Dutch RFID transit pass cracked and cloned

Melanie Rieback, who worked on the RFID Guardian, sez,
Roel Verdult, an MSc. student from the Raboud University of Nijmegen, used an RFID tag emulator to perform a successful practical relay attack on the single-use OV Chipkaart (the Dutch RFID public transportation card), that uses MIFARE Ultralights (no crypto).

There's a video of the relay attack available. The video speaks for itself.

Roel used a homemade tag emulator that was modeled after Kfir and Wool's "ghost and leech", to perform a simple relay attack. However, anyone can perform the same attack using the RFID Guardian, whose HW/SW is freely available.

PDF Link

Read more    

show full bio

Cory Doctorow

Jun 1, Sydney Vivid
Jul 14, London EFF Speakeasy
Jun 18, Dublin Internet Freedom
Context (essays)
With a Little Help (short stories)
For the Win (YA novel)
Makers (adult novel)

Where not otherwise specified, this work is licensed under a Creative Commons License permitting non-commercial sharing with attribution. Boing Boing is a trademark of Happy Mutants LLC in the United States and other countries.