Backdoor in RFID cards allows instant cloning
securityweek.com
securityweek.com
Blog post: https://blog.quarkslab.com/mifare-classic-static-encrypted-n...
Discussion: https://news.ycombinator.com/item?id=41269249
A backdoor is one thing, but the technology is paper-thin when used alone.
RFID is an inexpensive thing-monitoring platform, great for tracking goods in a process (manufacturing or in some cases, warehousing) but it should not be relied upon as the only layer in a security solution.
The title is quite misleading (at least for people in the field).
RFID identifies; MIFARE and similar cards also mutually authenticate and/or store data securely (or not so securely when using MIFARE Classic or clones, such as this one).
Even the ones not made by a Chinese company had the same backdoor. Perhaps, the original design had this backdoor and the manufacturers simply implemented the design. NXP is Dutch. Infineon is German.
So if the code was there it's not the fault of the card manufacturer but the applet developer.
Static key, decrypts all cards of a given model regardless of user stored keys? Yep, it's a backdoor.
> put in there on purpose by the manufacturer
Hard to prove "on purpose" either way, my guess it was for debugging.
(but hey, taking Croudstrike into account, everything is possible)