• On GameSpot: Wii Fit tells 10-year-old she's fat
July 19, 2008 9:25 AM PDT

Protecting against Wi-Fi, Bluetooth, RFID data attacks

NEW YORK--Using a laptop, cell phone headset, building access badge, credit cards, or even a passport can make you a walking target for data thieves and other criminals, a security expert warned at the Last HOPE hacker conference here late Friday.

Security expert RenderMan discusses the insecurity of RFID chips, Bluetooth headsets and laptops using Wi-Fi at the Last HOPE hacker conference.

(Credit: Elinor Mills/CNET News)

In a frightening but entertaining session entitled "How do I Pwn Thee? Let me Count the Ways" (pwn is hacker speak for "own" or control), a hacker who goes by the alias "RenderMan" explained how most people are at risk and don't even know it.

By now most people probably know they should be careful using Wi-Fi networks, especially public hotspots that don't encrypt data transmissions and where network access points can be spoofed. These issues leave Web surfers at risk of having their data stolen, receiving fake Web pages and other information, and having their computers completely taken over, he said.

Even airplane passengers who either ignore stewardess requests to disable Wi-Fi or don't know how to turn it off are not immune to attacks from others in the airplane, he added.

RenderMan suggests that people disable Wi-Fi when it is not in use and use VPNs and firewall software.

Bluetooth headset users are at risk because of a security hole in the technology and default PINs that don't get changed, he said. Exploiting vulnerabilities someone can break in and steal data from the phones, make calls without the cell phone owner knowing, listen in on and break into conversations, and even spy on people by turning the device into a bug.

He advises that people change the default password, disable the Bluetooth on the phones, turn off the headsets when not in use, and limit access to the data and features when communicating with other Bluetooth devices.

Many people don't realize that new U.S. passports have RFID technology with weak encryption that makes the data on the chip easy to read with the proper reader device. (See related video below).

The U.S. government attempted to mitigate the privacy threat by putting a metal foil layer on the front and back cover of the passports, but the stiffness of the foil pops the passport open as much as an inch, wide enough for RFID readers to snatch the data, RenderMan said, showing a video to demonstrate this.

"There is no rule that says that if the chip doesn't work, they will refuse you access to the border. You will get increased scrutiny, but it's still a valid document," he said. "So, liberal application of a hammer can negate a lot of the possible" problems.

But doing willful damage to the passport is a crime, one attendee pointed out. "I fell, really hard," RenderMan deadpanned.

RFID used in transit and building access badges has also been proven to be insecure, allowing someone to use an RFID reader to copy data off the card and make a clone of it, he said.

A security flaw in the Mifare Classic Chip used in transit systems is the subject of a court case in The Netherlands. The maker of the chip, NXP Semiconductors, sued to block a university from publishing details of the problems, but a court ruled on Friday that the research can be made public.

Even traditional keys are vulnerable, RenderMan said. For instance, photographs of spare keys for electronic-voting machines displayed on a Web page were used to make replicas with similar-looking keys, he said. A video demo showed how someone filed down a key from a hotel mini-bar and was able to open up the memory card slot of a Diebold voting system.

Credit: CNET News
Michael Aiello, president of DIFRwear, demonstrates at Last HOPE how easy it is to swipe the data off someone's RFID-enabled credit card, building access badge, or passport from a few feet away. DIFRwear sells wallets and cases to protect cards from data thieves.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 and previously covered search, online advertising, and portals. E-mail Elinor.
Recent posts from News - Security
World Bank under cyberattack?
Apple's October update fixes 20 security flaws
Microsoft to issue 11 security patches on Tuesday
Parity provides free online identity management
Symantec eyes pay-per-use software
Add a Comment (Log in or register) 5 comments
by Travis Ernst July 19, 2008 4:26 PM PDT
As much as I like the concept of causing the newer passports RFID's to malfunction, Department Of State will make you get a new one sooner or later before it expires. They like to be pushy just like the TSA. They want their trackers working. Trust me. I even thought about running mine through an MRI "by accident" when I had a medical scan. Sadly I forgot to bring it with me. Pretty soon they will be "chipping" our kids at birth. Lets wait until they start beta testing that method on the jail population before we need to really panic.
Reply to this comment
by Travis Ernst July 19, 2008 4:27 PM PDT
As much as I like the concept of causing the newer passports RFID's to malfunction, Department Of State will make you get a new one sooner or later before it expires. They like to be pushy just like the TSA. They want their trackers working. Trust me. I even thought about running mine through an MRI "by accident" when I had a medical scan. Sadly I forgot to bring it with me. Pretty soon they will be "chipping" our kids at birth. Lets wait until they start beta testing that method on the jail population before we need to really panic.
Reply to this comment
by tonyspencer2 July 20, 2008 2:27 AM PDT
So I guess if you put an elastic band around your passport, it won't open and lave your data vulnerable to IP theft...
Reply to this comment
by theprez98 July 21, 2008 5:30 PM PDT
Passports are good for 10 years, so I don't think anybody is worrying about them expiring.
Reply to this comment
by ralfthedog July 23, 2008 11:07 AM PDT
Put your passport in a Faraday bag.
Reply to this comment
Powered by Jive Software
advertisement
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About News - Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

News - Security topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right