Mythbusters RFID episode axed after 'pressure' from credit card firms
theregister.co.uk
theregister.co.uk
Threatening Mythbusters is probably a matter of 15 billable minutes of legal time. Whereas building a secure RFID is hundreds or thousands of engineering hours.
Here's something that just occurred to me: One reason why actual security is more expensive than lawyers is that your security team is up against black-hat hackers who are willing to spend hundreds of hours working -- anonymously, in secret, and without pay -- to defeat you. Whereas your legal team is generally not opposed by a black-hat legal team that is willing to spend hundreds of pro bono legal hours to try to defeat you in court. Particularly because you can't challenge a legal threat while simultaneously remaining anonymous and working in secret.
Building the insecure RFID is also hundreds or thousands of engineering hours. There is a lot of grunt work that was done regardless; designing the radios, designing the manufacturing process for the ID chips to be as cheap as possible, etc. Getting the crypto right isn't much on top of that.
With information like the defcon slides already readily available I'm surprised to see such pressure. I guess a segment on a cable TV show is more public than MIT student newspaper.
http://www.thelasthope.org/talks.html http://www.thelasthope.org/media/audio/16kbps/REAL_ID_Act_an...
I figure it shouldn't be too hard, it's just sending out a radio frequency, right?
Then bad publicity ensues and what do you know: Adam now claims he had a brain fart and all the big corporations say there just giddy over the Mythbusters segment. They were bending over backwards to help!
Shucks, what a silly misunderstanding!
I had to re-read that first sentence a few times.
Or would it even be possible given how easy it is?
i can't find a link to the experiment, but i saw something on rfid wardriving and hacking that involved setting up a node near gas station rfid payment nodules (similar to how ATM hackers set up fake fronts on the card insertions), intercepting the information that can get cracked or copied for use.