RFID Security

This post was written in reaction to this Slashdot story about Gilette’s agreement to purchase half a billion RFID tags from the eminently fascinating and quite well named Alien Technology. I’d probably be rather annoyed at the name of the company if I hadn’t watched their video regarding Fluidic Self Assembly…but lets just say they earned the name. Building LCD screens, a pixel at a time. Whoa.

Interesting. I just started doing some preliminary research on the security of RFID badge readers, based off of hazy memories that somebody had shown they were absolutely trivial to capture and replay.

Haven’t been able to find that paper yet, but I can tell you what I’ve seen ain’t great. Here’s the story:

RFID stands for Radio Frequency Identification, and is essentially a Tesla-esque hack to allow contactless, bidirectional storage of small amounts of data on trivial circuits powered by the reader infrastructure itself. It’s most commonly deployed nowadays as a replacement for magnetic-swipe oriented systems, as the lack of an exposed data surface and the absence of contact during scanning make RFID astonishingly reliable. The functionality is quite compelling, as Gilette’s mass purchase shows — what if you never needed to do inventory? What if you could just have a few sensors throughout your warehouse do a “mass ping” and acquire from the mass of replies precisely what needs to be restocked?

And it would only take a few sensors, too. Badge readers may only provide a few inches range, but there was a pretty big fuss a while back about RFID becoming functional at nine meters. At that point, you’re quite a bit beyond the forklift knowing precisely what it’s carrying. It’s pretty clear that Gilette will make its $50M back within a year.

Oddly enough, Inventory Tracking is much, much better use of RFID than as a badging technology, even though the latter remains much more common than the former. Badging, like all trust management systems, attempts to differentiate the few who are trusted from the many that aren’t.

Read the rest of this entry »

Behold, The Volumetric Canvas!

Ever since the late 3Dfx revolutionized consumer PC hardware — and by revolutionized, I mean “was completely without peer for over two years” — it’s been clear that specialized ASICs (Application Specific Integrated Circuits) can, in certain instances, utterly wipe the floor with General Purpose processors — even with Moore’s Death March fully in place. I doubt even a Pentium 4 can match 3Dfx’s first product when it comes to the bilinear filtering of even a moderate number of polygons!

The story continues, though. 3Dfx was supplanted, and eventually purchased outright, by nVidia…and here’s where things get interesting: Those circuits, ever so specialized, once only barely programmable via register combiners, have grown in power and flexibility. They’re becoming…if not general purpose, no longer fixed function. NV20 — embedded in the GeForce 3 and the X-Box — retains the capacity to execute small but powerful pixel and vertex programs against anything streaming out the pipe. The specialized have gone general — what’s old is new again.

And interesting things are coming because of it.

Check this out: At SIGGRAPH 2002, Christof Rezk-Salama released OpenQVIS, his implementation of the techniques in his doctoral thesis: Volume Rendering Techniques for General Purpose Graphics Hardware. What’s this? Check out the following renderings:

Original source: /vol/volren_CTA.jpg
Original source: /vol/volren_CTHead_rmgw01.jpg
Original source: /vol/volren_Isis.jpg
Original source: /vol/volren_MRHead.jpg
Original source: /vol/volren_MicroCT.jpg

Three things are important to realize about those images: First, the hardware used to render them was built to render polygons, not MRI data. Second, if you’ve got an X-Box in your living room, you already own the requisite silicon. Finally, those images render in realtime, somewhere between 10 and 30FPS. Relative to software performance, that’s the same kind of boost to volumetric rendering as we saw hardware provide to the polygon thrash — not bad, considering the once fixed-function hardware was never intended to provide this service!

Now, Rezk-Salama isn’t the first to be doing such work. It was, after all, Klaus Engel’s Pre-Integrated Volume Renderer that introduced me to realtime volumetric rendering, not to mention OpenQVIS itself. Klaus’s work is excellent, but it’s OpenQVIS that has me really excited. It’s complete, mature, cross platform through the Qt toolkit, and Open Source. It’s trivial to generate data for, and it’s fast. So, we’ve got a way to directly render arbitrary 3D matrixes. What will you do with it? Keep me posted 🙂

Read the rest of this entry »

This isn't how to crack SSH…

…this is SSH on crack 🙂 Such was my line back during Black Hat 2001; I did all sorts of funky things with OpenSSH. Since then, some major new stuff has come out. Check it out:

  • LUFS: The Linux Userspace File System.
    lufsmount sshfs://user@host /mnt/dir

    I’ve been saying for quite some time that ssh2’s sftp was the dark horse network file system of the future. LUFS ain’t perfect — but wow, that’s one hell of a proof of concept.

  • JSch: Java Secure Channel

    Java may be an “Internet-Ready Language”. Java may be a “Secure Language”. Now, finally, we can make Java a “Secure-Internet Ready Language”, without having to resort to deploying IPSec. Using JSch, arbitrary Java2 applications can route their normal, insecure traffic, through SSH2, to wherever it needs to go. In other words — no more pain trying to secure and authenticate your Java traffic; just SSH into a host and talk securely to the TCP resources at its disposal. Excellent.

Read the full entry »

C’est Graphique 2002

Considering everything I’ve been up to for the last couple of months, you’d think I’d be satisfied. But alas, there was indeed one event I had to skip — SIGGRAPH 2002, in (I believe) San Antonio.

Hmmm? A network/security geek, mourning a missed SIGGRAPH?

Not so surprising. I started out in Graphics, before meandering through Web Design, User Interfaces, Emergency Windows Repair, Unix Admin, Security, Low Level Networking…heh, and whatever comes next. But after attending SIGGRAPH 2001, and seeing the Ferrofluid Masterpiece, Protrude, Flow live, I remembered exactly what attracted me to graphics in general and SIGGRAPH in particular.

Nothing like your brain calling bullshit on your eyes to wake you up in the morning.

Anyway, there was some genuinely incredible stuff at SIGGRAPH this year that, surprisingly enough, I never saw much mention of after the show. (As it turns out, my absolute favorite piece of work — the one I myself have become an avid user of — doesn’t even show up on Google!) This is shocking, to the point that I’m actually going to bother to report on something like four months after the fact just because, well, it’s just that impressive.

The definitive, though incomplete archive of papers can be found here; I’ve decided to write about a few of the things that surprised/impressed me. Note, I’m heavily biased towards those papers that I could actually download the associated videos of, so very cool sounding things (like raytracing with pixel shaders) couldn’t really be checked out. Oh well.

Read the rest of this entry »

Idea

Whew! Running through the prerelease audit, last 24 to 48 hours before I stamp this 1.0 and move onto more interesting things, like 1.1 and 1.2. Just stamped out an ugly but incredible obscure ICMP parsing bug, and in doing so almost completely removed that annoying Ethernet dependancy permeating even my L3 port scanner. Hopefully I’ll be able to sneak some NAT2NAT code in under the buzzer, given that it’s even more useful and bizarre than Yet Another Port Scanner.

I may just wait until after Paketto comes out, just so I’ll have access to a real development environment. Yes folks, my code is finally stranger than my home network, and that’s saying something.

But that’s not the purpose of this post: Are you an administrator at a large school or company that tracks computer models and MAC addresses en masse, and has for several years? Mail me.

Read the full entry »

Domo Arigato, Mr. Paketto

On networks, as in most things, there is that which is possible, and there is that which is impossible. There is a line between the two, built on assumptions, thoughts, and precious few truths.

It’s reasonable to argue that the definition of progress is in moving that line…by whatever cracked-out means happen to be available, as the case may be. Recently, I wrote significant portions of a book: Hack Proofing Your Network: Second Edition, from Syngress Press. Beyond finally documenting the massive hackery I’ve always been known to pull with OpenSSH, Syngress gave me the opportunity to research useful implications of spoofing techniques.

The result: On Saturday, August 3rd, 2002, I am delivering the following talk at Defcon X, in Las Vegas:

Communication under TCP/IP networks has become extraordinarily popular; still, there remains significant problems that as of yet have remained unsolved within its layered rules. So, lets break the rules, elegance (and possibly security) be damned. Signficant new techniques and code will be unveiled to answer the following questions:

A) Instant Portscan

B) Guerrila Multicast 

Read the rest of this entry »