, Interesting)
That comment just triggered an odd thought in my head...
Parent
Old News (Score:3, Funny)
Re: (Score:3, Interesting)
Staff: www.rfidguardian.org/people.html
Re: (Score:2)
KISS (Score:4, Insightful)
Re: (Score:2)
Re: (Score:2)
correct me if I am wrong, but I thought RFID tags were passive reflectors. which can be read without contact in somewhat the same sense as an optical bar code can be read without contact.
Re: (Score:2)
Re: (Score:2)
DOH!
Re: (Score:3, Insightful)
They have circuits in them, and wires. The fact that the power source is external is irrelevant. By your logic, a lamp can't have a switch because it relies on current from the wall for power. DOH!
Attack Barriers (Score:5, Interesting)
Link to PDF (Score:5, Informative)
http://www.cs.vu.nl/~melanie/rfid_guardian/papers
But is she hot? (Score:4, Funny)
Tanenbaum's theory is false (Score:3, Informative)
This is not true. There is no Pandora's box. Read the paper and you'll see why.
Tanenbaum and his co-authors exploited vulnerabilities in RFID middleware - the software that connects to an RFID reader. What makes this less interesting is that they wrote the middleware. Yes, they deliberately built in vulnerabilities like SQL injection, then crafted RFID tags to exploit them.
Tanenbaum's team did not find any weaknesses in any commercial RFID middleware. And their entire premise is flawed. The weaknesses they scanned for, such as SQL injection, are not going to exist in the dominant RFID system, which is EPC. An EPC tag contains a binary number (frequently 96 bits). This bit vector is divided into fields for manufacturer, part number, and serial number. It is binary, not text. There is no way a malformed number could trigger an SQL injection vulnerability.
Re: (Score:3, Funny)
And will Tannenbaum back him up this time, too?