At this month's RFID Security Alliance meeting Mohinder Sikka of Sensitel, Inc. will be providing information about the India Wide Identification system which is being implemented. Q&A session to follow.
This open discussion will be followed by a RFID Security Alliance business meeting.
You are welcome to join us.
Meeting Details:
Thursday, June 10
10:00 a.m. – 11:00 a.m. PST / 1:00 p.m. – 2:00 p.m. EST
To participate:
Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)
Physical Location: QLM Consulting, Sausalito CA
Showing posts with label RFID. Show all posts
Showing posts with label RFID. Show all posts
Wednesday, June 9, 2010
Friday, April 30, 2010
Video: The Use of RFID in Supply Chain Security
Contributed by Joanne C. Kelleher
Last week was the annual INTERPHEX Conference for pharmaceutical manufacturers and packagers. Editors of BioPharm International and Pharmaceutical Technology conducted a series of in-depth conversations with speakers, industry stakeholders and thought leaders.
RFID Security Alliance members Louis Parks, CEO of SecureRF and Bikash Chatterjee, CTO of Pharmatech Associates, along with Anthony Palermo, Director of the RFID Centre of Excellence were interviewed together about the use of RFID in supply chain security.
You can view their interview at http://interphexvideocast.com/media/index.php?vid=Bikash_Anthony_Louis.
All of the interviews conducted at INTERPHEX are at http://interphexvideocast.com/
Last week was the annual INTERPHEX Conference for pharmaceutical manufacturers and packagers. Editors of BioPharm International and Pharmaceutical Technology conducted a series of in-depth conversations with speakers, industry stakeholders and thought leaders.
RFID Security Alliance members Louis Parks, CEO of SecureRF and Bikash Chatterjee, CTO of Pharmatech Associates, along with Anthony Palermo, Director of the RFID Centre of Excellence were interviewed together about the use of RFID in supply chain security.
You can view their interview at http://interphexvideocast.com/media/index.php?vid=Bikash_Anthony_Louis.
All of the interviews conducted at INTERPHEX are at http://interphexvideocast.com/
Labels:
INTERPHEX,
pharmaceutical,
RFID,
RFID security
Friday, April 9, 2010
RFIDSA at RFID Journal LIVE 2010
RFID Journal LIVE 2010 is next week, April 14-16 in Orlando, FL.
Michael McCartney, RFID Security Alliance's chairperson, will be speaking in the RFID for IT Professionals track. His talk, titled RFID Security: Potential Threats, Their Impact and Solutions, will be presented on 4/14 at 11:30 am.
If you are going to this conference, please attend this session and introduce yourself to Michael.
Michael McCartney, RFID Security Alliance's chairperson, will be speaking in the RFID for IT Professionals track. His talk, titled RFID Security: Potential Threats, Their Impact and Solutions, will be presented on 4/14 at 11:30 am.
If you are going to this conference, please attend this session and introduce yourself to Michael.
Labels:
RFID,
RFID Journal,
RFID security
Friday, March 26, 2010
Notes on InterTraffic Conference
RFIDSA's Vice Chairperson, Neil Mitchell, shared his insights about the InterTraffic Conference.
---------------
InterTraffic was held over 4 days this month from March 23rd – 26th in Amsterdam. The show runs every 2 years and has considerably expanded from the show 2 years ago (having almost tripled in size!). It is a broad based traffic event and not solely focused on RFID or security technologies. While some portions of the show are not relevant to MIKOH and the RFID Security Alliance there are significant key parts that are.
ITS (Intelligent Traffic Systems) and Cooperative Systems which are highly relevant took up 1/3 of the show and Safety and Infrastructure that had parts that were relevant and parts that were not took up another 1/3 of the show.
Attendance was mostly European but there were significant attendance from beyond including North and South America, Asia (including Russia and China), and Australia.
Major themes from the show were:
• Increased use of video based vehicle tracking (free flow, parking, security etc). Note: Clearly video based tracking has hugely varying read rates from 65%-95%) and if to be used as a revenue generating activity is often used in addition to a technology such as RFID to fill that significant gap (unless in a more controlled environment such as parking).
• Vehicle networking and traffic management using vehicle-to-vehicle communication (of information such as speed, time, GPS location etc). There was actually a live demo around Amsterdam of this technology. RFID tags on vehicles can be part of this solution but is likely to be used only if employed for other reasons beyond just this.
While the theme of security was present, it was mostly from the point of view of vehicle security (high level tracking and monitoring) and less so the detailed issues relating to tag security.
The show was generally, highly relevant for anyone involved in Automatic Vehicle Identification (e.g. Electronic Vehicle Registration, tolling, parking etc) and a very good meeting place for customers, partners and relevant industry bodies.
---------------
InterTraffic was held over 4 days this month from March 23rd – 26th in Amsterdam. The show runs every 2 years and has considerably expanded from the show 2 years ago (having almost tripled in size!). It is a broad based traffic event and not solely focused on RFID or security technologies. While some portions of the show are not relevant to MIKOH and the RFID Security Alliance there are significant key parts that are.
ITS (Intelligent Traffic Systems) and Cooperative Systems which are highly relevant took up 1/3 of the show and Safety and Infrastructure that had parts that were relevant and parts that were not took up another 1/3 of the show.
Attendance was mostly European but there were significant attendance from beyond including North and South America, Asia (including Russia and China), and Australia.
Major themes from the show were:
• Increased use of video based vehicle tracking (free flow, parking, security etc). Note: Clearly video based tracking has hugely varying read rates from 65%-95%) and if to be used as a revenue generating activity is often used in addition to a technology such as RFID to fill that significant gap (unless in a more controlled environment such as parking).
• Vehicle networking and traffic management using vehicle-to-vehicle communication (of information such as speed, time, GPS location etc). There was actually a live demo around Amsterdam of this technology. RFID tags on vehicles can be part of this solution but is likely to be used only if employed for other reasons beyond just this.
While the theme of security was present, it was mostly from the point of view of vehicle security (high level tracking and monitoring) and less so the detailed issues relating to tag security.
The show was generally, highly relevant for anyone involved in Automatic Vehicle Identification (e.g. Electronic Vehicle Registration, tolling, parking etc) and a very good meeting place for customers, partners and relevant industry bodies.
Labels:
Automatic Vehicle Identification,
AVI,
RFID
Thursday, January 7, 2010
Karsten Nohl to Discuss Hacking Mifare and other 'secure' RFID on 1/13/2010
The RFID Security Alliance has changed the format of their monthly meetings and will now start with a discussion of a topic of interest. On January 13, 2010 researcher Karsten Nohl will mark the 25th anniversary month of declaring Mifare insecure by leading a discussion about Mifare and several other types of 'secure' RFID which have been broken in the meantime (HID, Legic).
Questions to be covered include:
The meetings can be joined in person in California or via conference call. If you want to participate in next week's call (Wednesday, 1/13) on this topic, you are welcome to join us at 10 AM PST / 1PM EST. After this discussion and an open Q&A you can stay on the call for RFIDSA internal business topics if you wish.
Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)
RFID Security Alliance meetings are usually scheduled for the second Wednesday of each month at 10 AM PST / 1PM EST. More info about the RFID Security Alliance is at http://www.rfidsa.com/ or via the LinkedIn Group at http://www.linkedin.com/groups?gid=62849.
Questions to be covered include:
- How have the hacks on the Mifare transit cards impacted new projects?
- How have existing systems been protected?
- What is status of Mifare Plus?
- How have other systems been broken?
Karsten bridges the three worlds of academic research, hacking, and industry. His academic research with the University of Virginia focuses on privacy protection in large networks. His hacking projects-- at H4RDW4RE in the Silicon Valley or with the CCC in Berlin--assess (and usually break) proprietary cryptography. Finally, his consulting job at McKinsey helps him understand why corporations often choose technically inferior solutions.
Dial in Phone Number: 218.936.7999
Access code: 413685# (Follow the prompts)
RFID Security Alliance meetings are usually scheduled for the second Wednesday of each month at 10 AM PST / 1PM EST. More info about the RFID Security Alliance is at http://www.rfidsa.com/ or via the LinkedIn Group at http://www.linkedin.com/groups?gid=62849.
Contributed by Joanne C. Kelleher
RFIDSA Marketing Committee
Tuesday, December 22, 2009
RFID Readers May Become Ubiquitous
During December’s RFID Security Alliance call, there was an open discussion on the effects of RFID readers becoming ubiquitous. This frank and useful discussion posed the following questions:
What will happen when RFID Readers become embedded in common every day devices that a non-expert can use?
One examples of RFID readers becoming embedded in a common device is with the Smart Phone that many of us own today. Such speculation is not baseless and while limited to the rumor mill at this point, it seems likely that some consumer devices will start to incorporate such reader technologies in the near future. How do we know this?
On the speculative side, the rumor mills are filled with suggestions that next generation Apple iPhone may include such technology:
http://www.appleinsider.com/articles/09/11/05/report_apple_testing_rfid_swipe_support_in_iphone_prototypes.html
http://www.tuaw.com/2009/04/15/iphone-rfid-prototype-is-very-cool/
On the more fact-based side, we know that NXP semiconductors and others are developing combo chips that combine Cell Phone and RFID technology into single devices. While this does not mean a product will certainly be on the market with this functionality, it seems a high probability.
How might such multi-function devices be used?
There could be many uses. Speculating a little, one rational would be to incorporate such RFID reading capability with bar code and other sensors to allow a device to read a product ID (and other information). This would then be used to locate information about the product (through the internet via the cell phone connection), possibly including price at varying local stores as well as a combination of other on-line retailers. Why? To enable a purchase from a different location than the one were you scanned the item. Motivation for purchasing elsewhere includes price, offering a value added purchase, offering related products and their improved availability or other factors (service, support etc). The goal would be to take a small service fee for the pleasure.
Another possible usage is to turn the iPhone into a ‘digital wallet” with RFID.
http://www.9to5mac.com/node/11939
What will happen when RFID Readers are available to such users?
Phones are regularly hacked (e.g. “Jailbreaking” iPhone) or increasingly targeted for unscrupulous activities (e.g. identity theft etc). It will be no different with RFID reader enabled devices and the system and tags in question. One member suggested that applications that have value will be the first ones hacked and then hackers will pick on applications that will be fun to break or for bragging rights.
The RFID Security Alliance is looking carefully at such concerns and has decided to pull together a “Best Practices” white paper to address these concerns. Any solution must address the full spectrum of threats, RF security, physical tag security, reader security etc.
Contributed by Neil Mitchell, RFIDSA Vice Chair
What will happen when RFID Readers become embedded in common every day devices that a non-expert can use?
One examples of RFID readers becoming embedded in a common device is with the Smart Phone that many of us own today. Such speculation is not baseless and while limited to the rumor mill at this point, it seems likely that some consumer devices will start to incorporate such reader technologies in the near future. How do we know this?
On the speculative side, the rumor mills are filled with suggestions that next generation Apple iPhone may include such technology:
http://www.appleinsider.com/articles/09/11/05/report_apple_testing_rfid_swipe_support_in_iphone_prototypes.html
http://www.tuaw.com/2009/04/15/iphone-rfid-prototype-is-very-cool/
On the more fact-based side, we know that NXP semiconductors and others are developing combo chips that combine Cell Phone and RFID technology into single devices. While this does not mean a product will certainly be on the market with this functionality, it seems a high probability.
How might such multi-function devices be used?
There could be many uses. Speculating a little, one rational would be to incorporate such RFID reading capability with bar code and other sensors to allow a device to read a product ID (and other information). This would then be used to locate information about the product (through the internet via the cell phone connection), possibly including price at varying local stores as well as a combination of other on-line retailers. Why? To enable a purchase from a different location than the one were you scanned the item. Motivation for purchasing elsewhere includes price, offering a value added purchase, offering related products and their improved availability or other factors (service, support etc). The goal would be to take a small service fee for the pleasure.
Another possible usage is to turn the iPhone into a ‘digital wallet” with RFID.
http://www.9to5mac.com/node/11939
What will happen when RFID Readers are available to such users?
Phones are regularly hacked (e.g. “Jailbreaking” iPhone) or increasingly targeted for unscrupulous activities (e.g. identity theft etc). It will be no different with RFID reader enabled devices and the system and tags in question. One member suggested that applications that have value will be the first ones hacked and then hackers will pick on applications that will be fun to break or for bragging rights.
The RFID Security Alliance is looking carefully at such concerns and has decided to pull together a “Best Practices” white paper to address these concerns. Any solution must address the full spectrum of threats, RF security, physical tag security, reader security etc.
Contributed by Neil Mitchell, RFIDSA Vice Chair
Wednesday, November 18, 2009
Speaking Opportunity in Singapore
Hello RFIDSA members,
I received an email today that the Pharmas & Biotech Supply Chain Asia 2010 conference has an open call for speakers. This conference is being held on March 17-18, 2010 in Singapore. http://www.terrapinn.com/2010/pharmascm/index.stm
The invitation said:
"Pharmas & Biotech Supply Chain Asia 2010 will address:
- Import & export regulatory compliance
- Clinical Supply Chain
- Cold chain management and supply
- Achieving Drug Safety across the entire supply chain
- Protecting Inbound Supply Chain Through Stringent Suppliers Qualification
- Managing your logistics and distribution in Asian context
- Strategising the right demand forecasting strategy to ensure speed to market and product availability
- The essential data management technologies to drive supply chain visibility and security
- Manufacturers-Suppliers- Vendors Relationship Management: Collaborating with varies supply chain stakeholders to increase supply chain visbility and integration
- Establishing good supply chain practice in challenging market - India And China
- Packaging and labelling strategies to ensure regulatory compliance and product safety
We are now looking for industry leaders to share their expertise, experience and strategies on the above mentioned topics. Do you have an interesting case study to share? Interested to speak at the event?
Contact Stella Teo at +65 6322 2737 or email stella.teo@terrapinn.com to discuss your speaking opportunity at Pharma & Biotech Supply Chain Asia now!"
I don't know anything else about this event and it sounds like a "sponsored" speaking opportunity (i.e. you have to pay), but I thought I would pass it along in case anyone was interested.
Joanne Kelleher
SecureRF Corporation
RFID Security Alliance Marketing Committee
I received an email today that the Pharmas & Biotech Supply Chain Asia 2010 conference has an open call for speakers. This conference is being held on March 17-18, 2010 in Singapore. http://www.terrapinn.com/2010/pharmascm/index.stm
The invitation said:
"Pharmas & Biotech Supply Chain Asia 2010 will address:
- Import & export regulatory compliance
- Clinical Supply Chain
- Cold chain management and supply
- Achieving Drug Safety across the entire supply chain
- Protecting Inbound Supply Chain Through Stringent Suppliers Qualification
- Managing your logistics and distribution in Asian context
- Strategising the right demand forecasting strategy to ensure speed to market and product availability
- The essential data management technologies to drive supply chain visibility and security
- Manufacturers-Suppliers- Vendors Relationship Management: Collaborating with varies supply chain stakeholders to increase supply chain visbility and integration
- Establishing good supply chain practice in challenging market - India And China
- Packaging and labelling strategies to ensure regulatory compliance and product safety
We are now looking for industry leaders to share their expertise, experience and strategies on the above mentioned topics. Do you have an interesting case study to share? Interested to speak at the event?
Contact Stella Teo at +65 6322 2737 or email stella.teo@terrapinn.com to discuss your speaking opportunity at Pharma & Biotech Supply Chain Asia now!"
I don't know anything else about this event and it sounds like a "sponsored" speaking opportunity (i.e. you have to pay), but I thought I would pass it along in case anyone was interested.
Joanne Kelleher
SecureRF Corporation
RFID Security Alliance Marketing Committee
Friday, July 17, 2009
Reporters: Unsure of the RFID Security Facts? Contact the RFIDSA.
Contributed by Joanne C. Kelleher
Earlier this week one of my co-workers sent me a link with the comment “No surprise, but this kind of guy really irritate me.” The article, Chips in official IDs raise privacy fears by AP National Writer, Todd Lewan appeared in several places including http://news.yahoo.com/s/ap/20090711/ap_on_bi_ge/us_chipping_america_iv. It also triggered follow up articles such as Robin Harris’ blog post on ZDnet entitled RFID passports: a tragedy waiting to happen.
I was planning to post about how much of the content was old news or technically incorrect. For example, Harris mixed up Pass Cards and Passports which use different RFID protocols and have different security features. But Mark Roberti, editor of RFID Journal, beat me to it so I am going to refer you to his postings -AP Hack Strikes Again and Another Blogger Confuses the RFID Issue.
If any reporters wish to write about RFID security issues in the future, please contact the RFID Security Alliance and we can refer you to people who can accurately talk about the topic.
Earlier this week one of my co-workers sent me a link with the comment “No surprise, but this kind of guy really irritate me.” The article, Chips in official IDs raise privacy fears by AP National Writer, Todd Lewan appeared in several places including http://news.yahoo.com/s/ap/20090711/ap_on_bi_ge/us_chipping_america_iv. It also triggered follow up articles such as Robin Harris’ blog post on ZDnet entitled RFID passports: a tragedy waiting to happen.
I was planning to post about how much of the content was old news or technically incorrect. For example, Harris mixed up Pass Cards and Passports which use different RFID protocols and have different security features. But Mark Roberti, editor of RFID Journal, beat me to it so I am going to refer you to his postings -AP Hack Strikes Again and Another Blogger Confuses the RFID Issue.
If any reporters wish to write about RFID security issues in the future, please contact the RFID Security Alliance and we can refer you to people who can accurately talk about the topic.
Labels:
Passports,
RFID,
RFID Journal,
RFID security
Tuesday, May 12, 2009
RFID Privacy and Data Protection Principles
Contributed by Joanne C. Kelleher
The Commission of The European Communities issued a recommendation today “on the implementation of privacy and data protection principles in applications supported by radio-frequency identification.”
Their “recommendation provides guidance to Member States on the design and operation of RFID applications in a lawful, ethical and socially and politically acceptable way, respecting the right to privacy and ensuring protection of personal data.”
Here is a summary of the recommendations:
I also found several of the Commission’s reasons behind these recommendations (the “whereas” clauses in the beginning of the document) to be right on target:
6.) Because of its potential to be both ubiquitous and practically invisible, particular attention to privacy and data protection issues is required in the deployment of RFID. Consequently, privacy and information security features should be built into RFID applications before their widespread use (principle of ‘security and privacy-bydesign’).
13.) RFID application operators should take all reasonable steps to ensure that data does not relate to an identified or identifiable natural person through any means likely to be used by either the RFID application operator or any other person, unless such data is processed in compliance with the applicable principles and legal rules on data protection.
19.) An assessment of the privacy and data protection impacts carried by the operator prior to the implementation of an RFID application will provide the information required for appropriate protective measures. Such measures will need to be monitored and reviewed throughout the lifetime of the RFID application.
22.) RFID applications with implications for the general public, such as electronic ticketing in public transport, require appropriate protective measures. RFID applications that affect individuals by processing, for example, biometric identification data or health related data, are especially critical with regard to information security and privacy and therefore require specific attention.
26.) Research and development on low-cost privacy-enhancing technologies and information security technologies is essential at Community level to promote a wider take-up of these technologies under acceptable conditions.
A full copy of the document, issued May 12, 2009, is at http://ec.europa.eu/information_society/policy/rfid/documents/recommendationonrfid2009.pdf. Also check out their RFID page at http://ec.europa.eu/information_society/policy/rfid/index_en.htm.
The Commission of The European Communities issued a recommendation today “on the implementation of privacy and data protection principles in applications supported by radio-frequency identification.”
Their “recommendation provides guidance to Member States on the design and operation of RFID applications in a lawful, ethical and socially and politically acceptable way, respecting the right to privacy and ensuring protection of personal data.”
Here is a summary of the recommendations:
- Develops a framework for privacy and data protection impact assessments
- Identify those applications that might raise information security threats then develop new schemes, or apply existing schemes, in order to demonstrate that an appropriate level of information security and protection of privacy is established in relation to the assessed risks.
- Develop and publish a concise, accurate and easy to understand information policy for each RFID application and inform individuals of the presence of RFID readers for the application.
- Inform individuals of the presence of RFID tags that are placed on or embedded in products in the retail trade, determine whether tags placed on or embedded in products sold to consumers through retailers by others represent a likely threat to privacy or the protection of personal data and deactivate or remove at the point of sale tags used in their application.
- Take appropriate measures to inform and raise awareness among public authorities and companies of the potential benefits and risks associated with the use of RFID technology, especially information security and privacy aspects.
- Stimulate and support the introduction of the ‘security and privacy by design’ principle at an early stage in the development of RFID applications.
I also found several of the Commission’s reasons behind these recommendations (the “whereas” clauses in the beginning of the document) to be right on target:
6.) Because of its potential to be both ubiquitous and practically invisible, particular attention to privacy and data protection issues is required in the deployment of RFID. Consequently, privacy and information security features should be built into RFID applications before their widespread use (principle of ‘security and privacy-bydesign’).
13.) RFID application operators should take all reasonable steps to ensure that data does not relate to an identified or identifiable natural person through any means likely to be used by either the RFID application operator or any other person, unless such data is processed in compliance with the applicable principles and legal rules on data protection.
19.) An assessment of the privacy and data protection impacts carried by the operator prior to the implementation of an RFID application will provide the information required for appropriate protective measures. Such measures will need to be monitored and reviewed throughout the lifetime of the RFID application.
22.) RFID applications with implications for the general public, such as electronic ticketing in public transport, require appropriate protective measures. RFID applications that affect individuals by processing, for example, biometric identification data or health related data, are especially critical with regard to information security and privacy and therefore require specific attention.
26.) Research and development on low-cost privacy-enhancing technologies and information security technologies is essential at Community level to promote a wider take-up of these technologies under acceptable conditions.
A full copy of the document, issued May 12, 2009, is at http://ec.europa.eu/information_society/policy/rfid/documents/recommendationonrfid2009.pdf. Also check out their RFID page at http://ec.europa.eu/information_society/policy/rfid/index_en.htm.
Labels:
RFID,
RFID privacy,
RFID security
Thursday, April 16, 2009
Welcome to a New Security Alliance
Contributed by Joanne C. Kelleher
A new organization, the Cloud Security Alliance is being launched next week at the RSA Conference. They plan to provide security advice to companies adopting cloud computing products.
SearchSecurity.com has an opinion piece about the challenges the new Cloud Security Alliance (CSA) will face and the RFIDSA gets a mention. The CSA is tackling 15 "Domains of Concern" and several of these items overlap with issues we face with RFID.
-------------------------------------------------------------
Cloud computing group to face challenges ahead
By Eric Ogren at SearchSecurity.com
15 Apr 2009
-snip-
"This is not the first, nor will it be the last, security alliance that was formed to get ahead of security issues that may stunt the growth of enticing new technologies. A search on "security alliances" will quickly uncover similar organizations including the Internet Security Alliance, Voice over IP Security Alliance, Document Security Alliance and Radio Frequency Identification (RFID) Security Alliance. Security practitioners are well-schooled in talking about potential security pitfalls in new technologies and in making best practices recommendations."
-snip-
Read the full piece at http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1353872,00.html#
A new organization, the Cloud Security Alliance is being launched next week at the RSA Conference. They plan to provide security advice to companies adopting cloud computing products.
SearchSecurity.com has an opinion piece about the challenges the new Cloud Security Alliance (CSA) will face and the RFIDSA gets a mention. The CSA is tackling 15 "Domains of Concern" and several of these items overlap with issues we face with RFID.
-------------------------------------------------------------
Cloud computing group to face challenges ahead
By Eric Ogren at SearchSecurity.com
15 Apr 2009
-snip-
"This is not the first, nor will it be the last, security alliance that was formed to get ahead of security issues that may stunt the growth of enticing new technologies. A search on "security alliances" will quickly uncover similar organizations including the Internet Security Alliance, Voice over IP Security Alliance, Document Security Alliance and Radio Frequency Identification (RFID) Security Alliance. Security practitioners are well-schooled in talking about potential security pitfalls in new technologies and in making best practices recommendations."
-snip-
Read the full piece at http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1353872,00.html#
Friday, April 3, 2009
Help Present a Balanced View of RFID Security
Bert Moore, Editor of AIM Global’s RFID Connections, discusses RFID security and privacy in his April 1, 2009 column titled RFID: Legislative Action.
The RFID Security Alliance invites vendors and end users interested in this issue to join our organization.
Burt also goes on to announce the availability of a new technical report from the International Organization of Standards (ISO) which was based on the work of AIM Global. Publication ISO/IEC TR24729-4, Information technology - Radio frequency identification for item management - Implementation guidelines - Part 4: Tag data security is available for purchase from the AIM Global website.
I was pleased to see that this report “offers sufficient guidance to enable users or developers to assess potential risks and determine appropriate techniques to mitigate these risks.” The RFID Security Alliance encourages users and implementers to completing a risk assessment of potential RFID systems.
"At some recent legislative hearings on whether to limit, regulate or restrict RFID in some way, advocates of RFID finally began to get their views heard. Why? Because many of the advocates weren't companies manufacturing or selling RFID, they were companies and agencies actively using the technology. They were able to point out to state legislators how the technology was actively benefitting citizens of the state. And their real world experiences helped put to rest some of the more outlandish claims of some privacy advocates.
At the same time, there are new concerns that some companies and governmental agencies are implementing RFID technology without giving adequate attention to the need for security and, therefore, privacy. Concerns about covert reading of ID cards and similar items must be addressed because they highlight real or potential system vulnerabilities that expose not only individuals but the entire system to unnecessary risk.
It is up to those in the RFID community -- both vendors and end users -- to be heard in legislative hearings and community forums in order to present a balanced view of the technology and point to ways in which it can be implemented securely so that it can continue to provide benefits while protecting the integrity of the system and personal privacy."
The RFID Security Alliance invites vendors and end users interested in this issue to join our organization.
Burt also goes on to announce the availability of a new technical report from the International Organization of Standards (ISO) which was based on the work of AIM Global. Publication ISO/IEC TR24729-4, Information technology - Radio frequency identification for item management - Implementation guidelines - Part 4: Tag data security is available for purchase from the AIM Global website.
I was pleased to see that this report “offers sufficient guidance to enable users or developers to assess potential risks and determine appropriate techniques to mitigate these risks.” The RFID Security Alliance encourages users and implementers to completing a risk assessment of potential RFID systems.
Labels:
AIM Global,
RFID,
RFID security,
security
Wednesday, August 6, 2008
Karsten Nohl Discusses RFID Insecurities
Karsten Nohl, the security researcher who was part of a team that broke the crypto algorithm in the Mifare Classic RFID-based smart card, talks about his upcoming briefing at Black Hat in Las Vegas in an interview with Security Wire Weekly called Wireless Insecurities.
Nohl, a University of Virgina graduate student, has been active with the RFID Security Alliance and presented a threat model for Mifare at our May meeting. Hear his interview at http://securitywireweekly.blogs.techtarget.com/2008/08/01/sww-wireless-insecurities/
Nohl, a University of Virgina graduate student, has been active with the RFID Security Alliance and presented a threat model for Mifare at our May meeting. Hear his interview at http://securitywireweekly.blogs.techtarget.com/2008/08/01/sww-wireless-insecurities/
Subscribe to:
Posts (Atom)