Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
RFID Chips Are Here
Scott Granneman, 2003-06-26

RFID chips are being embedded in everything from jeans to paper money, and your privacy is at stake.

Comments Mode:
Great Summary 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (4 replies)
RFID Chips Are Here 2003-06-27
Anonymous (1 replies)
Re: RFID Chips Are Here 2008-02-02
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
Re: RFID Chips Are Here 2007-10-24
Anonymous
RFID Chips Are Here 2003-06-27
DruG5t0r3
RFID Chips Are Here 2003-06-27
Stefan Sokolowski (31 replies)
RFID Chips Are Here 2003-06-27
Pascal Allain
RFID Chips Are Here 2003-06-27
Anonymous (2 replies)
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-07-01
Stefan Sokolowski
RFID Chips Are Here 2003-06-27
Anonymous (5 replies)
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (1 replies)
RFID Chips Are Here 2003-07-04
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-29
Tom Parker (tom.parker@pentest-limited.co
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (6 replies)
RFID Chips Are Here 2003-06-27
Mark Robertson
RFID Chips Are Here 2003-06-27
Bagheera
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-29
Anonymous
RFID Chips Are Here 2003-06-30
Y2K Again
RFID Chips Are Here 2003-07-01
Stefan Sokolowski
RFID Chips Are Here 2003-06-27
Fluxxx
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous (3 replies)
RFID Chips Are Here 2003-07-04
Aywitb
Re: RFID Chips Are Here 2008-01-22
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Carl Kaehler
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-27
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
TKB
to Stefan Sokolowski 2003-06-28
TKB
RFID Chips Are Here 2003-06-28
DigitalSpirit
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-29
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
CISSPs are often the jr. security people
The author doesn't say the sky is falling, he is commenting on potential privacy-eroding technology (which the US does not legislate against) and some of the links even offer solutions.

RFID tags have been standardized and that is what he is talking about with range-v-size so your reference to large devices is off-topic. One artice (linked I believe) states that a 9 meter ranged prototype for standard RFID tags has been constructed.

If I buy jeans in a store, the store's database will have that meaning next time I walk in (through the electronic security gates most stores have) they can track that I walked in. They can link what I buy and build a profile; if they share the data a la DoubleClick, then quite a profile can be collected. Anytime ID is taken and someone has a purse or handbag with an RFID tag, there is the potential for linking this data.

This is the privacy concern but it is not a sky-is-falling prophecy. Even if the ID-person match is not available, tracking where a pair of jeans goes can reveal advertiser-interesting data. The whole concern is after-checkout tracking (which will be valuable).

Why couldn't tires be checked at border crossings and then at toll booth stops (or traffic lights or what have you). If I was the INS, I would think about this for tracking the cars of visitors to ensure that they did not stay too long -- or track criminals -- or simply as an alternative way to pay tolls -- or to pay for gas -- or to track rental cars.

If you open your mind just a bit, you will realize that RFID technology is really neat and it has a lot of potentials. Security practitioners (CISOs, security administrators, security analysts, firewall specialists, etc. etc. save privacy compliance officers) will not need to pay professional attention to the risks of RFID given that they have limited resources and there are many wiser places to use them (ie. get rid of the low hanging fruit before worrying about the next big problem).

However, policy makers and citizens should be concerned about such things as well as the manufacturers and users (so they can have more secure alternatives ready to sell in those situations where such alternatives make sense).

About my byline: You engaged in your comment in an opening hard criticism of the author and by including your company in your signature, implicated these rude and ill-considered views to those of your employer. There is no reason to ignore security against liability and bad press and taking a dump on the author is quite uncalled for. There is nothing wrong with summarizing other work and linking to it.

I have also found that CISSPs tend to have the required knowledge, maybe some business skills or ambition but not necessarily strong analytical skills, background, and the ability to view the big picture. I had one CISSP come to me who thought DES was an inherently insecure cryptographic algorithm and challenged me when I said it was a good algorithm save that the bitlength is too small -- hence triple-DES (and then I went on to explain in my presentation about why three-key triple-DES is not the same strength as an algorithm with triple the bit length) in a presentation on the business uses of cryptography.

You definately prove the point in your last sentence.

- A former applied cryptographyer/security analyst at a large bank

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/169/20693#20693
RFID Chips Are Here 2003-07-02
Another Real Life security Professional
RFID Chips Are Here 2003-07-03
Anonymous
RFID Chips Are Here 2003-07-08
Anonymous
RFID Chips Are Here 2003-07-08
Penguinisto
Re: RFID Chips Are Here 2005-10-18
Anonymous
Re: RFID Chips Are Here 2007-08-19
Anonymous
Re: RFID Chips Are Here 2008-01-22
no body
Re: RFID Chips Are Here 2008-02-28
Samuel Fischer
Re: RFID Chips Are Here 2008-06-15
Anonymous
My RAM dies on a static discharge. 2003-06-27
webgiant (6 replies)
My RAM dies on a static discharge. 2003-06-27
Wrex (1 replies)
My RAM dies on a static discharge. 2003-06-30
Roger (1 replies)
RFID Chips Are Here 2003-06-27
Anonymous
I like the idea of RFID chips 2003-06-27
Peter (4 replies)
People with bar codes! 2006-04-03
Anonymous
Re: I like the idea of RFID chips 2008-04-04
Anonymous
Re: I like the idea of RFID chips 2008-06-17
Anonymous
RFID Chips Are Here 2003-06-27
TJ
Mark of the Beast 2003-06-27
Charbroiled
mCloak is Here... 2003-06-27
Bob
RFID Chips Are Here 2003-06-27
Anonymous
Trust 2003-06-27
sh64109
RFID Chips Are Here 2003-06-27
Dave Dooling
RFID Chips Are Here 2003-06-27
Anonymous
Anonymous Purchases 2003-06-27
Steve Pannekoeken
RFID Chips Are Here 2003-06-27
Anonymous
track anyone's RFID tags 2003-06-28
RFtracker.com
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
RFID Chips Are Here 2003-06-28
Anonymous
You forgot about Built in burn outs 2003-06-28
Gypsy Rogers
RFID Chips Are Here 2003-06-28
J
RFID Chips Are Here 2003-06-28
Jack@jackmatthews.com
RFID Chips Are Here 2003-06-29
elg
RFID Chips Are Here, so is EMP 2003-06-30
Anonymous (1 replies)
RFID Chips Are Here, so is EMP 2003-07-02
AnonymousGeoff
RFID Chips Are Here 2003-06-30
Anonymous
RFID Chips Are Here 2003-06-30
Amera
RFID Chips Are Here 2003-06-30
Vance
RFID Chips Are Here 2003-06-30
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-01
Anonymous
RFID Chips Are Here 2003-07-02
Anonymous
RFID Chips Are Here 2003-07-02
Fred Dunn (1 replies)
Re: RFID Chips Are Here 2007-04-16
Anonymous
RFID Chips Are Here 2003-07-03
Anonymous
unique id's 2003-07-03
Anonymous (1 replies)
unique id's 2003-07-08
Anonymous (1 replies)
Re: unique id's 2008-03-13
Anonymous
RFID Chips and thiefs 2003-07-08
Anonymous
RFID Chips Are Here 2005-08-03
Anonymous
RFID Chips Are Here 2005-11-15
Brandon
RFID Chips Are Here 2006-01-05
ParanoidNot
RFID Chips Are Here 2006-03-13
Anonymous
RFID Chips Are Here 2006-07-26
Anonymous (1 replies)
Re: RFID Chips Are Here 2006-08-23
Anonymous
RFID Chips Are Here: Chips in Humans 2006-12-03
Anonymous (1 replies)
RFID Chips Are Here// Rev 13:16 2007-04-26
Joanna Oznowicz-Davis
Orwell Was Right 2007-08-18
Anonymous (1 replies)
Re: Orwell Was Right 2007-10-04
Anonymous (1 replies)
Re: Re: Orwell Was Right 2007-12-18
Anonymous
Too far 2007-10-05
KATRINA (2 replies)
Re: Too far 2007-10-19
Anonymous
Re: Too far 2007-11-11
Anonymous
RFID Chips Are Here. 2007-10-14
Anonymous
RFID Chips Are Here 2007-11-11
Anonymous
RFID Chips Are Here 2007-12-18
Anonymous (1 replies)
Re: RFID Chips Are Here 2007-12-23
Anonymous
RFID Chips Are Here 2008-01-17
Anonymous (1 replies)
Re: RFID Chips Are Here 2008-01-22
Anonymous (1 replies)
Revolution is the only answer 2008-03-14
ginger (1 replies)
Re: Revolution is the only answer 2008-07-08
Anonymous
RFID Chips Are Here 2008-01-30
steve
RFID Chips Are Here 2008-02-06
Anonymous
RFID Chips Are Here 2008-02-08
Anonymous
RFID Chips Are Here 2008-02-21
Anonymous
RFID Chips Are Here 2008-03-07
Anonymous
RFID Chips Are Here 2008-03-27
Justin Lamb
RFID Chips Are Here 2008-04-14
J Schukow
RFID Chips Are Here 2008-04-23
Anonymous
WE HAD FREEDOMS 2008-04-28
Anonymous (1 replies)
Re: WE HAD FREEDOMS 2008-05-17
Anonymous (1 replies)
RFID Chips Are Here 2008-06-01
Anonymous
RFID Chips Are Here 2008-06-05
Anonymous
RFID Chips Are Here 2008-08-12
Destroy the NewWorldOrder
movie very on topic 2008-08-14
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus