Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • Mobile

    RFID Hack Could Allow Retail Fraud

    Written by

    Mark Hachman
    Published July 29, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      LAS VEGAS—A German consultant has released a tool that its creator says will allow modifications of the code stored within RFID tags, theoretically allowing consumers to wreak havoc in future retail deployments.

      The RFDump software allows a user equipped with an RFID reader, a laptop or PDA, and a power supply to rewrite the data stored in ISO 15693 tags, the most common tags used to host the EPC (Electronic Product Code) information traditionally stored in bar codes.

      /zimages/3/28571.gifClick here to read about eWEEK Labs analysis of RFID.

      Although each RFID tag carries with it a unique product ID, the EPC is stored in the “user area” portion of the chip, which allows it to be rewritten. That poses problems to both consumers and retailers, RFDumps author, Lukas Grunwald, a senior consultant with Hildesheim, Germany-based DN-Systems Enterprise Solutions GmbH, said: On one hand, consumers could defraud a retailer by reprogramming a premium item as a cheap commodity. On the other hand, consumers would have to worry about the items in their shopping carts being read by “Big Brother,” or at least the many retailers in a shopping mall.

      The tool was released as part of a talk at the Black Hat Briefings here, dedicated to IT security.

      /zimages/3/28571.gifClick here to read about Congress RFID concerns.

      And theres an even worse scenario: “It is only a matter of time before someone puts a root exploit on one of these tags and hacks into your supply chain,” Grunwald said.

      RFID tags have been seen as a revolutionary device by retailers, manufacturers and the military. Theoretically, a pallet or product with an embedded RFID tag can be tracked more accurately, resulting in a more efficient inventory-management system that could be used to quickly replace umbrellas, for example, that sold out during a rainstorm. Gap Inc. and Italys Benetton already use the tags in their stores.

      In Europe, the Gillette Co. has used RFID tags inside packages of razor blades to minimize theft, Grunwald said. And Wal-Mart Stores, the worlds largest company, and the U.S. Department of Defense have separate programs to rework their supply chains around RFID tags by next year. By 2007, all manufacturers, retailers, drug stores, hospitals and smaller retails will use the tags, according to Robin Koh, a member of the Auto-ID Labs industry consortium. Already, RFID tags are popping up inside consumer loyalty cards.

      The assumption is that the military will have the budget to buy tamperproof tags. But not so for retailers and manufacturers, who will likely try to scrimp, Grunwald said. The most common EPC tags store the item information in cleartext inside the tag, and allow rewriting of the data. Each tag sits idle until powered on by the RF energy emitted from the gate, and can then be read.

      Next Page: Tool facilitates criminal mischief.

      Page 2


      Using the RFDump tool, a shopper could covertly rewrite the tag inside the store, creating all sorts of criminal mischief. The shopper could reprogram a bottle of shampoo as cream cheese, or rewrite a pornographic DVD as childrens entertainment, Grunwald said.

      The trick only works if a shop has implemented automatic checkout, or at least one that doesnt encourage human intervention. Some retailers use a video camera to double-check items, according to a Defense Department IT employee attending the convention. Germanys METRO Group has already deployed an RFID-equipped store in Rheinburg, Germany, complete with self-checkout kiosks.

      /zimages/3/28571.gifFor insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzers Weblog.

      A second system at the store exit checks to see if the user has paid for all of his items, then supposedly writes 0s in the user ID field, erasing the tag for privacy purposes. Alarms will sound if a shopper attempts to sneak away. One way to exasperate store owners, Grunwald said, is to buy an individual tag, program it with item data, then slip the tiny tag near the gate. After 5 minutes of shrieking sirens, the gate will be turned off, he said.

      However, the tags require the RF energy to function. Wrapping a tag in aluminum foil blocks the radio waves and prevents a tag from being identified. Security firm RSA Security has also released a so-called “blocker tag” to prevent a shoppers privacy. But RFDump can still access and attack the stored information, Grunwald said.

      /zimages/3/28571.gifeWEEK.coms Lisa Vaas offers tips for getting ready for RFID.

      As a proof of concept, Grunwald also added a “cookie” function to RFDump that allows a store to track the number of times a shopper enters or picks up an item. An audience member pointed out that that had serious implications for personal privacy. “You are exactly correct,” Grunwald said. “It is a very scary thing.”

      /zimages/3/28571.gifCheck out eWEEK.coms Security Center at http://security.eweek.com for the latest security news, reviews and analysis.

      /zimages/3/77042.gif

      Be sure to add our eWEEK.com developer and Web services news feed to your RSS newsreader or My Yahoo page

      Mark Hachman
      Mark Hachman

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×