pwshub.com

RFID cards could turn into a global security mess after discovery of hardware backdoor

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

WTF?! Chinese-made chips used in popular contactless cards contain hardware backdoors that are easy to exploit. These chips are compatible with the proprietary Mifare protocol developed by Philips spin-off NXP Semiconductors and are inherently "intrinsically broken," regardless of the card's brand.

Security researchers at Quarkslab have discovered a backdoor in millions of RFID cards developed by Shanghai Fudan Microelectronics (FMSH). When properly exploited, this backdoor could be used to quickly clone contactless smart cards that regulate access to office buildings and hotel rooms worldwide.

According to French researchers, "Mifare Classic" cards are widely used but have significant security vulnerabilities. These chip-based contactless cards have been targeted by various attacks over the years and remain vulnerable despite the introduction of updated versions.

In 2020, Shanghai Fudan released a new variant that provides a compatible (and likely cheaper) RFID technology through the Mifare-compatible FM11RF08S chip. It featured several countermeasures designed to thwart known card-only attacks, but introduced its own security issues.

Quarkslab analyst Philippe Teuwen discovered an attack capable of cracking FM11RF08S "sector keys" within a few minutes, but only if a specific key is reused across at least three sectors or three cards.

Armed with this new knowledge, the researcher made a subsequent, puzzling discovery: the FM11RF08S cards contain a hardware backdoor that allows certain authentication through an unknown key. He ultimately cracked this secret key and discovered that it was used by all existing FM11RF08S cards.

Furthermore, the previous generation of Mifare-compatible cards (FM11RF08) had a similar backdoor protected by another secret key. After cracking this second key, Teuwen found that it was common to all FM11RF08 cards and even to "official" Mifare cards manufactured by NXP and Infineon.

The newly discovered FM11RF08S backdoor could enable an attacker to compromise all user-defined keys by simply accessing the card for a few minutes, Teuwen said. Customers should be aware that RFID cards based on FM11RF08 and FM11RF08S chips are also used outside the Chinese market, with numerous hotels in the US, Europe, and India employing this significantly insecure technology.

"It is important to remember that the MIFARE Classic protocol is intrinsically broken, regardless of the card," Teuwen said.

Recovering the keys will always be possible if an attacker has access to the corresponding reader. More robust (and hopefully backdoor-free) alternatives for RFID-based security are already available on the market.

Source: techspot.com

Related stories
1 month ago - I took the all-electric Lotus Eletre on a mammoth road trip, and I learned a lot about living with an EV.
1 month ago - Whether for his birthday or just cause, these are the gifts for dad we guarantee he'll love.
1 month ago - Why You Can Trust CNET Our expert deal-hunting staff showcases the best price drops and discounts from reputable sellers daily. If you make a...
6 days ago - Where'd I leave that again? — For small birds, remembering where the food is beats forgetting when it's gone. ...
Other stories
1 hour ago - After the last few entries visited historical and near-future time periods, the next Battlefield game will return to a modern-day setting, aiming to recapture the essence of Battlefield 3 and 4. The follow-up recently entered full...
1 hour ago - The Windows App allows you to access your Windows PC, Azure Virtual Desktop, or Remote Desktop from almost any device. It is available for Windows, Macs, iPhones, iPads, and Android devices. The app supports multiple monitors, USB...
1 hour ago - Why You Can Trust CNET Our expert, award-winning staff selects the products we cover and rigorously researches and tests our top picks. If you buy...
1 hour ago - The video game Devil May Cry is getting its own animated Netflix show, and the streaming service revealed a teaser during Geeked Week on Thursday....
1 hour ago - He's terrier-fying. And you can now change Skelly's spooky eyes to fit in with various holidays.