39 ms·
Does RFID allow for encryption? I'd thought they were too constrained re: power and cpu.
by pronoiac 3y ago
Does RFID allow for encryption? I'd thought they were too constrained re: power and cpu.
- bennettnate5 3y agoYour contactless credit card uses RFID; I sure hope it would use encryption :)
- kevin_thibedeau 3y agoIt operates at a close distance to the reader and can collect more energy to run its electronics.
- bennettnate5 3y agoThis is a good point--my understanding is that it also takes a little longer to run than simple value-store RFID tags do (second(s) instead of milliseconds). Pressure sensors in tires might be far enough removed from the corresponding reader that encryption is not feasible for the RFID chip.
- SoftTalker 3y agoI thought contactless payment was less secure than chip. With a chip reader, the POS terminal powers the chip on the card to do encryption on the card. The POS terminal cannot access the private key on the card. Contactless is much lower power, and basically reads a one-time code for the transaction, and the card does not perform any encryption. Is that incorrect?
- deleted 3y ago[deleted]
- jeffbee 3y agoThat is not correct. Contactless cards can gather enough power from the terminal to operate a full-blown smart card.
- slau 3y agoIt is my understanding this is incorrect. Whether chip or NFC is used, the private key is still used to perform a challenge-response signature for the transaction (ARQC/ARPC and SDAD)
- auguzanellato 3y agoIt’s the exact same protocol (EMV), just using a different transport layer (ISO 7816 for contact vs ISO 14443 for contactless). It’s basically the same thing as IP traffic that can be transported over an Ethernet cable or over Wi-Fi.
- rcxdude 3y agoA surprising amount of encryption is optional in EMV (the underlying protocol for contactless and chip cards), because when it was originally developed (way before contactless was a thing), vanks were worried about the price of a chip capable of doing all the encryption. It's a source of all kinds of attacks on the protocol (though I don't know how bad it is now). For example, it's not at all uncommon for the reader to send your PIN to the chip in the clear, whoch makes skimming with a modified reader pretty easy (in general the readers have a lot of anti-tamper mechanisms, but they're designed to protect the operator's cryptographic keys, not the security of the card holder)
- SkyPuncher 3y agoEven if it doesn’t, the values are finite. Tire pressures and temperatures have expected operating ranges and precision limitations. You could very easily pre-hash the values. It’s not cryptographically secure, but secure enough to prevent your opponent from figuring it out during the race.