On TechRepublic: 10 dying IT skills
BNET Business Network:
BNET
TechRepublic
ZDNet

February 27th, 2007

RFID security: Black Hat muzzle prevents real discussion

Posted by Larry Dignan @ 9:52 am

Categories: General, RFID, Security, Software Infrastructure

Tags:

In Focus » See more posts on: Black Hat

Ryan Naraine gives details on why a talk about RFID security was canceled at Black Hat.

In short, IOActive’s Chris Paget’s plan to explain why RFID technology is “insecure and untrustworthy” was nixed after secure card maker HID Corp. raised objections in a letter that claims possible patent infringement. Infoworld's Paul Roberts also reported the legal roadblock. In Naraine's update he gives highlights over a conference call on the issues.

My takeaways:

Black Hat has gone corporate and it's a handicap.
CMP now owns the show, but rest assured if this conference was still underground this legal mumbo jumbo wouldn't have occurred.

Any discussion about real security issues can be muzzled by cease and desist letters by some vendor worried about its perception. Jeff Moss, founder of Black Hat, said:

"It really surprised us that HID got really excited about this. It has snowballed into shades of a [Michael Lynn-type] scenario where cease-and-desist letters are circulating. I don’t like having speakers intimidated so the prudent approach now is to just get out of the way of this speeding train. CMP and Black Hat were not threated by HID but we have to be mindful of the threats against IOActive. They are a small security research company and we have to support them."

Memo to HID: Your perception just took a hit even though your patent didn't.

RFID security is now a front-burner issue. I've written about RFID a bunch and always thought the privacy issues related to tagging were a red herring. Now there's an issue–intercepting data on inventory whereabouts and getting inside corporate operations is very interesting. Just how big of an issue is RFID security?

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
Big Enough
http://www.spychips.com/about_us.html

http://www.spychips.com/blo... (Read the rest)
Posted by: pritchet1 Posted on: 02/27/07 You are currently: a Guest | | Terms of Use
Well apparently the issue is big enough for...  mrlinux | 02/27/07
Big Enough  pritchet1 | 02/27/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More