Mark Roberti, owner of the popular RFID Journal (http://www.rfidjournal.com) recently posted a small piece on the RFID Journal Blog where he admonished Greg Day, an analyst for security company McAfee, for comments he made regarding the security issues surrounding contactless payments. While I feel Mr. Roberti has every right to express his opinion of Mr. Day, I was a bit disappointed in a comment he made which I felt characterized security experts as fear mongers:
"So security experts can try to scare people, but the truth is, consumers don't appear to have much to be concerned about at this point. "
I sent an the following email to Mr. Roberti:
Mark,
I read the article titled "Yes, Contactless Payments Are Safe" and found the final line more than a little alarming:
"So security experts can try to scare people, but the truth is, consumers don't appear to have much to be concerned about at this point."
While there are many instances we all can point to where scare tactics are used to promote agendas, not all security experts are trying to scare people. In fact, one of the basic tenants of the RFID Security Alliance is to avoid using scare tactics, and carefully presenting information as factually as possible and fostering a collaborative environment to discuss the issues surrounding RFID and security.
As a security expert, there are several points in the article that I would like to discuss. For example, the point of OTA dynamic security patches. Many systems designed to be managed in this manner are fraught with security issues. The iPhone, for example, has had many security patches applied to it in a similar manner (not OTA, but through a downloaded update), and is generally hacked again within 24-48 hours. OTA management systems, once breached, can become a means of mass hacking from literally thousands of miles away. I would love to discuss a threat model about this issue.
Security experts are not here merely to generate Fear, Uncertainty, and Doubt. Believe it or not, many of us truly care about being ethical and shy away from scaring people. Many security problems are caused by fear mongering, because people tend to make rash decisions out of fear, and that is rarely the best decision. Consumers do indeed have much to be concerned with, and security experts are working hard (around the clock) to address and FIX the problems. That is the true measure of our success. Please reconsider the tone of this article. RFID Journal is arguably the most prominent RFID publication in this nation. What you say carries a lot of weight, and the tone of this article may serve to alienate many stakeholders who are indeed concerned with creating secure RFID solutions.
Please consider attending a meeting of the RFID Security Alliance. I have invited you several times. Your presence would be welcomed.
Thank You,
Mike Ahmadi
Mr. Roberti graciously replied:
Mike,
It's interesting that you are alarmed by my comment about security experts and not alarmed by the original article in which Greg Day says that this is a huge threat to consumers. It's okay for Day to say something that is extremely detrimental to the NFC industry, but it's not okay for me to be critical of security experts?
If the Alliance has credibility, it should come out and condemn Day an his irresponsible comments and then set the record straight. I'm sure not all security experts are trying to scare people, but I frankly haven't seen a lot of evidence of that. Comment's like Day's are far more common.
Having said that, I'm interested in open and honest discussion of the issues. I suggest you post your comments about OTA on the blog page for others to read. I'm sure many readers will be interested.
Mark
My response:
Mark,
Thank you very much for your quick response. It is certainly okay for you to voice your opinion on any topic. I truly believe that is what makes the internet fantastic. My point is that you carry quite a bit of weight in what you say. I would like to posit that more people in the RFID industry are familiar with Mark Roberti than they are with Greg Day.
That being said, I do not feel the credibility of the RFID Security Alliance hinges on the condemnation of anyone. We are not here to admonish anyone. We are trying to foster open discussions of security issue surrounding the secure implementation of RFID systems. That is why the RFIDSA is open to all who wish to attend.
As for the comments Greg Day made in the article you mention, I could not find it through the link on your blog, but I did find the Reuter's article at the Reuter's site:
http://uk.reuters.com/articlePrint?articleId=UKNOA94822420080519
While I understand how many in the NFC industry may be concerned by some of Day's comments, I am curious as to why you feel his comments are any more or less irresponsible than making the blanket statement that Contactless Payments Are Safe. Once again, your words carry a lot of weight, and such statements should be carefully considered.
Is there any way we can perhaps foster more of an environment where the RFIDSA can work together with RFID Journal to deliver the message in a better way. I can understand your viewpoint about security experts being alarmist, but there are many of us that choose not to take that stance, and would like to foster a more cooperative environment. Your support can go a long way to creating an environment where we ALL achieve the credibility we would like to have.
Sincerely,
Mike Ahmadi
Mr. Roberti's response:
Mike, Here why I feel my comments are not irresponsible and his are. First, McAfee is a company that is well know and carries a great deal of weight with consumers. The article was published by Reuters, a news agency picked up by hundreds, maybe thousands, of newspapers around the world. It had the potential to influence millions of consumers, and yet Day provided no evidence or reasons for claiming NFC phones are such a huge threat. He said only that criminals will steal in small increments. He doesn’t explain what the security flaws are or why they can’t be addressed by the NFC industry. Reuters was equally irresponsible for not having an NFC person respond in the article.My blanket statement was not irresponsible because my statement is demonstrably true. Even if a hacker steels information stored on your NFC phone and makes a fraudulent purchase, you are not any more responsible for that purchase than you would be if the waiter you gave your card to last night used it to buy something. Also, to my knowledge, there has not been a single case where an NFC device being abused. Further, one would have to be insane to believe that the makers of phones and NFC chips will not continue to enhance the technology in an effort to make it safer.You may believe that my statement is inaccurate. But I think you would be hard pressed to say that I did not try to support it with the facts as I know them, as opposed to Day who does not support his argument. I recognize that I don’t know everything, so if you believe my statement to be wrong, then I would welcome you to publish an article on RFID Journal to say why. I have credibility because I am willing to criticize those in my industry who would not respect people’s privacy and because I am willing to publish views that are contrary and/or critical of my own. Not only am I willing, I believe it is essential to the RFID industry to do so. So I’m more than willing to work with any party to enlighten and inform the public and the RFID industry about potential problems.
mark
Mr. Roberti then posted a new entry:
Fairness
Yes, it is true that consumers have much to be concerned about and it is true that the cost of NFC fraud would be passed on to them. It's equally true that when credit card numbers are stolen from databases and when mag stripe cards are cloned, consumers pay the price for that too. I was wrong to generalize. All security experts aren't trying to scare people. But Day's comments were grossly irresponsible and potentially very damaging to the NFC industry and to consumers who could benefit from the technology should it take off.
I wish to thank Mr. Roberti for clarification of his statement, and wish to once again invite him to attend a meeting of the RFID Security Alliance. As of this date, all my requests to Mr. Roberti to attend a meeting have gone unanswered.
I am sure Mr. Roberti is a very busy person. He should, however, consider working directly with security experts in order to avoid such misunderstandings in the future.
Just my opinion, so take it or leave it!
Monday, June 30, 2008
Tuesday, May 20, 2008
ABI Research Response
I contacted the authors of the ABI Research Article mentioned in the previous post. Both Mr. Collins and Mr. Liard graciously accepted my LinkedIn invitation, and I used the messaging system to send them both a message. Here is a what I wrote:
Your recent paper titled "Developing a Corporate Plan for RFID Adoption: Enterprise RFID Blueprint and Program Management Considerations" fails to address security issues surrounding RFID. Was this intentional. We discussed this at the RFID Security Alliance, and find it a bit alarming that ABI Research, a trusted research firm, is failing to address this. Can you please expain?
Both Mr. Collins and Mr. Liard replied. Mr. Collins told me he would forward my inquiry to Mr. Liard, and Mr. Liard sent me this response:
Thanks for your interest and comments, Mike. The ABI Research RFID & Contactless team appreciates your feedback. The reason that security was not mentioned explicitly in the article is simply because it was a short, focused piece and the focus was not security. As a security specialist we can understand how you would be eager for the topic to be explicitly included as often as possible. Security is of course an important aspect of any RFID deployment and ABI Research often has highlighted issues and strategies with regard to implementing security-conscious RFID applications for many years and in many pieces of research. We are sure you will agree that to dismiss those efforts on the basis of that a single article is a bit unjust given the original intent of the piece: for users to consider value propositions and understand that RFID deployment plans must be structured to appreciate both the business process and technology change. The onus of educating enterprise end users on current and potential security considerations is not the lone responsibility of each item of research published nor of any single group or player in the RFID space, but rather, through combined messaging and commitment from all parties in the value chain. We continue to engage with and monitor companies specializing in RFID data and system security and will consider sharing more of our thoughts on RFID security in the public domain in the future.
Regards,
Michael J. Liard
Research Director
RFID & Contactless
ABI Research
I wish to sincerely thank both Mr. Collins and Mr. Liard for their replies.
Your recent paper titled "Developing a Corporate Plan for RFID Adoption: Enterprise RFID Blueprint and Program Management Considerations" fails to address security issues surrounding RFID. Was this intentional. We discussed this at the RFID Security Alliance, and find it a bit alarming that ABI Research, a trusted research firm, is failing to address this. Can you please expain?
Both Mr. Collins and Mr. Liard replied. Mr. Collins told me he would forward my inquiry to Mr. Liard, and Mr. Liard sent me this response:
Thanks for your interest and comments, Mike. The ABI Research RFID & Contactless team appreciates your feedback. The reason that security was not mentioned explicitly in the article is simply because it was a short, focused piece and the focus was not security. As a security specialist we can understand how you would be eager for the topic to be explicitly included as often as possible. Security is of course an important aspect of any RFID deployment and ABI Research often has highlighted issues and strategies with regard to implementing security-conscious RFID applications for many years and in many pieces of research. We are sure you will agree that to dismiss those efforts on the basis of that a single article is a bit unjust given the original intent of the piece: for users to consider value propositions and understand that RFID deployment plans must be structured to appreciate both the business process and technology change. The onus of educating enterprise end users on current and potential security considerations is not the lone responsibility of each item of research published nor of any single group or player in the RFID space, but rather, through combined messaging and commitment from all parties in the value chain. We continue to engage with and monitor companies specializing in RFID data and system security and will consider sharing more of our thoughts on RFID security in the public domain in the future.
Regards,
Michael J. Liard
Research Director
RFID & Contactless
ABI Research
I wish to sincerely thank both Mr. Collins and Mr. Liard for their replies.
Wednesday, May 14, 2008
Maybe If We Don't Talk About It The Problem Will Go Away.
When I was growing up there was a neighborhood kid whose parents chose to ignore his fits and general bad behavior, despite the fact that it was causing general discomfort to all those around him (myself included). Needless to say, he grew up to be the neighborhood bully, and eventually ended up going to prison for armed robbery. Ignoring him did not make the problem go away.
Unfortunately, that is the exact tactic many "experts" in the RFID industry are taking when it comes to RFID security. They are simply choosing to discuss nearly everything about RFID implementation EXCEPT security. Lets take, for example, an study recently published by ABI Research (a trusted research firm) titled Developing a Corporate Plan for RFID Adoption: Enterprise RFID Blueprint and Program Management Considerations. The publication is quite well written, and discusses practically all management considerations, with the exception of security.
A note to ABI Research and other experts out there. RFID security issues are not going to go away just because they are not discussed. I attempted to contact the authors of the article for comment, to no avail. EDIT: Both Mr. Collins and Mr. Liard did indeed reply to my request for comment. I wish to thank both of them.
That's okay. The RFID Security Alliance is not planning on going away either.
Unfortunately, that is the exact tactic many "experts" in the RFID industry are taking when it comes to RFID security. They are simply choosing to discuss nearly everything about RFID implementation EXCEPT security. Lets take, for example, an study recently published by ABI Research (a trusted research firm) titled Developing a Corporate Plan for RFID Adoption: Enterprise RFID Blueprint and Program Management Considerations. The publication is quite well written, and discusses practically all management considerations, with the exception of security.
A note to ABI Research and other experts out there. RFID security issues are not going to go away just because they are not discussed. I attempted to contact the authors of the article for comment, to no avail. EDIT: Both Mr. Collins and Mr. Liard did indeed reply to my request for comment. I wish to thank both of them.
That's okay. The RFID Security Alliance is not planning on going away either.
Wednesday, April 9, 2008
Is RFID Ready For Drug Pedigree ?
An article published on April 8th, 2008 in RFID Update asks the question "California Not Ready for Drug Pedigrees -- Is RFID?", and goes on to discuss how the California Board of Pharmacy has moved the compliance deadline to 2011 from the original 2009 deadline. The article goes on to discuss how RFID and other drug pedigree solutions need more time to mature before implementation.
What is important for all stakeholders to understand about the drug pedigree challenge is that it is not an RFID issue. It is a security issue. Drug pedigree is not about being able to easily inventory drugs, it is about being able to securely identify and track them. RFID is a technology which plays a small (albeit potentially a very significant) part in the drug pedigree solution chain. The benefits of the currently available RFID technologies definitely outweigh the risks of using a non-RFID based solution as a primary means of identifying and tracking drugs. What organizations need to begin focusing on is securing the drug pedigree solution on a systemic level. What are the concerns pharma has with deploying RFID solutions and what can be done to address those concerns? How significant is the issue compared to a protracted delay of deploying a solution? Can a solution be put in place with an understanding of potential current weaknesses and a road map to improving the weaknesses as resources permit?
RFID technologies are, without a doubt, ready for the challenge. We simply need to move forward and intelligently deploy solutions which are ready for the next improvement. We need to do this now, because drug counterfeiters are not slowing down their developments while we decide what to do.
What is important for all stakeholders to understand about the drug pedigree challenge is that it is not an RFID issue. It is a security issue. Drug pedigree is not about being able to easily inventory drugs, it is about being able to securely identify and track them. RFID is a technology which plays a small (albeit potentially a very significant) part in the drug pedigree solution chain. The benefits of the currently available RFID technologies definitely outweigh the risks of using a non-RFID based solution as a primary means of identifying and tracking drugs. What organizations need to begin focusing on is securing the drug pedigree solution on a systemic level. What are the concerns pharma has with deploying RFID solutions and what can be done to address those concerns? How significant is the issue compared to a protracted delay of deploying a solution? Can a solution be put in place with an understanding of potential current weaknesses and a road map to improving the weaknesses as resources permit?
RFID technologies are, without a doubt, ready for the challenge. We simply need to move forward and intelligently deploy solutions which are ready for the next improvement. We need to do this now, because drug counterfeiters are not slowing down their developments while we decide what to do.
Saturday, March 15, 2008
Mifare Hack Demonstrated and NXP Announces New Chips
In light of reports earlier this month detailing vulnerabilities of the Mifare Classic RFID cards, the Dutch Government has now issued a warning that the hack can be accomplished relatively easily. A team at Radboud University Nijmegen have detailed the process in a video published on the University website. This serves to illustrate the relative ease of reproducing the hack.
Of particular interest is the final paragraph from the article on the RFID Update website, which states:
"The long term impact of this hack on the public's perception of RFID security is unclear. It will likely depend on the extent to which nefarious hackers widely exploit the vulnerability."
I believe the long term impact will be determined by how well the public understands both the vulnerability and the proposed solutions, and how well organizations, such as the RFID Security Alliance, communicate the information. Otherwise, it is simply going to remain an opportunity to generate interesting headlines.
As Karsten Nohl, who published the original vulnerability findings told me:
"So far no nefarious hackers have contacted me to get the details of the cipher and it appears that all academics that share our results will not go out and cause any real-world system to break. After all, this could still take an ok outcome for industry if current systems upgrade reasonably soon. The message that will stick is that RFID aren't some magically secure new technology but rather suffer from the same shortcomings that haunt pretty much any security system."
NXP Semiconductors, the makers of the Mifare chips used in these cards, announced an update to the technology used in the Mifare cards which NXP is referring to as the Mifare Plus. According to the report in RFID Journal, cards using the new technology are backwards compatible with the Mifare Classic system.
Of particular interest is the final paragraph from the article on the RFID Update website, which states:
"The long term impact of this hack on the public's perception of RFID security is unclear. It will likely depend on the extent to which nefarious hackers widely exploit the vulnerability."
I believe the long term impact will be determined by how well the public understands both the vulnerability and the proposed solutions, and how well organizations, such as the RFID Security Alliance, communicate the information. Otherwise, it is simply going to remain an opportunity to generate interesting headlines.
As Karsten Nohl, who published the original vulnerability findings told me:
"So far no nefarious hackers have contacted me to get the details of the cipher and it appears that all academics that share our results will not go out and cause any real-world system to break. After all, this could still take an ok outcome for industry if current systems upgrade reasonably soon. The message that will stick is that RFID aren't some magically secure new technology but rather suffer from the same shortcomings that haunt pretty much any security system."
NXP Semiconductors, the makers of the Mifare chips used in these cards, announced an update to the technology used in the Mifare cards which NXP is referring to as the Mifare Plus. According to the report in RFID Journal, cards using the new technology are backwards compatible with the Mifare Classic system.
Saturday, March 8, 2008
What drives adoption ?
I recently read the fascinating document produced by University Of Virginia student Karsten Nohl titled "Mifare Security". In this document, Karsten describes some of the issue with the Mifare RFID Security tag, and how Karsten was able to break the security. This has now raised much concern in the city of Boston, which is using such technology for their CharlieCards subway passes, as was pointed out in this article in CSO Online, as well as other articles scattered across the web.
The question I want to ask is what drives an organization, such as Boston's subway system, to adopt RFID technology for their system? Is it convenience? Does it look cool? Do they feel it will save them time and money? Does Mifare have a fantastic sales team? Do they want a more secure system? In other words, what was the ultimate OBJECTIVE of implementing an RFID solution? I am going to make the assumption that the objective was to save money (and saving time is exactly the same as saving money), and I want to know if whoever made the decision to implement the Mifare system created a Threat Model before deciding to build the infrastructure. A good model would address the question "What would it take to break the encryption of the Mifare chip?", which turns out to be about $1000. I would suspect somebody at Mifare knew this, in light of the findings of Nohl, which highlight the inherent weakness of the crypto used in the chips. If this is indeed the case, was Mifare (or whoever sold the Mifare system) forthcoming with this information? Did Mifare prepare their own Threat Model?
What is important to understand is that 100% security is simply not possible, and that is not what the objective should focus on. The objective should be focused on what level of security is required for the specific application. The Mifare technology used in the CharlieCard is perhaps more than adequate for access control in a closed environment (such as inside an office building), where it would be unlikely that someone would bother spending $1000 to crack tags so they can gain access to the executive dining room. Motivations, however, can be quite high when you can recharge subway passes and make several dollars each time you resell one of them to thousands upon thousands of users on the black market. What is even more interesting is the relatively low risk associated with the office building crack (if it happened). There is very little motivation for a cracker to attempt to "market" his crack of office access control passes to the "masses" yearning to enter a controlled area of corporate headquarters, where it is likely an intruder would be discovered anyway, due to the closed nature of the environment.
It all comes down to why you want to adopt the solution, and what risks adoption brings with it. Taking this approach is the first step.
The question I want to ask is what drives an organization, such as Boston's subway system, to adopt RFID technology for their system? Is it convenience? Does it look cool? Do they feel it will save them time and money? Does Mifare have a fantastic sales team? Do they want a more secure system? In other words, what was the ultimate OBJECTIVE of implementing an RFID solution? I am going to make the assumption that the objective was to save money (and saving time is exactly the same as saving money), and I want to know if whoever made the decision to implement the Mifare system created a Threat Model before deciding to build the infrastructure. A good model would address the question "What would it take to break the encryption of the Mifare chip?", which turns out to be about $1000. I would suspect somebody at Mifare knew this, in light of the findings of Nohl, which highlight the inherent weakness of the crypto used in the chips. If this is indeed the case, was Mifare (or whoever sold the Mifare system) forthcoming with this information? Did Mifare prepare their own Threat Model?
What is important to understand is that 100% security is simply not possible, and that is not what the objective should focus on. The objective should be focused on what level of security is required for the specific application. The Mifare technology used in the CharlieCard is perhaps more than adequate for access control in a closed environment (such as inside an office building), where it would be unlikely that someone would bother spending $1000 to crack tags so they can gain access to the executive dining room. Motivations, however, can be quite high when you can recharge subway passes and make several dollars each time you resell one of them to thousands upon thousands of users on the black market. What is even more interesting is the relatively low risk associated with the office building crack (if it happened). There is very little motivation for a cracker to attempt to "market" his crack of office access control passes to the "masses" yearning to enter a controlled area of corporate headquarters, where it is likely an intruder would be discovered anyway, due to the closed nature of the environment.
It all comes down to why you want to adopt the solution, and what risks adoption brings with it. Taking this approach is the first step.
Thursday, February 14, 2008
Welcome to the RFID Security Alliance WebLog
The goal in forming the RFID Security Alliance is to establish a De-Facto authoritative organization regarding the subject of security as it applies to the implementation of an RFID system.
The RFID Security Alliance is your one-stop shop for the latest information, collaboration and productivity within the secure RFID industry.
The latest in policy development, RFID news and industry trends brought to you all in central location: The RFID Security Alliance.
The RFID Security Alliance is your one-stop shop for the latest information, collaboration and productivity within the secure RFID industry.
The latest in policy development, RFID news and industry trends brought to you all in central location: The RFID Security Alliance.
Subscribe to:
Posts (Atom)