Monday, October 30, 2006

Potential dangers with "proximity" cards

Do you have a proximity access card for your secure building, or a credit/debit card with 'tap and go' or some other variety of proximity based radio transmission of your account info? How secure do you imagine those transmissions to be? Are they encrypted? Do the POS terminals decrypt the signal, then? Do they? Are you sure? Did you ask your bank?

Well at least these RFID-based things are convenient. They must be coupled with encryption in order to defeat 'eavesdroppers' who can use sensitive antennae to pick up the RFID signal and save the info for nefarious use. If you have multiple such cards then at least you have muddied the electronic waters a bit, but a single card is prey to short range transmission - and reception. Maybe that guy in the queue behind you is reading your card right now... read the full study here (from the University of Massachusetts).

No comments: