Campus Cards, College and University Identification and Security

Episode 8: Interview with Mifare hacker Karsten Nohl

Wednesday, April 2, 2008

Evaluating the reality of the hack from his perspective and industry insiders

In this episode, the publicized Mifare Crypto-1 hack is examined. Interviews with the researcher that uncoverd the alleged vulnerability, Karsten Nohl, as well as NXP representative Manuel Albers and Smart Card Alliance’s Randy Vanderhoof delve into the topic from all sides.

Albers reports that between 1 and 2 billion of these chips have been issued to date and are in use in transit systems and security and access applications.

Nohl stated that he would wait until next year to make the complete nature of attack public, suggesting “if you are relying on Mifare security, you should start migrating.” When asked if the intent was to give the issuers time to migrate or if he was holding the industry ransom, he replied, “I would acknowledge that we are playing along in the obscurity game … we want every one of these systems to wake up and realize how insecure they are … to convince the last ones that are still claiming we have not found it, we will have to release it.”


Download MP3.

http://www.secureidnews.com/podcasts for older podcasts.


Karsten Nohl and Henryk Plötz present at 24C3

Karsten’s slides (pdf)

Henryk’s slides (pdf)

 [end] 

The top stories of 2009 centered on government identification initiatives including electronic passports, national ID programs, driver license reform and identity management. Take a moment and check out what you and our worldwide base of more than 30,000 readers found most interesting during the last year. I think you will agree it provides a unique snapshot into the “identity Zeitgeist.” Our editorial team and the rest of the AVISIAN Publishing staff look forward to bringing you the best in ID and security insight again in 2010. Here’s to the New Year!

read more »

Government issued ID cards aren’t what they use to be. In the last 10-years the documents have changed from simple piece of laminated plastic to high-tech IDs with multiple security features. Regarding ID Editor Zack Martin spoke with Robert DeVincenzi, president and CEO at LaserCard, about the company’s role in changing IDs and a Frost & Sullivan report that analyzes some of the progress.

read more »

In another of a series of podcasts investigating identity standards, Kevin Gillick, executive director at GlobalPlatform, talks with Regarding ID Editor Zack Martin about its place in the standards landscape and the role it plays.

read more »

The top stories from the campus card market in 2009 included a controversial patent on web revalue, a series of pieces on campus card banking programs, and a nationwide assortment of innovative card programs from Boston to Montana. The CR80News editorial team and the rest of the AVISIAN Publishing staff are working hard to bring you the best in campus ID and security insight once again in 2010. Here’s to the New Year, our ninth publishing CR80News!

read more »

In our continuing podcast series on identification standards, Don Thibeau, executive director at the The OpenID Foundation and chairman and president of The Open Identity Exchange, speaks with Regarding ID Editor Zack Martin about its place in the ID standards landscape and some of its different projects. OpenID may be the one ID standard that many people are already using but don’t even realize it.

read more »

China’s GYRFID has announced the release of its new ISO14443A Mifare 1K/ Mifare 4K/ Mifare Ultralight multi-function contactless card.

The 13.56Mhz, 512bit contactless card is suitable for public transportation, payment systems, logistics, e-ticketing and more, according to GYRFID, and measures 86mm by 54mm, with a thickness of 0.84mm.  

read more »