Electronic Frontier Foundation
EFF is the leading civil liberties group defending
your rights in the digital world. » About Us
  • Home
  • About
  • Our Work
  • Deeplinks Blog
  • Press Room
  • Take Action
  • Shop
Home » Deeplinks Blog » February, 2009
  • Deeplinks Archives
    • October, 2011
    • September, 2011
    • August, 2011
    • July, 2011
    • June, 2011
    • May, 2011
    • April, 2011
    • March, 2011
    • More Archives
  • Blog Categories
    • Accessibility for the Reading Disabled
    • Analog Hole
    • Announcement
    • Anonymity
    • Anti-Counterfeiting Trade Agreement
    • Bloggers' Rights
    • Broadcast Flag
    • Broadcasting Treaty
    • CALEA
    • Call To Action
    • CDA 230
    • Cell Tracking
    • Coders' Rights Project
    • Commentary
    • Copyright Trolls
    • Council of Europe
    • Criminalizing Content
    • Development Agenda
    • Digital Books
    • Digital Radio
    • Digital Rights Management
    • Digital Video
    • DMCA
    • DMCA Rulemaking
    • Do Not Track
    • E-Voting Rights
    • EFF Europe
    • EFF15
    • File Sharing
    • FOIA Litigation for Accountable Government
    • Free Speech
    • Free Trade Agreement of the Americas
    • Hollywood v. DVD
    • Innovation
    • Intellectual Property
    • International
    • International Privacy Standards
    • Legal Analysis
    • Legislative Analysis
    • Locational Privacy
    • Mandatory Data Retention
    • miniLinks
    • National Security Letters
    • Net Neutrality
    • News Roundup
    • News Update
    • No Downtime for Free Speech Campaign
    • NSA Spying
    • Online Behavioral Tracking
    • Patents
    • PATRIOT Act
    • Pen Trap
    • Printers
    • Privacy
    • Real ID
    • RFID
    • Search Engines
    • Search Incident to Arrest
    • Security
    • Social Networks
    • Technical Analysis
    • Terms Of (Ab)Use
    • Test Your ISP
    • The COICA Internet Censorship and Copyright Bill
    • The Global Network Initiative
    • Transparency
    • Travel Screening
    • Trusted Computing
    • Video Games
    • Wikileaks
    • WIPO
February 5th, 2009
Email This Digg This Post this to Reddit Share this blog post with delicious Share this on Facebook Tweet this blog post Dent this blog post

RFID PASScards Easily Cloned

Commentary by Hugh D'Andrade

On a recent afternoon, security researcher Chris Paget was able to capture the passport card information of several unsuspecting individuals while driving through San Francisco, using a device he built in his spare time for a total of $250. A video released by Paget shows just how easy it is to clone RFID (Radio Frequency ID) tags with this relatively simple technology.

The tags he captured are part of a new generation of ID cards that come with embedded RFID microchips. These vulnerable IDs include PASScards, new mini-passports the size of a credit card which are designed for non-air travel between the US, Canada, Mexico and the Caribbean. They also include the Enhanced Drivers' Licenses (EDLs) issued by New York, Michigan and Washington states. These cards use the same type of simple RFID tags used in shipping and pallet tracking, which allows them to be read from a distance of tens of feet under normal conditions — and UW researchers demonstrated 50 meters in some situations.

Paget's work confirms a study released by RSA Labs and the University of Washington last year which found that RFID tags in PASScards and EDLs were vulnerable to remote capture using widely available tools. That study pointed out while the vulnerable information is only a unique number — not a name or passport number — there is still a reasonable threat to privacy since the tags can enable location tracking, could eventually be linked to individuals, and could also be cloned into fake IDs, making identity theft easier. (The RFID tags embedded in passport books issued by the US government are somewhat more secure, with a shorter range and some cryptographic protections.)

The same factors that make radio great for broadcasting — radio waves travel through many materials to many receivers — make it inappropriate for sensitive information, including unique ID numbers. A person carrying an unprotected RFID passport card or other ID may be broadcasting personal information or a tracking number to anyone with the right reader.

You can catch Paget presenting his findings at the upcoming ShmooCon in Washington DC this Sunday.

Update: View Chris Paget's ShmooCon presentation here.

Related Issues: RFID

[Permalink]

Donate to EFF
Make a One-Time Contribution
Join EFF
Become a Member

Subscribe to EFFector

EFF's Newsletter and Action Alerts

Headlines

  • Victory for Reader Privacy
  • The Humble Frozen Synapse Bundle
  • Don't Let Privacy Law Get Stuck in 1986
  • Open Source Security
  • 2011 Pioneer Awards!

Projects

  • Bloggers' Rights
  • Coders' Rights
  • FOIA Project
  • Follow EFF
  • Patent Busting
  • Surveillance Self-Defense
  • Teaching Copyright
  • Takedown Hall of Shame
  • TOSBack
  • Ways To Help
Want to learn how you can defend free speech, stand up for privacy, fight for government transparency, support consumer rights, and protect your right to innovation in the digital world? Visit http://eff.org/fight to find ways to help.
Creative Commons Licensed
  • Thanks
  • RSS Feeds
  • Copyright Policy
  • Privacy Policy
  • Contact EFF