6 ms·
It's not limited to NFC (email or website can be used as attack vectors), but the researchers apparently decided to show off the NFC method as it's a relatively
by Empro 14y ago
It's not limited to NFC (email or website can be used as attack vectors), but the researchers apparently decided to show off the NFC method as it's a relatively new medium for malware (though of course not a very practical one).
- rat87 14y ago> the NFC method as it's a relatively new medium for malware (though of course not a very practical one). Why not? Ever since I heard of the idea of trying to replace QR codes with passive always on NFC I've thought that this will be one of the first methods for massive infections of smartphones. Just put one in a public place(public transportation, store, etc.)
- gwillen 14y agoI doubt it -- the range of NFC seems to be very bad. Unless the malware can turn up the gain, you have to hold the phones back-to-back within about a centimeter of each other.
- ryanhuff 14y agoIs this true? My understanding is that the range issue of NFC has more to do with the non-powered nature of NFC chip, thus having very limited broadcasting range. If I had a powered device that broadcasted NFC responses over a much greater range, wouldn't the phone happily accepting this as an NFC chip response?
- jerf 14y agoIt's just a feature of this particular hack that it was two phones. The real-world manifestation would probably be an NFC skimmer, like ATM skimmers [1]. Slam the virus in, then proxy the original request (or vice versa, depends on the timing), use the network on the phone to connect to the malware hub control, owned phone. Note you only have to slam a shim in; the shim can then download an arbitrary payload. [1]: http://krebsonsecurity.com/2012/07/atm-skimmers-get-wafer-thin/ http://krebsonsecurity.com/2012/07/atm-skimmers-get-wafer-th...
- Unoeufisenough 14y agoThe vector is the same as for QR codes, paste a different tag overtop of a legitimate tag that takes the user to a URI with a browser or other application exploit. Or physical world version of phishing. Again it is the application that is the root of the vulnerability. NFC would be no worse than a QR code or even a malicious URL printed in plain english on a poster. The only unique theoretical option would be to hack a very highpowered antenna and transmitter to try and pick up blast out RFID-compatible signals to/from the very weak NFC radios of handsets from further away.
- gcb 14y agoNo, a qr tag can't replicate itself on infected devices. A nfc phone can. Even if the range is small, it can send it's payload everyone you were trying to use it intentionally.
- noselasd 14y agoPeople have been hacking ATMs for years by installing gear on those ATMs. With NFC, such skimming might be much easier, as the gear you need to install can be _tiny_, and you only need to be in the vicinity of the target, making it easier to camouflage. And attacks doesn't need to come from cots phones, with your own higher gain NFC device, you can interact with with ordinary NFC devices from greater distances.
- headShrinker 14y agoor maybe you could embed your hack in on of these ads. http://nfctimes.com/sites/default/files/imagecache/poster/nfc_vh1_bbwives_nyc-proxama-crop-2.jpg http://nfctimes.com/sites/default/files/imagecache/poster/nf...
- cbsmith 14y agoI think NFC is a far less interesting attack vector simply because I'd expect NFC links to be with at least somewhat trusted partners.
- ConstantineXVI 14y agoNot only is it low-range (~2" in my experience), at least in Android the phone has to be on+unlocked before NFC is on. The only realistic route for this attack is a compromised NFC device (such as a payment terminal) that your victim would be using anyway. For that sort of effort, compromising a Wi-Fi hotspot would likely be more effective in terms of reach.