3DES protected smartcard cracked with side channel analysis.
aktuell.ruhr-uni-bochum.de
aktuell.ruhr-uni-bochum.de
Sadly, the 7MB file linked from that article is not a PDF of a published research paper, but an enormously high-res version of the photo to the right of the article.
So you need a few thousand Euros of equipment, some knowledge, and undetected access to a card for three to seven hours... --considering the requirements to be "quite low" is just the typical security world scare-mongering journalism.
(A bit of perspective: this is not really a new result, the same group has cracked similar systems before. Smart cards are quite hard to protect from side-channel attacks.)
I used to work for a DRM company, and the physical protections designed into those things (not near-field, just standard smartcards) was ludicrous. self-destruction on exposure to light. Measured to ensure that you can't detect good or bad keys by: thermal emissions, electric resistance, electrical consumption, time to respond, and rf emissions.
All of that on top of the standard cryptographic requirements makes smartcard design an incredibly challenging proposition, and one that is ultimately futile in my opinion. For example, the last I heard from friends in the biz was that the crackers are still just using agregate measurements, but what happens when they start using high-res thermal imaging? You'll have to make sure that there is no special hotspot (or coldspot) on the chip when decryption succeeds. The same applies to RF emissions. Not easy.
Theoretical cryptographers have recently begun studying this kind of problem (in fact, that's what my PhD is about). That may help. Or not. But throwing the problem "over the wall" to the engineers hasn't worked that well, and I hope that some theory can be helpful here.
The issues I take with calling the requirements "quite low" are two fold; (1) Most people could never succeed with this attack vector, and (2) Most people would never bother. This certainly isn't "FireSheep" which really does have "quite low" requirements, and getting free bus passes in San Francisco is certainly not worth the time, expense, and effort, so most people would ever bother to do it.
BTW, I've collected some interesting papers and whatnot on side channel attacks. If you want them, email me, but knowing you, you probably already have most of them. ;)
Selling fake bus passes might be worth it though
Hiring the equipment would be possible. I bet it would bring the price down to under a hundred euros.
What I'm trying to get to is: Is there a (illegal) business model possible, a la
- invest 'a few thousand Euros' for equipment
- buy and unlock such a card for a month/year (maybe with stolen details, if necessary)
- copy this card (3-7 hours are no problem, it's yours) and sell it on the black market
Impossible? Why?
Also, 3-7 hours for a typical attack time is notable because it fits into a typical human sleep cycle. You could pick the target's pocket on the way out of the office, and return the card as "lost and found" the next morning.