Researchers have taken a look at the first generation of RFID-enabled credit cards and the security picture isn’t pretty. The RFID Consortium for Security and Privacy states in its blog today:
While appealing to both consumers and merchants, the convenience of RFID credit cards has a flip side. What a legitimate merchant terminal can read, a malicious scanning device can also read without a consumer’s consent or knowledge. RFID credit cards therefore call for particularly careful security design.
The researchers (from UMass, Johns Hopkins and RSA Labs) say there are two main concerns: User names are easily learned and that crooks can clone the cards and make charges against the real ones.
The researchers say hope is not lost:
Slightly stronger data protections and cryptography could largely prevent Johnny Carson attacks and most of the other vulnerabilities illustrated in the RFID-CUSP study. Check out a version of the paper here.




