RFID Security
This post was written in reaction to this Slashdot story about Gilette’s agreement to purchase half a billion RFID tags from the eminently fascinating and quite well named Alien Technology. I’d probably be rather annoyed at the name of the company if I hadn’t watched their video regarding Fluidic Self Assembly…but lets just say they earned the name. Building LCD screens, a pixel at a time. Whoa.
Interesting. I just started doing some preliminary research on the security of RFID badge readers, based off of hazy memories that somebody had shown they were absolutely trivial to capture and replay.
Haven’t been able to find that paper yet, but I can tell you what I’ve seen ain’t great. Here’s the story:
RFID stands for Radio Frequency Identification, and is essentially a Tesla-esque hack to allow contactless, bidirectional storage of small amounts of data on trivial circuits powered by the reader infrastructure itself. It’s most commonly deployed nowadays as a replacement for magnetic-swipe oriented systems, as the lack of an exposed data surface and the absence of contact during scanning make RFID astonishingly reliable. The functionality is quite compelling, as Gilette’s mass purchase shows — what if you never needed to do inventory? What if you could just have a few sensors throughout your warehouse do a “mass ping” and acquire from the mass of replies precisely what needs to be restocked?
And it would only take a few sensors, too. Badge readers may only provide a few inches range, but there was a pretty big fuss a while back about RFID becoming functional at nine meters. At that point, you’re quite a bit beyond the forklift knowing precisely what it’s carrying. It’s pretty clear that Gilette will make its $50M back within a year.
Oddly enough, Inventory Tracking is much, much better use of RFID than as a badging technology, even though the latter remains much more common than the former. Badging, like all trust management systems, attempts to differentiate the few who are trusted from the many that aren’t.