RFID Hack Could Allow Retail Fraud

New tool allows modifications of the code stored within RFID tags, potentially allowing consumers to buy caviar for the price of a dozen eggs.

LAS VEGAS—A German consultant has released a tool that its creator says will allow modifications of the code stored within RFID tags, theoretically allowing consumers to wreak havoc in future retail deployments.

The RFDump software allows a user equipped with an RFID reader, a laptop or PDA, and a power supply to rewrite the data stored in ISO 15693 tags, the most common tags used to host the EPC (Electronic Product Code) information traditionally stored in bar codes.

/zimages/3/28571.gifClick here to read about eWEEK Labs analysis of RFID.

Although each RFID tag carries with it a unique product ID, the EPC is stored in the "user area" portion of the chip, which allows it to be rewritten. That poses problems to both consumers and retailers, RFDumps author, Lukas Grunwald, a senior consultant with Hildesheim, Germany-based DN-Systems Enterprise Solutions GmbH, said: On one hand, consumers could defraud a retailer by reprogramming a premium item as a cheap commodity. On the other hand, consumers would have to worry about the items in their shopping carts being read by "Big Brother," or at least the many retailers in a shopping mall.

The tool was released as part of a talk at the Black Hat Briefings here, dedicated to IT security.

/zimages/3/28571.gifClick here to read about Congress RFID concerns.

And theres an even worse scenario: "It is only a matter of time before someone puts a root exploit on one of these tags and hacks into your supply chain," Grunwald said.

RFID tags have been seen as a revolutionary device by retailers, manufacturers and the military. Theoretically, a pallet or product with an embedded RFID tag can be tracked more accurately, resulting in a more efficient inventory-management system that could be used to quickly replace umbrellas, for example, that sold out during a rainstorm. Gap Inc. and Italys Benetton already use the tags in their stores.

In Europe, the Gillette Co. has used RFID tags inside packages of razor blades to minimize theft, Grunwald said. And Wal-Mart Stores, the worlds largest company, and the U.S. Department of Defense have separate programs to rework their supply chains around RFID tags by next year. By 2007, all manufacturers, retailers, drug stores, hospitals and smaller retails will use the tags, according to Robin Koh, a member of the Auto-ID Labs industry consortium. Already, RFID tags are popping up inside consumer loyalty cards.

The assumption is that the military will have the budget to buy tamperproof tags. But not so for retailers and manufacturers, who will likely try to scrimp, Grunwald said. The most common EPC tags store the item information in cleartext inside the tag, and allow rewriting of the data. Each tag sits idle until powered on by the RF energy emitted from the gate, and can then be read.

Next Page: Tool facilitates criminal mischief.