• On MovieTome: The 10 worst movies of 2009 so far!
July 18, 2008 7:32 AM PDT

Dutch court allows publication of Mifare security hole research

by Elinor Mills

Updated 8:30 a.m. PDT with researcher comment and photos. Updated 11:17 a.m. with NXP comment.

NEW YORK--A Dutch court ruled on Friday that a university can publish an article on security flaws in the Mifare Classic wireless smart card chip, the most popular chip used in transit systems around the world.

Security researcher Karsten Nohl discusses how he cracked the cryptography in the Mifare Classic Chip at the Last HOPE conference.

(Credit: Elinor Mills)
NXP Semiconductors, formerly Philips Semiconductors, sued to prevent computer science professor Dr. B. Jacobs Radboud at University Nijmegen from publishing a scientific paper on the technology, arguing that it would be irresponsible to make the information public.

The Rechtbank Arnhem court ruled that prohibiting publishing of the article would violate the researcher's freedom of expression which is vital to a democratic society, according to a news release from the university.

The article will be published at the beginning of October during a scientific conference in Malaga in Spain. Jacobs demonstrated how one could ride the London transit system for free by making a clone of a stranger's transit card. The card is also used for access control to buildings.

Karsten Nohl, a University of Virginia graduate student who worked with others to break the crypto algorithm last year, was giving a talk about his research into security problems with Mifare chips at the Last HOPE hacker conference here on Friday morning.

"I don't think anyone truly believes you can prevent reverse engineering techniques from being published," Nohl said during his talk. Although the Digitial Millenium Copyright Act would apply in the U.S., universities are exempt, he said.

"I'm very happy that the court upheld the right to open research and freedom of publication," Nohl told CNET News after his talk. "I'm also happy that the court understood that publishing vulnerabilities is a crucial part of the evolution of security and a different court outcome would have slowed down that evolution of smart card security and left too many systems vulnerable."

Rop Gonggrijp, a Dutch security researcher attending the conference, said publishing information on vulnerabilities is often the only way to get the vendor to fix the problem. "Any other outcome would have changed the way science discloses security vulnerabilities," he said.

Security researchers Karsten Nohl and Rop Gonggrijp discuss the Mifare court ruling at the conference.

(Credit: Elinor Mills)

In a statement, NXP said publishing the means to carry out hacks on the chip "is contradictory to the scientific goal of prevention and the responsible disclosure of sensitive information."

"We have not and will not seek any kind of punitive action toward the university or researchers," Henri Ardevol, general manager of automatic fare collection for NXP, told CNET News on Friday. "Affected parties may want to see if they themselves want to take direct action" against the university.

Ardevol said it was too early to say whether NXP would appeal the ruling.

There are techniques and countermeasures to detect cards and data which have been tampered with, although there remains a residual risk, Ardevol said. (More information on the risks is on Mifare's Web site.)

"Migration to a different format is one option," he said. "We introduced Mifare Plus earlier this year, and it is designed to help migrate from Mifare Classic to a higher level of security...We will be developing plans for how to guide these migrations."

NXP has sold more than 1 billion of the cards, although it does not know how many are still active, according to Ardevol.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register)
by Barbara80 October 15, 2009 1:20 PM PDT
I cannot belive it! But I'm glad because this information can be really useful for professionals. As a scientist, I'm interested in this topic, because I work as a Risk Manager and often have a deal with different types of frauds. I found some statistics at <a href=http://rapid4me.com > http://rapid4me.com , and I was surprised, that often young specialists do not have enough knowledge to be a profesionals. I really hope, that despite of importance of this information, it will be more useful than harmful.
Reply to this comment
by Barbara80 October 15, 2009 1:21 PM PDT
I cannot belive it! But I'm glad because this information can be really useful for professionals. As a scientist, I'm interested in this topic, because I work as a Risk Manager and often have a deal with different types of frauds. I found some statistics at http://rapid4me.com , and I was surprised, that often young specialists do not have enough knowledge to be a profesionals. I really hope, that despite of importance of this information, it will be more useful than harmful.
Reply to this comment
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right