ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Tech-savvy shoplifters 'could alter RFID tags'

Published: 29 Jul 2004 08:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Privacy advocates may not be the only people taking issue with the current crop of radio-frequency identification tags -- merchants will probably have problems with a lack of security as well, a German technology consultant said on Wednesday.

Low-cost RFID tags -- many which are smaller than a nickel and cost less too -- are already being added to packaging by retailers to keep track of inventory but could be abused by hackers and tech-savvy shoplifters, said Lukas Grunwald, a senior consultant with DN-Systems Enterprise Solutions GmbH. While the technology mostly threatens consumer privacy, the new technology could allow thieves to fool merchants by changing the identity of goods, he said.

"This is a huge risk for companies," Grunwald said during a discussion at the Black Hat Security Briefings. "It opens a whole new area for shoplifting as well as chaos attacks."

While expensive RFID reader hardware and hard-to-use software have hindered security research in the area, Grunwald said that's no longer a hurdle. The security expert announced during the session a new software tool that he helped create that can be used to read and reprogram radio tags.

When such tools become widely available, hackers and those with less pure motives could use a handheld device and the software to mark expensive goods as cheaper items and walk out through self checkout. Underage hackers could attempt to bypass age restrictions on alcoholic drinks and adult movies, and pranksters could create confusion by randomly swapping tags, requiring that a store do manual inventory.

Grunwald's software program, RFDump, makes rewriting RFIDs easy. While there are significant malicious uses of the program, consumers could also use it to protect themselves, he said.

"Everyone should have the right, once they leave the store, to erase the RFID tags," he said. Deleting information on the tags would allow people to stop RFID checkpoints in stores and other places from tracking which products they are carrying, or read tags that have been inserted under their skin.

Solving the business security issues may not be easy. While encryption could be used to hide data from unauthorised snoopers, not many RFID chips can handle the more-involved task of crunching cryptographic keys. Moreover, the RFID tags that can handle those tasks are among the most expensive on the market and not something you would stick on a cream cheese box at the grocery store, Grunwald said.

Store owners could have a database server that they program to track their goods using the unchangeable serial number on the RFID tag but that adds a lot more complexity to the adoption of such technology, Grunwald added.

"The people who will be using this (shopkeepers) don't know much about technology," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
70 out of 146 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Application Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

SAP ERP SD Application Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Test Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Challenges of Nigeria mobile Banking

Mobile Banking refers to provision of banking and financial services with the help of mobile telecommunication devices. The scope of offered services may include facilities to conduct... More

Post a comment

Mobile marketing innovations will driv...

Farmed out License Holder, Etisalat Nigeria sure understand how to engage the subscribers in the 3G Era. During the launch of the Network last week in Lagos, the company spokesperson... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment