• On BNET: Vote: How will Apple blow it?
July 18, 2008 7:32 AM PDT

Dutch court allows publication of Mifare security hole research

by Elinor Mills
  • Font size
  • Print
  • 2 comments

Updated 8:30 a.m. PDT with researcher comment and photos. Updated 11:17 a.m. with NXP comment.

NEW YORK--A Dutch court ruled on Friday that a university can publish an article on security flaws in the Mifare Classic wireless smart card chip, the most popular chip used in transit systems around the world.

Security researcher Karsten Nohl discusses how he cracked the cryptography in the Mifare Classic Chip at the Last HOPE conference.

(Credit: Elinor Mills)
NXP Semiconductors, formerly Philips Semiconductors, sued to prevent computer science professor Dr. B. Jacobs Radboud at University Nijmegen from publishing a scientific paper on the technology, arguing that it would be irresponsible to make the information public.

The Rechtbank Arnhem court ruled that prohibiting publishing of the article would violate the researcher's freedom of expression which is vital to a democratic society, according to a news release from the university.

The article will be published at the beginning of October during a scientific conference in Malaga in Spain. Jacobs demonstrated how one could ride the London transit system for free by making a clone of a stranger's transit card. The card is also used for access control to buildings.

Karsten Nohl, a University of Virginia graduate student who worked with others to break the crypto algorithm last year, was giving a talk about his research into security problems with Mifare chips at the Last HOPE hacker conference here on Friday morning.

"I don't think anyone truly believes you can prevent reverse engineering techniques from being published," Nohl said during his talk. Although the Digitial Millenium Copyright Act would apply in the U.S., universities are exempt, he said.

"I'm very happy that the court upheld the right to open research and freedom of publication," Nohl told CNET News after his talk. "I'm also happy that the court understood that publishing vulnerabilities is a crucial part of the evolution of security and a different court outcome would have slowed down that evolution of smart card security and left too many systems vulnerable."

Rop Gonggrijp, a Dutch security researcher attending the conference, said publishing information on vulnerabilities is often the only way to get the vendor to fix the problem. "Any other outcome would have changed the way science discloses security vulnerabilities," he said.

Security researchers Karsten Nohl and Rop Gonggrijp discuss the Mifare court ruling at the conference.

(Credit: Elinor Mills)

In a statement, NXP said publishing the means to carry out hacks on the chip "is contradictory to the scientific goal of prevention and the responsible disclosure of sensitive information."

"We have not and will not seek any kind of punitive action toward the university or researchers," Henri Ardevol, general manager of automatic fare collection for NXP, told CNET News on Friday. "Affected parties may want to see if they themselves want to take direct action" against the university.

Ardevol said it was too early to say whether NXP would appeal the ruling.

There are techniques and countermeasures to detect cards and data which have been tampered with, although there remains a residual risk, Ardevol said. (More information on the risks is on Mifare's Web site.)

"Migration to a different format is one option," he said. "We introduced Mifare Plus earlier this year, and it is designed to help migrate from Mifare Classic to a higher level of security...We will be developing plans for how to guide these migrations."

NXP has sold more than 1 billion of the cards, although it does not know how many are still active, according to Ardevol.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Cisco launches iPhone security app
Town to photograph every car that enters and leaves
Add a Comment (Log in or register)
by Barbara80 October 15, 2009 1:20 PM PDT
I cannot belive it! But I'm glad because this information can be really useful for professionals. As a scientist, I'm interested in this topic, because I work as a Risk Manager and often have a deal with different types of frauds. I found some statistics at <a href=http://rapid4me.com > http://rapid4me.com , and I was surprised, that often young specialists do not have enough knowledge to be a profesionals. I really hope, that despite of importance of this information, it will be more useful than harmful.
Reply to this comment
by Barbara80 October 15, 2009 1:21 PM PDT
I cannot belive it! But I'm glad because this information can be really useful for professionals. As a scientist, I'm interested in this topic, because I work as a Risk Manager and often have a deal with different types of frauds. I found some statistics at http://rapid4me.com , and I was surprised, that often young specialists do not have enough knowledge to be a profesionals. I really hope, that despite of importance of this information, it will be more useful than harmful.
Reply to this comment
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right