<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: smartcard]]></title>
    <link>http://securityratty.com/tag/smartcard</link>
    <description></description>
    <pubDate>Wed, 05 Mar 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[RFID Smartcard Vulnerability Published, Allows Anyone To Crack It In Minutes Using Inexpensive Tools]]></title>
      <link>http://securityratty.com/article/5a0a77597d26c38bcccaef92987ee312</link>
      <guid>http://securityratty.com/article/5a0a77597d26c38bcccaef92987ee312</guid>
      <description><![CDATA[Details about worlds most widely deployed radio frequency identification (RFID) smartcard vulnerability have finally been published Monday. RFID smartcards are used to control access to many...]]></description>
      <content:encoded><![CDATA[Details about world&#8217;s most widely deployed radio frequency identification (RFID) smartcard vulnerability have finally been published Monday. RFID smartcards are used to control access to many transportation systems, military installations, and other restricted areas, and it can be cracked in a matter of minutes using inexpensive tools.
The first among the 2 papers about this issue [...]]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 19:22:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rfid">rfid</category>
      <category domain="http://securityratty.com/tag/inexpensive tools">inexpensive tools</category>
      <category domain="http://securityratty.com/tag/smartcard vulnerability">smartcard vulnerability</category>
      <category domain="http://securityratty.com/tag/rfid smartcards">rfid smartcards</category>
      <category domain="http://securityratty.com/tag/radio frequency identification">radio frequency identification</category>
      <category domain="http://securityratty.com/tag/transportation systems">transportation systems</category>
      <category domain="http://securityratty.com/tag/military installations">military installations</category>
      <category domain="http://securityratty.com/tag/minutes">minutes</category>
      <category domain="http://securityratty.com/tag/control access">control access</category>
      <source url="http://cyberinsecure.com/rfid-smartcard-vulnerability-published-allows-anyone-to-crack-it-in-minutes-using-inexpensive-tools/">RFID Smartcard Vulnerability Published, Allows Anyone To Crack It In Minutes Using Inexpensive Tools</source>
    </item>
    <item>
      <title><![CDATA[Mt. Sinai Medical Center looks to open standards for patient smartcards ]]></title>
      <link>http://securityratty.com/article/7707ac3bbe29e5f74497f090b7e5ce69</link>
      <guid>http://securityratty.com/article/7707ac3bbe29e5f74497f090b7e5ce69</guid>
      <description><![CDATA[New York City's Mt. Sinai Medical Center, which a few years ago began a project to give patients a smartcard storing identity and health records, is realigning its focus with an eye toward using...]]></description>
      <content:encoded><![CDATA[New York City's Mt. Sinai Medical Center, which a few years ago began a project to give patients a smartcard storing identity and health records, is realigning its focus with an eye toward using format standards that could help spur many hospitals to back the idea of a single, shared patient card.]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sinai medical center">sinai medical center</category>
      <category domain="http://securityratty.com/tag/patient card">patient card</category>
      <category domain="http://securityratty.com/tag/york city">york city</category>
      <category domain="http://securityratty.com/tag/format standards">format standards</category>
      <category domain="http://securityratty.com/tag/health records">health records</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/single">single</category>
      <source url="http://www.networkworld.com/news/2008/082708-mt-sinai-open-standards-smartcards.html?fsrc=rss-security">Mt. Sinai Medical Center looks to open standards for patient smartcards </source>
    </item>
    <item>
      <title><![CDATA[Learning from Ghana]]></title>
      <link>http://securityratty.com/article/6db10d84d0fd57500d7865198a2bae4a</link>
      <guid>http://securityratty.com/article/6db10d84d0fd57500d7865198a2bae4a</guid>
      <description><![CDATA[Its always interesting to see where the developed world can learn from emerging economies. A lot of the best engineering work comes from having to deal with harsh constraints (opposite of architecture...]]></description>
      <content:encoded><![CDATA[<p>Its always interesting to see where the developed world can learn from emerging economies. A lot of the best engineering work comes from having to deal with harsh constraints (opposite of architecture astronomics). I <a href="http://1raindrop.typepad.com/1_raindrop/2007/08/beer-shotguns-a.html">blogged awhile ago</a> about using smart cards for digital cash in Africa</p>

<p><br />
<img alt="Ezwichcard" title="Ezwichcard" src="http://1raindrop.typepad.com/photos/uncategorized/2008/05/09/ezwichcard.jpg" border="0" style="float: left; margin: 0px 5px 5px 0px;" /></p>

<p>Looks like there is a new system in Ghana as well</p>

<blockquote><a href="http://www.newtimesonline.com/index.php?option=com_content&task=view&id=15408&Itemid=203">E-zwhich smart launched</a>

<p>-ZWICH smartcard, a universal electronic system that facilitates easy access to and transfer of money has now become part of financial transactions in Ghana.</p>

<p>The new system which is also designed to remove the cumbersome and insecure processes of using cash, was launched in Accra yesterday by President J.A. Kufuor, with a call on corporate bodies and government agencies to use it to ensure transparency and integrity on payrolls.</p>

<p>E-zwich is an electronic payment system that allows one to make payments for goods and services or transfer money to others without having to carry physical cash.</p>

<p>Available at all banks countrywide, the system involves the loading of money onto the smart card after registering with any bank without necessarily having an accounts with that bank.</p>

<p>President Kufuor said the introduction of the system has the potential of transforming the payments landscape, the financial services industry and the general conduct of business in the country.</p>

<p>He said accessing the technology was an integral part of government’s overall vision of making Ghana the gateway to the West Africa sub-region and transforming her into a major financial hub.</p>

<p>The President said that globalisation has come with a major challenge of adopting best practices in all spheres of endeavour especially within the macro economy in order to survive in the market.</p>

<p>He said it was against that background that the government has pursued polices to develop and modernise the financial sector to enable it to play a key role in resource mobilisation for increased investment.</p>

<p>With the reforms and the stability of the macro-economy, President Kufuor said the nation was witnessing dramatic growth in the banking sector.</p>

<p>He pointed out, however, that inspite of the impressive growth of financial institutions, an estimated 80 per cent of the eligible population was still "un-banked" or "under-banked" and seemed not to have access to financial services.</p>

<p><br />
</blockquote></p>

<p>Wonder when we will see US, UK, and other first world banks and brokerages catch up to Ghana and South Africa on these technologies? Is it really a good idea in 2008 to have everyone type their username and password into a web browser?</p>]]></content:encoded>
      <pubDate>Fri, 09 May 2008 06:27:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/system involves">system involves</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial services industry">financial services industry</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/electronic payment system">electronic payment system</category>
      <category domain="http://securityratty.com/tag/ghana">ghana</category>
      <category domain="http://securityratty.com/tag/president kufuor">president kufuor</category>
      <category domain="http://securityratty.com/tag/kufuor">kufuor</category>
      <category domain="http://securityratty.com/tag/universal electronic system">universal electronic system</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/05/learning-from-g.html">Learning from Ghana</source>
    </item>
    <item>
      <title><![CDATA[Keeping your Mac locked down: a Mac OS X security primer]]></title>
      <link>http://securityratty.com/article/2093c16ff32ee73477c76780d6551b6c</link>
      <guid>http://securityratty.com/article/2093c16ff32ee73477c76780d6551b6c</guid>
      <description><![CDATA[Mac users need to think about security, tooApple's approach to security can be a little bewildering at times. It's a well-trumpeted aspect of the OS, marketed in detail on the website. Mac OS X has...]]></description>
      <content:encoded><![CDATA[Mac users need to think about security, tooApple's approach to security can be a little bewildering at times. It's a well-trumpeted aspect of the OS, marketed in detail on the website. Mac OS X has integrated smartcard support and Apple has certified the OS under the Common Criteria guidelines; a section of Apple's developer site is devoted to th]]></content:encoded>
      <pubDate>Thu, 17 Apr 2008 22:30:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mac users">mac users</category>
      <category domain="http://securityratty.com/tag/common criteria guidelines">common criteria guidelines</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/developer site">developer site</category>
      <category domain="http://securityratty.com/tag/smartcard support">smartcard support</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/aspect">aspect</category>
      <source url="http://digg.com/security/Keeping_your_Mac_locked_down_a_Mac_OS_X_security_primer">Keeping your Mac locked down: a Mac OS X security primer</source>
    </item>
    <item>
      <title><![CDATA[London Tube Smartcard Cracked]]></title>
      <link>http://securityratty.com/article/c48310619266462e0772f7b6319297c4</link>
      <guid>http://securityratty.com/article/c48310619266462e0772f7b6319297c4</guid>
      <description><![CDATA[Looks like lousy cryptography
Details here . When will people learn not to invent their own crypto
Note that this is the same card -- maybe a different version -- that was used in the Dutch transit...]]></description>
      <content:encoded><![CDATA[<p>Looks like <a href="http://www.theregister.co.uk/2008/03/12/mifare_classic_smartcard_crack/">lousy cryptography</a>.</p>

<p>Details <a href="http://www.cs.virginia.edu/~kn5f/Mifare.Cryptanalysis.htm">here</a>. When will people learn not to <a href="http://www.schneier.com/crypto-gram-9904.html#different">invent their own crypto</a>?</p>

<p>Note that this is the same card -- maybe a different version -- that was used in the <a href="http://www.schneier.com/blog/archives/2008/01/dutch_rfid_tran.html">Dutch transit system</a>, and was hacked back in January.  There's <a href="http://www.pcworld.com/article/id,143371-c,privacysecurity/article.html">another hack</a> of that system (press release <a href="http://www2.ru.nl/media/pressrelease.pdf">here</a>, and a <a href="http://www.ru.nl/ds/research/rfid/">video demo</a>), and many companies -- and government agencies -- are scrambling in the wake of all these revelations.</p>

<p>Seems like the Mifare system (especially the version called Mifare Classic -- and there are billions out there) was really badly designed, in all sorts of ways.  I'm sure there are many more serious security vulnerabilities waiting to be discovered.  </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aS8sTiF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aS8sTiF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dQHaQAF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dQHaQAF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 14 Mar 2008 04:27:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/mifare system">mifare system</category>
      <category domain="http://securityratty.com/tag/dutch transit system">dutch transit system</category>
      <category domain="http://securityratty.com/tag/video demo">video demo</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/press release">press release</category>
      <category domain="http://securityratty.com/tag/lousy cryptography">lousy cryptography</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/london_tube_sma.html">London Tube Smartcard Cracked</source>
    </item>
    <item>
      <title><![CDATA[Hacker trio finds a way to crack popular smartcard in minutes ]]></title>
      <link>http://securityratty.com/article/ad09abaa258826282350157e74596740</link>
      <guid>http://securityratty.com/article/ad09abaa258826282350157e74596740</guid>
      <description><![CDATA[Cracking popular wireless smartcard is now a lot easier. A hacker trio has found a low-cost, fast way to decrypt a widely-used, RFID-enabled...]]></description>
      <content:encoded><![CDATA[Cracking popular wireless smartcard is now a lot easier. A hacker trio has found a low-cost, fast way to decrypt a widely-used, RFID-enabled smartcard. ]]></content:encoded>
      <pubDate>Wed, 05 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/smartcard">smartcard</category>
      <category domain="http://securityratty.com/tag/popular wireless smartcard">popular wireless smartcard</category>
      <category domain="http://securityratty.com/tag/hacker trio">hacker trio</category>
      <category domain="http://securityratty.com/tag/lot easier">lot easier</category>
      <category domain="http://securityratty.com/tag/low-cost">low-cost</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/decrypt">decrypt</category>
      <source url="http://www.networkworld.com/news/2008/030608-hacker-cracks-smartcard.html?fsrc=rss-security">Hacker trio finds a way to crack popular smartcard in minutes </source>
    </item>
  </channel>
</rss>
