4 ms·
Not entirely sure why you're being downvoted. Sun terminals have had smartcard access for, what, 15 years? (Yes, for hospitals). It's a good idea. Some sort of
by gozo 11y ago
Not entirely sure why you're being downvoted. Sun terminals have had smartcard access for, what, 15 years? (Yes, for hospitals). It's a good idea. Some sort of complementary directional RFID might be even better.
E.g. https://www.youtube.com/watch?v=R497CzmKyVQ&t=38s https://www.youtube.com/watch?v=R497CzmKyVQ&t=38s
- pdkl95 11y ago> RFID Adding radio as a primary component in a security system is always going to be a bad idea. Security is hard enough without adding in the possibility of 3rd parties hearing the protoocol - or worse. > directional A common misunderstanding of radio is the belief that it can be contained in an area. Unless you're building a proper Faraday cage (which is hard), the ability to hear a transmmission often depends on the receiving antenna. For convenience without involving radio, one simply has to get creative. Something like the (defunct) Java Ring[1] would allow most of the ease-of-use of RFID (possibly with a simple proximity sensor for auto-logout, if needed). [1] http://electronics.howstuffworks.com/gadgets/home/digital-jewelry3.htm http://electronics.howstuffworks.com/gadgets/home/digital-je... edit: fixed typo
- jjoonathan 11y ago> Security is hard enough without adding in the possibility of 3rd parties hearing the protoocol Asymmetric encryption is not that hard. In fact, you were using it while complaining about the problem it solves. > Garaday Faraday. > the ability to hear a transmmission often depends on the receiving antenna So even if you somehow get past the asymmetric crypto you need RF expertise and a special antenna to mount the attack from more than a foot away? And not even a special antenna beyond a few miles? I'd call that "defense in depth," not a flaw. > http://electronics.howstuffworks.com/gadgets/home/digital-jewelry3.htm http://electronics.howstuffworks.com/gadgets/home/digital-je... Just what do you think "digital jewelry" can do that a smartcard can't?
- pdkl95 11y ago> > Garady Thanks, typo fixed. > Asymmetric encryption ...doesn't protect against everything. Not letting people hear the asymmetric encryption is even better. > special antenna Cantennas are easy, and you should never underestimate the amount of technology people will throw at an attack. Consider, for example, the people that made ATM shims that captured the card data while recording the PIN being entered on the keypad. > "defense in depth" Defense in depth would be using cryto while requiring a physical connection. > smartcard A smartcard is fine - my argument is against RFID. A card that requires an electrical or inductive connection isn't going to leak everything over the radio. My suggestion of "digital jewelry" is merely an example of how the form of the smartcard is flexible. Creativity in this area could allow for some easier to use devices, which could be important in places like hospitals.
- jjoonathan 11y ago> > Asymmetric encryption > ...doesn't protect against everything. But it does protect against the exact threat model you proposed. > Defense in depth would be using cryto while requiring a physical connection. > Consider, for example, the people that made ATM shims that captured the card data while recording the PIN being entered on the keypad. How about you consider it? Building a facade to intercept physical communications is very much on par with building increasingly large, awkward, and expensive antennas in terms of difficulty barriers (especially if you need enough polish to blend in). I'm a ham, I would know. I'm not sure why you are so insistent on drawing the line between these two particular techniques. > A card that requires an electrical or inductive connection isn't going to leak everything over the radio. Are you familiar with the distinction between near-field and far-field? Because both RFID and smartcards span that distinction while you just tried to draw a line down the middle. > A smartcard is fine - my argument is against RFID. Many (most?) smartcards communicate over RF. Your argument (and my rebuttal) was about > Adding radio as a primary component in a security system not the RFID technology in particular. So do you or don't you think RF communication in a security device is an inherent problem in and of itself?
- pdkl95 11y ago
- epistasis 11y agoPretty sure he got downvoted because of this canard: >If you don't you end up with bad passwords. This is a terrible fallacy that has brought so much pain on the world. The rate of bad passwords is probably not so different, but the rate of frustration is so much higher.
- unprepare 11y agoWere these regulations created at a time when brute force password cracking was a legitimate concern? Password policies do definitely raise the entropy of the passwords, so if the attack vector you're concerned about is entropy sensitive, its a decent strategy. As someone who has had to enforce such password policies many times, I can say that it's almost always because of some regulatory or certification organization that requires complex policies.