You're riding the subway to work,Roman Perez Jr. Archives or taking a smoke break outside the office, or simply strolling down the street. Someone with a backpack is standing nearby, but you think nothing of it.
Thirty seconds later that very same someone has a cloned hard copy of your work ID badge, ready to stroll right into your office.
SEE ALSO: Meet the cyborg bringing biohacking to the peopleThis is not only possible, but "very simple" according to security researcher Dennis Maldonado. Maldonado, the founder of Houston Area Hackers Anonymous and an Adversarial Engineer at pen-testing company Lares Consulting, was speaking to a packed house of hackers at the 25th annual DEF CON in Las Vegas on Thursday.
"In seconds you steal someone's badge, have a complete copy, and you walk into the building."
And they were very receptive.
"I'm going to assume everyone here is legit — is a pen tester, not a black hat," Maldonado said to laughs as he showed off a custom system he built to remotely copy and clone RFID tags.
While you may not know what an RFID tag is, chances are you've used one. You may even have one in your pocket right now. Put simply, radio-frequency identification (RFID) is a means of using electromagnetic waves to track and identify specific tags. The tags are frequently embedded in company ID cards, and employees — especially in the tech industry — have become accustomed to tapping those cards against readers to unlock office doors.
They're digital keys, albeit keys that are extremely easy to copy — even from a distance.
Maldonado proceeded to demonstrate a rig that would allow an attacker to remotely scan a card, from a distance of approximately 2 feet, and then send that data to a cloning machine (up to 30 feet away) which would then automatically write the card.
He even made the setup user friendly, developing an Android app that syncs to a Pebble watch and notifies him via chime if his read on the target card was good. And, because standing two feet away from someone is a normal thing to do in elevators and subway cars, the victim would presumably never be the wiser.
"You don't have to go up to someone and touch their butt to get a card read," he noted — shortly before observing out loud that someone was trying to break into his network mid-talk (it's that kind of conference).
This Tweet is currently unavailable. It might be loading or has been removed.
The basic technology he used is readily available for purchase on eBay, and he told the crowd that he had already posted his code to GitHub. If you don't want to throw down the cash? Well, Maldonado pointed out that the remote RFID-scanning tech is all around us, like in parking garages, but he cautioned the hackers in attendance: "Don't go stealing those."
Which, well, that may have been the only part of his talk the crowd didn't seem too interested in hearing.
"In seconds you steal someone's badge, have a complete copy, and you walk into the building," he told those gathered. For the attendees of DEF CON, Maldonado's statement may have sounded like a challenge. For anyone who uses an RFID tag to badge into their office or home? They should take it as a warning.
Topics Cybersecurity
NYT Strands hints, answers for January 10Tesla launched the new Model Y in China. Here's what you need to knowWordle today: The answer and hints for January 10, 2025Keys vs. Samsonova 2025 livestream: Watch Adelaide International for freeCES 2025: Meet AutoKeybo, the transforming keyboardX announces labels for parody accountsGet Peacock Premium for free with Instacart+Best iPad deal: Save $70 on 10th Gen Apple iPadLos Angeles wildfires: How to check the air quality near youHelp, I can't stop thinking about Suzie Toot's 'Woman's World' lip syncCES 2025: Evenflo's SensorySoothe smart car seat is a oneLos Angeles wildfires: How to check the air quality near youBest robot vacuum deal: Save over $100 on iRobot Roomba Q0120How to unblock XVideos for freeMeta, Zuckerberg threaten human rights by allowing dehumanizing speech, advocates warnHelp, I can't stop thinking about Suzie Toot's 'Woman's World' lip syncBest iPad deal: Save $70 on 10th Gen Apple iPadNYT Connections hints and answers for January 10: Tips to solve 'Connections' #579.Get Peacock Premium for free with Instacart+CES 2025: The Plantaform smart indoor garden grows plants with fog Airbnb files lawsuit against New York About 100,000 devices helped take down the internet via a cyberattack Instagram may be experimenting with live video in Stories A look at the 'League of Legends' Worlds semifinals match 'Overwatch' player lands a double kill while using a bow for a controller Scarlett Johansson's next business venture is a foray into gourmet popcorn What Ted Cruz fails to understand about Colin Kaepernick Hillary Clinton delivered these 18 zingers to Donald Trump's face Here's President Obama dancing to Drake's 'Hotline Bling' Oprah has a strong message for undecided voters Facebook has apologised for removing this cancer awareness video 10 ‘Civilization VI’ beginner tips to help you rule the world Internet of Things gets its zombie apocalypse, and this is just the beginning Dad's security camera captures young son's overnight couch Snapchat shows frontlines of battle for Mosul as it deepens a role in breaking news The entire internet is struggling after massive outage Duterte hating on the U.S. has inspired a Spam meme in the Philippines Donald Glover to play Lando Calrissian in 'Han Solo' movie Line joins in the Snapchat game with posts that only last 24 hours Google wants to take over your wallpaper, just like everything else on your phone
1.4171s , 10135.015625 kb
Copyright © 2025 Powered by 【Roman Perez Jr. Archives】,Wisdom Convergence Information Network