The widely reported dispute between security firm IOActive and secure card maker HID has raised awareness about the risks associated with RFID proximity cards and may prompt DHS warnings to government agencies about use of the technology.
Representatives from IOActive, Black Hat, the ACLU, and the U.S. Department of Homeland Security laid bare the vulnerabilities inherent in the popular proximity cards and debated with a HID representative at a panel discussion about RFID vulnerabilities that was part of the Black Hat Federal security conference. While the discussion did little to resolve the disagreements over the cancellation of a planned RFID hacking session, the publicity around the incident may prompt greater scrutiny of RFID security in the public and private spheres, panel members agreed.
The panel discussion at Black Hat followed an abbreviated version of a presentation on RFID security by Chris Paget, director of research and development at IOActive.
IOActive said on Tuesday that it was pulling its presentation under threat of legal action from HID, which claimed that Paget's discussion of methods for creating an RFID cloning device would violate two HID patents on RFID technology.
After discussing RFID technology at a high level and possible security concerns arising from RFID, Paget informed the audience that he couldn't discuss those vulnerabilities further. Instead, he presented a number of slides that excerpted a letter from HID's attorneys and that seemed to suggest that HID had demanded IOActive not present any information at Black Hat. The slides ran contrary to an HID statement late Tuesday that said the company never demanded that Paget cancel his talk.
"HID Global did not threaten IOActive or Chris Paget, its Director of Research and Development, to stop its presentation at the Black Hat event being held in Washington, DC on Wednesday, February 28, 2007. HID Global, acting in the best interests of its customers worldwide, simply informed IOActive and its management of the patents that currently protect HID Global intellectual property," the e-mail statement read.
Mike Davis, director of intellectual property at HID, defended that position and the company's efforts to suppress the presentation of schematics and source code concerning its RFID proximity cards. In sometimes testy exchanges with Paget and Dan Kaminsky of IOActive and in comments to InfoWorld after the panel, Davis said that his company was "ambushed" by IOActive and never threatened to sue Paget or IOActive.
"We never intended to sue IOActive," Davis said, noting that the company only became aware of the issue on the 14th after Paget contacted them in an e-mail but took a week to formulate a response.
Differences between the free-wheeling IT security community and a more closed physical security industry may be partially to blame, according to Joe Grand, a security researcher at Grand Idea Studio.
"Hardware companies are generally not involved in the security process, so they don't know anything about disclosure. So their response is, 'Let's throw down the hammer,'" he said.
While the specifics of the dispute between HID and IOActive are shrouded by legal maneuvers, there was general agreement that insecure RFID deployments are a big problem that needs to be addressed soon.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »