Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
RFID Chips Are Here
Scott Granneman, 2003-06-26

RFID chips are being embedded in everything from jeans to paper money, and your privacy is at stake.

Comments Mode:
Great Summary 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (4 replies)
RFID Chips Are Here 2003-06-27
Anonymous (1 replies)
Re: RFID Chips Are Here 2008-02-02
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
Re: RFID Chips Are Here 2007-10-24
Anonymous
RFID Chips Are Here 2003-06-27
DruG5t0r3
RFID Chips Are Here 2003-06-27
Stefan Sokolowski (31 replies)
This is the most hysterical piece of security journalism I have read in a long time.

Through the sea of links, you are taken on a voyage of discovery, and the conclusions that can be made are:

1) There is a good living to me made from recycling other peoples material that you have found on the Internet.

2) Don't try to embellish the content if you don't know what you are talking about. You will be made to look a proper berk by someone who does.

As a real security professional (i.e. one that does not go around screaming that the sky is falling) and as someone who has worked with RFID for the military and for civilian uses (mainly Post Offices) for over six years, I find your article makes a number of glaring omissions that would allow any sensible human being to make a rational judgement about this technology.

Omissions:

1) Range verses size. Very basic issue. The smaller it is, the closer you have to be to it to pick up the signal. For a small passive tag we are talking inches (3-4 feet max). In order to track something from 200 yards (maximum range currently in use), you need an active tag (i.e. with a battery) and it has to be the size of a beer mat. I think you would notice it in your jeans. The signal generator in this case is also a non-trivial device. It is the size on a lamp-post and weights in excuss of 30Kg. Hardly PDA attachment material.
2)Storage area on the device is tiny. For the small passive devices you are referring to the storage area is less than 1Kilobyte.
Not much space for your medical records here.

3)The logic associated with the tyre scenario. The association of the vehicle number and the tyre would not be stored on the tag. There is no space, and Read/Write tags are much more expensive (and larger). Easy to overwrite also. So for your big brother is watching scenario, you would need to replace every lamp-post on every highway with a signal generator, have assess to the database that cross-references your vehicle ID with the tag ids, and be able to monitor all of the signal generators in real-time to see what was happening.

And all this just to find out where you are.
Are you really that important? I think ringing your mobile would be easier.

There is also a problem with reading many tags at once. The current limit is around 200 tags per second for the best sensor. The tag will respond and continue to respond at regular intervals (sub-second usually but dependant on set-up). Because they are all talking at once on the same frequency, the sensor cannot distinguish and ignore tags in real-time. It may recieve many responses from the same tag, and there is no way to tell the tag to shut up. So imagine the situation across a busy highway.

Hope this helps to re-assure people that it is very dangerous to listen to people who don't know what they are talking about.

Stefan Sokolowski CISSP
Security Director
Unisys
UK



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/169/20588#20588
RFID Chips Are Here 2003-06-27
Pascal Allain
RFID Chips Are Here 2003-06-27
Anonymous (2 replies)
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-07-01
Stefan Sokolowski
RFID Chips Are Here 2003-06-27
Anonymous (5 replies)
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (1 replies)
RFID Chips Are Here 2003-07-04
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-29
Tom Parker (tom.parker@pentest-limited.co
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (6 replies)
RFID Chips Are Here 2003-06-27
Mark Robertson
RFID Chips Are Here 2003-06-27
Bagheera
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-29
Anonymous
RFID Chips Are Here 2003-06-30
Y2K Again
RFID Chips Are Here 2003-07-01
Stefan Sokolowski
RFID Chips Are Here 2003-06-27
Fluxxx
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (3 replies)
RFID Chips Are Here 2003-07-04
Aywitb
Re: RFID Chips Are Here 2008-01-22
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Carl Kaehler
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
TKB
to Stefan Sokolowski 2003-06-28
TKB
RFID Chips Are Here 2003-06-28
DigitalSpirit
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-29
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
CISSPs are often the jr. security people
RFID Chips Are Here 2003-07-02
Another Real Life security Professional
RFID Chips Are Here 2003-07-03
Anonymous
RFID Chips Are Here 2003-07-08
Anonymous
RFID Chips Are Here 2003-07-08
Penguinisto
Re: RFID Chips Are Here 2005-10-18
Anonymous
Re: RFID Chips Are Here 2007-08-19
Anonymous
Re: RFID Chips Are Here 2008-01-22
no body
Re: RFID Chips Are Here 2008-02-28
Samuel Fischer
Re: RFID Chips Are Here 2008-06-15
Anonymous
My RAM dies on a static discharge. 2003-06-27
webgiant (6 replies)
My RAM dies on a static discharge. 2003-06-27
Wrex (1 replies)
My RAM dies on a static discharge. 2003-06-30
Roger (1 replies)
RFID Chips Are Here 2003-06-27
Anonymous
I like the idea of RFID chips 2003-06-27
Peter (4 replies)
People with bar codes! 2006-04-03
Anonymous
Re: I like the idea of RFID chips 2008-04-04
Anonymous
Re: I like the idea of RFID chips 2008-06-17
Anonymous
RFID Chips Are Here 2003-06-27
TJ
Mark of the Beast 2003-06-27
Charbroiled
mCloak is Here... 2003-06-27
Bob
RFID Chips Are Here 2003-06-27
Anonymous
Trust 2003-06-27
sh64109
RFID Chips Are Here 2003-06-27
Dave Dooling
RFID Chips Are Here 2003-06-27
Anonymous
Anonymous Purchases 2003-06-27
Steve Pannekoeken
RFID Chips Are Here 2003-06-27
Anonymous
track anyone's RFID tags 2003-06-28
RFtracker.com
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
You forgot about Built in burn outs 2003-06-28
Gypsy Rogers
RFID Chips Are Here 2003-06-28
J
RFID Chips Are Here 2003-06-28
Jack@jackmatthews.com
RFID Chips Are Here 2003-06-29
elg
RFID Chips Are Here, so is EMP 2003-06-30
Anonymous (1 replies)
RFID Chips Are Here, so is EMP 2003-07-02
AnonymousGeoff
RFID Chips Are Here 2003-06-30
Anonymous
RFID Chips Are Here 2003-06-30
Amera
RFID Chips Are Here 2003-06-30
Vance
RFID Chips Are Here 2003-06-30
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-02
Anonymous
RFID Chips Are Here 2003-07-02
Fred Dunn (1 replies)
Re: RFID Chips Are Here 2007-04-16
Anonymous
RFID Chips Are Here 2003-07-03
Anonymous
unique id's 2003-07-03
Anonymous (1 replies)
unique id's 2003-07-08
Anonymous (1 replies)
Re: unique id's 2008-03-13
Anonymous
RFID Chips and thiefs 2003-07-08
Anonymous
RFID Chips Are Here 2005-08-03
Anonymous
RFID Chips Are Here 2005-11-15
Brandon
RFID Chips Are Here 2006-01-05
ParanoidNot
RFID Chips Are Here 2006-03-13
Anonymous
RFID Chips Are Here 2006-07-26
Anonymous (1 replies)
Re: RFID Chips Are Here 2006-08-23
Anonymous
RFID Chips Are Here: Chips in Humans 2006-12-03
Anonymous (1 replies)
RFID Chips Are Here// Rev 13:16 2007-04-26
Joanna Oznowicz-Davis
Orwell Was Right 2007-08-18
Anonymous (1 replies)
Re: Orwell Was Right 2007-10-04
Anonymous (1 replies)
Re: Re: Orwell Was Right 2007-12-18
Anonymous
Too far 2007-10-05
KATRINA (2 replies)
Re: Too far 2007-10-19
Anonymous
Re: Too far 2007-11-11
Anonymous
RFID Chips Are Here. 2007-10-14
Anonymous
RFID Chips Are Here 2007-11-11
Anonymous
RFID Chips Are Here 2007-12-18
Anonymous (1 replies)
Re: RFID Chips Are Here 2007-12-23
Anonymous
RFID Chips Are Here 2008-01-17
Anonymous (1 replies)
Re: RFID Chips Are Here 2008-01-22
Anonymous (1 replies)
Revolution is the only answer 2008-03-14
ginger (1 replies)
Re: Revolution is the only answer 2008-07-08
Anonymous
RFID Chips Are Here 2008-01-30
steve
RFID Chips Are Here 2008-02-06
Anonymous
RFID Chips Are Here 2008-02-08
Anonymous
RFID Chips Are Here 2008-02-21
Anonymous
RFID Chips Are Here 2008-03-07
Anonymous
RFID Chips Are Here 2008-03-27
Justin Lamb
RFID Chips Are Here 2008-04-14
J Schukow
RFID Chips Are Here 2008-04-23
Anonymous
WE HAD FREEDOMS 2008-04-28
Anonymous (1 replies)
Re: WE HAD FREEDOMS 2008-05-17
Anonymous (1 replies)
RFID Chips Are Here 2008-06-01
Anonymous
RFID Chips Are Here 2008-06-05
Anonymous
RFID Chips Are Here 2008-08-12
Destroy the NewWorldOrder
movie very on topic 2008-08-14
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus