Most Popular Stories
Events
- Northwestern University Master's in Information Systems
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- 5 Must Haves in your Information Management Strategy
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Is Corporate Liability Robbing YOU Blind?
- Attracting best-in-class clients with best-in-class OCR
- Virtual Game Changer
What's next for Mifare?
![]()
What's next for Mifare?
On Wednesday, a video was released on YouTube demonstrating the successful hack of physical access systems based on the Mifare Classic RFID chip. There were two vectors of attack in the video; the first of them shows the retrieval of the cryptographic key from a reader hooked up to the building's access control infrastructure. The other vector saw the RFID access card being wirelessly sniffed by simply walking past a victim with a handheld scanner. The retrieved data was sufficient to create a clone, which was then used to successfully gain entry.
Detractors say that part of the problem is caused by improper implementations, and that the door reader attack should not have been possible in the first place. Others argue that it is foolhardy not to have implemented additional layers of security.
The second argument ignores the fact that access control systems based on the Mifare work on the assumption that the Mifare cannot be cloned--which is, after all, its key security feature. Hence, a card that is registered with the access control system is assumed to be held by the person it has been assigned to--unless deactivated due to being misplaced or stolen. As such, unless it's a military installation, it does not make economic sense to piggy back a secondary layer of security--and its associated cost, onto an already "secure" system.
As for the first criticism, the fact is that most access control systems based on the Mifare Classic probably are implemented in the same flawed way. Complain as you will, but it's already a done deal. As you can imagine, the hack has thrown much of the world's access control market into disarray. This situation has even prompted the Dutch government to issue a public warning on the matter.
What will happen next? Will companies and organizations that have implemented Mifare Classic obediently upgrade to the just-announced "Mifare Plus"? Or will people simply dump RFID-based access system altogether? If jumping ship, what is there to switch to anyway? Magnetic swipe cards? - Paul
Related Stories
- Anonymous denies hacking Sony; concedes that some members may have done so
- Google explains reason for abandoning H.264 in Chrome
- Microsoft reveals multitouch mouse
- Google releases command line tool for its web services
- Google designing upgrade to Google File System
- SPOTLIGHT: Online video gets down to business
- MTube: The world's smallest PC
- iPhone gets International data/voice plan
- AMD prepping tri-core processors
- Storm Worm dupes YouTube fans
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




