[01:11.580 --> 01:12.960] Hello again, everyone. [01:13.820 --> 01:16.310] Second to the last talk for track three for the night. [01:16.590 --> 01:18.140] So super excited for this next one. [01:18.540 --> 01:24.800] As you most of you have already been through before, house business, mass, thank you for wearing them, keep wearing them, great. [01:25.160 --> 01:30.540] Stay hydrated, mute your phone, super sensitive audio, sign up for fourth unscheduled track. [01:30.800 --> 01:35.560] If you want to try and sign up and present something tomorrow or Sunday, go to the information desk. [01:35.760 --> 01:39.500] They'll help you schedule some time and get you set up in the coffee house to present. [01:40.300 --> 01:41.780] Karaoke tonight at 10 o'clock. [01:42.600 --> 01:46.060] Upstairs, track one, DAC 416. [01:46.060 --> 01:49.650] At the end, the big auditorium. [01:50.500 --> 01:53.580] Volunteers, if you want to volunteer, talk to the info desk or security. [01:53.760 --> 01:55.120] We can always use more volunteer help. [01:55.800 --> 02:01.740] And late-night content begins at 9:30 in half an hour, which you might, oh, you'll just make, right? [02:01.880 --> 02:02.020] Nope. [02:02.360 --> 02:03.650] You're going to miss the first part of it. [02:04.040 --> 02:08.660] So if you can and you're interested, go up and see it in room 406, fourth floor of the video room. [02:09.000 --> 02:11.990] And with that, next talk is Just Enough R.I.D. [02:12.060 --> 02:13.800] Cloning to be Dangerous with Gabe Schuyler. [02:13.940 --> 02:15.040] So take it away, Gabe. [02:15.180 --> 02:15.660] Thank you. [02:15.900 --> 02:16.440] All right. [02:17.400 --> 02:18.120] Here we go. [02:20.280 --> 02:23.210] Thank you diehards for sticking around. [02:24.380 --> 02:24.560] All right. [02:24.720 --> 02:28.220] Let's add to the delinquency of some mostly majors, I hope. [02:29.320 --> 02:30.060] All right. [02:30.600 --> 02:32.300] So this is my talk. [02:32.490 --> 02:34.650] Enough RFID cloning to be dangerous. [02:35.710 --> 02:42.560] The point here is really that I had kind of a need and I needed to clone a tag. [02:42.560 --> 02:45.080] And so I figured it out. [02:45.460 --> 02:47.540] And it's not that scary, really. [02:47.640 --> 02:55.800] The upshot of the whole thing is that we all, as, you know, elite hackers, we know that tags are real easy to copy. [02:56.180 --> 02:58.440] But, like, can you actually do it? [02:58.560 --> 02:59.280] I don't know. [03:00.160 --> 03:05.060] So I'm going to give you enough to know that you actually can pretty much copy most things. [03:06.080 --> 03:12.140] I mean, there's some cool stuff you can't, but it's also really cool to tell your friends, hey, maybe I can copy that. [03:12.280 --> 03:13.640] Oh, awesome. [03:13.820 --> 03:14.880] You have really good security. [03:16.920 --> 03:20.500] So here's me in a bit of a nutshell. [03:21.200 --> 03:23.320] I do hail from Austin, Texas. [03:23.800 --> 03:24.380] Yippee-ki-yay. [03:25.580 --> 03:27.360] I've been in ops forever. [03:28.080 --> 03:28.640] Ages. [03:29.380 --> 03:31.520] And I'm pretty new to cyber security. [03:31.780 --> 03:37.200] So I've been hacking for a long time, but I'm actually officially in cyber security now. [03:37.900 --> 03:43.840] On my spare time, I like to go running, but I also like tinkering with junk. [03:44.640 --> 03:46.780] Picking locks, I'm not that good at it. [03:47.640 --> 03:51.500] And I really do think that our technology should be used for social change. [03:51.860 --> 03:58.020] And I think that's the really wonderful thing about this conference is that I think that's what we're all here for. [03:58.840 --> 04:00.240] So let's get into it. [04:02.220 --> 04:04.000] Here's how I got here. [04:06.770 --> 04:08.360] I ride a motorcycle. [04:09.680 --> 04:13.980] My building requires an RFID tag to get into the garage. [04:15.180 --> 04:16.530] Not easy with a motorcycle. [04:16.980 --> 04:19.860] What I was doing was I had my hands in gloves. [04:19.880 --> 04:22.180] I was stopping halfway from the door. [04:22.360 --> 04:23.410] I was taking off one glove. [04:23.560 --> 04:27.170] I was fishing out this key, the blue guy there. [04:28.260 --> 04:32.800] Stuffing it in the other glove, hoping that it would stay there, put on the first glove. [04:33.600 --> 04:34.820] You need both hands. [04:35.100 --> 04:36.910] Clutch is on one side, throttle is on the other. [04:37.580 --> 04:40.120] And then, of course, I'm worrying that it's going to fall out. [04:40.480 --> 04:42.910] And then I'm sort of waving the thing at the reader. [04:43.530 --> 04:53.170] So this is how I got here, was that I had a real mother of invention, which was the necessity of I'm really tired of trying to do this. [04:54.970 --> 05:02.320] The other thing that I realized while I was putting together this talk is that I've actually been really interested in this stuff for quite a while. [05:02.920 --> 05:06.040] My work takes me to a bunch of places. [05:06.410 --> 05:16.320] And for years now, I've been writing down the date, how many days, the room number that I was staying in on all of my hotel keys. [05:16.880 --> 05:20.000] Because I figured, you know, someday I'm going to figure out how those things work. [05:21.920 --> 05:23.180] And here we are. [05:23.620 --> 05:28.440] But it was really the motorcycle glove problem that was the thing that got me to do it. [05:29.600 --> 05:32.040] And what's fun is they're two different technologies. [05:36.640 --> 05:39.240] Here's the basics of passive RFID. [05:39.240 --> 05:46.320] So tags to get into a building or get into a garage or get into your hotel room are using passive RFID. [05:46.700 --> 05:53.840] The device itself, the card, the tag, the key fob, whatever it is, doesn't have a battery in it. [05:53.900 --> 05:55.840] So it needs to power itself somehow. [05:57.380 --> 06:10.720] And the simplest metaphor that I found for this is that it's similar to, imagine you have, I have a flashlight or I'm operating a lighthouse. [06:11.880 --> 06:13.440] And there is a ship out there. [06:13.760 --> 06:21.400] And so I can blink a flashlight at a regular period or I can send Morse code out to the ship. [06:21.480 --> 06:24.800] But I want to be able to tell what the ship is saying back to me. [06:25.900 --> 06:30.140] Well, as long as somebody on the ship has a mirror, they don't need energy. [06:30.860 --> 06:33.720] I mean, avoiding the muscle and all that kind of stuff. [06:33.720 --> 06:35.960] We're all hackers, so we'll poke a million holes in that. [06:36.500 --> 06:45.400] But supposing that I don't have all those problems, all I really need is a mirror to reply. [06:45.980 --> 06:58.940] So the lighthouse can say, hey, boop, boop, ba-doop, ba-doop, ba-doop, ba-doop, ba-doop, and then as long as it gives me a pulse that's regular, now I can choose whether to show the mirror or not to return a message. [06:58.940 --> 07:05.460] So as long as it's just saying boop, boop, boop, boop, I can say on, off, off, on, off, on, off, on, on. [07:06.100 --> 07:11.100] So that's how passive RFID works in the simplest of metaphors. [07:11.700 --> 07:17.700] It just bounces back the energy provided by the reader to communicate back. [07:20.220 --> 07:23.700] There are two major frequencies for access keys. [07:24.900 --> 07:27.280] For my garage, which happens to be low frequency. [07:28.320 --> 07:30.940] And your hotel keys, which are high frequency. [07:32.360 --> 07:35.240] They speak on different frequencies. [07:35.860 --> 07:37.380] 125 kilohertz, pretty low. [07:38.000 --> 07:39.180] 13 megahertz, pretty high. [07:39.980 --> 07:44.680] And what you'll find is that the lower frequency ones are the dumb ones. [07:45.400 --> 07:48.540] Lucky for me that was my garage door, was that it was dumb. [07:49.320 --> 07:51.020] The high frequency ones are smarter. [07:51.540 --> 07:53.620] They can actually do some math. [07:53.880 --> 07:58.300] They can actually deal with cryptography, things like that. [08:02.150 --> 08:07.190] So here's a broad characterization of what I've found about the low frequency ones. [08:07.190 --> 08:09.750] Now, I'm just a person. [08:10.370 --> 08:11.330] Just this guy. [08:12.250 --> 08:16.550] And so there are plenty of talks about the real details of this stuff. [08:16.730 --> 08:21.410] But in a broad generalization, low frequency are these door keys. [08:21.710 --> 08:23.450] That happens to be mine right there. [08:23.570 --> 08:28.170] The blue one that I had to do with the garage door. [08:28.310 --> 08:29.350] I actually have it right there. [08:31.150 --> 08:33.130] All it really does is it just replies. [08:33.430 --> 08:36.150] It just says, hey, I am this serial number. [08:37.550 --> 08:39.510] The readers really just read the darn thing. [08:39.890 --> 08:42.050] They just say, hey, who are you? [08:42.190 --> 08:43.330] And it says, here's who I am. [08:45.430 --> 08:47.510] Similar to a barcode or a mag stripe. [08:48.450 --> 08:53.170] All it does is just returns what its serial number is. [08:53.770 --> 08:56.990] Similar to a physical key. [08:57.370 --> 08:59.650] Just returns what its pinning is. [09:00.230 --> 09:01.330] It's very similar. [09:02.210 --> 09:07.330] What I've found, which is interesting, is that they are harder to block by those RFID blockers. [09:08.170 --> 09:11.630] And I'm going to actually show that in a little bit. [09:13.930 --> 09:16.490] Here's the high frequency, higher energy. [09:17.970 --> 09:19.790] These cards can actually do some math. [09:20.650 --> 09:23.030] So they can actually do cryptographic routines. [09:24.290 --> 09:25.830] They're fairly smart. [09:26.630 --> 09:31.750] They also, in my experience, I've seen that they have some memory on there. [09:31.810 --> 09:33.430] So the reader can actually update that. [09:33.770 --> 09:39.590] So whereas the low frequency is saying, hey, here's just my name and my number. [09:39.590 --> 09:49.070] However, the actual high frequency reader can actually say to the card, hey, I want you to have this rolling code for the next time I read you. [09:51.550 --> 09:54.690] Kind of a very, very simple system on a chip. [09:55.610 --> 10:04.250] And what I've got here on the picture, actually, is the hotel I stayed in about a month ago had... [10:04.250 --> 10:07.370] They were kind enough to provide a key that was see-through. [10:07.870 --> 10:09.350] And what you can see is a chip. [10:09.970 --> 10:13.910] And then the coil that inducts the energy. [10:14.910 --> 10:17.410] So it looks a lot like a credit card, doesn't it? [10:17.910 --> 10:18.490] It's similar. [10:19.530 --> 10:21.030] So these are the smart ones. [10:21.450 --> 10:26.870] They are easier to block with your RFID wallets or whatever the heck you have. [10:31.070 --> 10:31.550] Chips. [10:32.170 --> 10:33.850] Every card has a chip. [10:34.430 --> 10:37.110] So it's not just the loop for the radio. [10:37.550 --> 10:39.290] It's also got to do something. [10:39.510 --> 10:40.490] Something has to reply. [10:40.710 --> 10:42.070] And so they all have chips. [10:42.350 --> 10:46.050] And so you'll need to figure out which chip yours has. [10:48.230 --> 10:57.930] 10 will get you 20 that if you've got a low frequency RFID tag, it can be emulated by what's called a T55 chip. [10:59.090 --> 11:03.810] And these are really, really easy to pick up. [11:03.930 --> 11:06.570] You can get like a dozen of them for like $5. [11:08.050 --> 11:10.550] The high frequencies are a little sneakier. [11:12.130 --> 11:15.990] But they seem to have pretty standards. [11:16.390 --> 11:19.510] Either a HID iClass or a MyFair Classic. [11:20.010 --> 11:23.250] Most of your hotel keys are a MyFair Classic. [11:25.530 --> 11:30.490] And your tools, the tools that you use for your RFID, they're going to tell you. [11:30.710 --> 11:32.570] They're going to figure out what the chipset is for you. [11:32.790 --> 11:39.010] Because plenty of people, amazing people, have gone before us and have decided to make this easy for people. [11:39.250 --> 11:41.450] Made it easy for themselves and then open sourced it. [11:45.550 --> 11:51.950] Beyond chips, chips are just the frequency is then enabling the chip to talk. [11:52.290 --> 12:00.610] And then similar to the OSI model, then there has to be a data format for what's being exchanged between the reader and the card. [12:01.550 --> 12:04.090] And so you'll need to know the data format. [12:05.330 --> 12:10.250] The big one that I've been finding is HID actually was the one that was for my garage store. [12:11.390 --> 12:13.710] And these are really just a data format. [12:14.150 --> 12:17.330] So that when the card replies, here's my name. [12:17.610 --> 12:19.650] Or when the card replies, hey, what do you want me to do? [12:20.270 --> 12:21.590] You're speaking the same language. [12:27.690 --> 12:29.930] Cards come in all sorts of form factors. [12:31.170 --> 12:34.790] I guess I should say tags come in all sorts of form factors. [12:35.770 --> 12:44.290] And pretty much anything that you can fit a chip into with a coil can be a card, can be a tag. [12:44.790 --> 12:47.210] So here I've got some examples. [12:47.690 --> 12:49.110] I've got my hotel key. [12:49.490 --> 12:50.670] I've got another key. [12:51.470 --> 12:57.150] That card is actually, I think, just like a normal access key for a building. [12:58.230 --> 13:03.310] You can inject these things, which is actually not that new of an idea. [13:04.010 --> 13:07.850] People have been injecting these into their pets for quite a while. [13:08.330 --> 13:09.410] Same technology. [13:10.390 --> 13:12.110] It's just a chip with a coil. [13:12.310 --> 13:16.330] It happens to be a really small one, which happens to be difficult to find sometimes. [13:16.590 --> 13:19.870] But it's really just a chip with a very small coil. [13:21.810 --> 13:32.950] When I was trying to solve my problem of the motorcycle rider who doesn't want to have to figure out where the heck his key is, I actually was... [13:32.950 --> 13:35.430] I was not going to inject it. [13:35.550 --> 13:36.490] I'm seeing some looks. [13:36.690 --> 13:37.250] I was not. [13:37.370 --> 13:38.130] I was actually... [13:38.130 --> 13:40.370] But I was going to get an injectable tag because they're tiny. [13:40.530 --> 13:42.370] They're like a piece of long grain rice. [13:42.370 --> 13:46.730] And I was actually going to, like, super glue it or sew it to my gloves. [13:47.430 --> 13:48.690] And it would have worked. [13:48.930 --> 13:50.030] Would have worked just fine. [13:51.630 --> 13:53.030] Ended up not doing that in the end. [13:54.390 --> 13:57.410] But all sorts of form factors for this stuff. [13:57.890 --> 13:59.550] Stickers are kind of one of my favorites. [14:00.450 --> 14:01.490] They're sort of fun. [14:02.530 --> 14:07.510] NFC is an RFID technology, and obviously you can get stickers for that. [14:07.510 --> 14:08.730] I think everybody's seen those. [14:11.450 --> 14:12.570] So what do you do? [14:12.690 --> 14:13.370] Here I was. [14:13.710 --> 14:16.910] I knew that I had my little blue key. [14:17.390 --> 14:18.970] I knew that I wanted to do something. [14:19.110 --> 14:21.570] I thought I was going to do an injectable and then sew it onto something. [14:22.470 --> 14:23.370] So what do you do? [14:23.450 --> 14:24.710] How do you copy these darn things? [14:25.010 --> 14:26.370] So I started to do some research. [14:29.530 --> 14:30.750] Here's where I started out. [14:32.570 --> 14:37.510] You can get copiers for basically any format. [14:38.130 --> 14:41.210] If you know what kind of chip you want to copy something onto. [14:41.570 --> 14:42.970] And you know what format. [14:43.770 --> 14:45.990] You can just buy something. [14:46.570 --> 14:48.390] This thing, this little blue thing. [14:49.150 --> 14:52.110] Cloner of Doom because it sets a password on the darn thing. [14:53.630 --> 14:55.190] This little thing was like ten bucks. [14:55.590 --> 14:58.430] And it came with like five free tags to write to. [15:00.370 --> 15:01.510] Super, super simple. [15:01.510 --> 15:09.890] So I guess the moral of that story is if you just want to copy this stupid thing onto some other stupid thing, ten bucks will do it. [15:10.310 --> 15:14.230] You can even get it shipped from the United States and it gets there in like four days. [15:14.490 --> 15:16.170] And it has spare tags. [15:17.730 --> 15:19.190] So super, super doable. [15:19.730 --> 15:20.770] But we're all hackers. [15:20.950 --> 15:23.070] So we want to do more than that. [15:23.190 --> 15:24.150] We aren't happy with that. [15:25.450 --> 15:29.790] There are also tools that will copy numerous formats. [15:30.950 --> 15:32.070] iCopyX is one of them. [15:33.710 --> 15:35.750] Pretty darn closed systems. [15:36.050 --> 15:37.490] But they can copy lots of stuff. [15:37.650 --> 15:39.090] And they have a little display and it's great. [15:39.690 --> 15:40.930] They cost a bunch of money. [15:41.730 --> 15:42.690] Three, four hundred dollars. [15:44.210 --> 15:54.450] So where you end up if you end up in the rabbit hole, which I inevitably did, where you end up is going with something like the Proxmark. [15:55.630 --> 16:00.890] If there is one thing you're going to write down today, Proxmark 3 is the thing. [16:01.230 --> 16:02.270] It's open source. [16:03.690 --> 16:08.210] And it's really a Swiss army knife for RFID hacking. [16:08.950 --> 16:13.730] It has a low frequency and it has a high frequency antenna on it. [16:15.370 --> 16:19.350] And the firmware is actively maintained. [16:19.830 --> 16:23.530] The software that you run on your system is actively maintained. [16:23.730 --> 16:25.650] It can run in a standalone mode. [16:26.010 --> 16:28.090] But it's really where you want to end up. [16:28.630 --> 16:32.410] What I ended up with is what's called the Proxmark 3 Easy. [16:33.890 --> 16:34.970] Totally open source. [16:35.170 --> 16:36.130] It's like 50 bucks. [16:37.230 --> 16:45.430] If you're going to dive into this stuff, get the version that has 512 megs of space for the flash. [16:47.490 --> 16:50.050] Some of the firmware images are starting to get pretty big. [16:51.010 --> 16:52.430] Which is interesting. [16:52.710 --> 16:57.090] I'm going to go to that demo scene thing because I like things small. [16:57.350 --> 16:59.530] But hey, if you got it, you can use it. [16:59.970 --> 17:01.710] The 512 is what you want to get. [17:02.510 --> 17:04.530] And they're really pretty cool. [17:06.390 --> 17:11.930] If you're trying to copy low frequency tags, make sure you get rewritable ones. [17:13.550 --> 17:17.030] The difference is like $0.35 instead of $0.25. [17:17.630 --> 17:25.250] There are plenty of places that sell tags that just have a serial number on them. [17:25.250 --> 17:32.090] And if you're a building person and you want to program your building to open things, not a big deal. [17:32.510 --> 17:34.670] You just tell the central system, I have a new tag. [17:34.670 --> 17:35.850] It goes for this apartment. [17:35.850 --> 17:38.330] They can get onto the 10th floor or whatever. [17:39.770 --> 17:43.050] So there are plenty of non-rewritable ones. [17:43.170 --> 17:44.550] Make sure you get rewritable ones. [17:46.050 --> 17:54.950] In the high frequency world, if you're going to be copying your hotel keys or your fancier access keys, you want to get what are called magic keys. [17:56.630 --> 18:02.970] Every key in the high frequency world, I'll get into this a little bit more in a minute, has a unique identifier. [18:03.290 --> 18:08.170] And you need to be able to rewrite that in order to do some really fun stuff. [18:09.130 --> 18:13.250] So those are my two notes for you so that you save a little money. [18:13.570 --> 18:16.030] On the low frequency, you're saving yourself a dollar. [18:16.490 --> 18:22.530] But the magic ones, Chinese, sometimes they call them for the high frequency or what you want to get. [18:25.580 --> 18:26.240] All right. [18:27.520 --> 18:28.800] Let's look at my problem. [18:29.720 --> 18:31.180] A little self-centered, sorry. [18:32.680 --> 18:34.920] So what I had was this blue thing. [18:35.440 --> 18:37.460] And I wanted to copy it onto something. [18:37.600 --> 18:38.240] It was low frequency. [18:39.280 --> 18:42.860] And I'll show you live in a minute how to do this. [18:43.040 --> 18:46.360] But these things have just two pieces of data on them. [18:46.680 --> 18:52.500] They have a facility code, which is basically what building they're allowed into. [18:52.720 --> 18:54.200] And then a card number. [18:54.720 --> 18:56.820] And that's pretty much just a serial number. [18:57.020 --> 18:59.200] And these really are like physical keys. [18:59.200 --> 19:01.260] It's really just basically like a pinning. [19:01.460 --> 19:02.940] It's just numbers. [19:03.420 --> 19:05.400] And then the reader just kind of goes, okay. [19:07.400 --> 19:09.420] And they're super easy to clone. [19:10.140 --> 19:14.640] That's what I found out really much to my serious amusement. [19:15.860 --> 19:21.000] And then much to my friends' amusement until they were not amused anymore as I copied all their stuff. [19:23.060 --> 19:25.060] But I didn't save any of it. [19:25.220 --> 19:27.520] It was really just like, hey, can I try to copy your key? [19:27.820 --> 19:29.240] And they were like, yeah. [19:29.840 --> 19:31.080] And I was like, I'm not going to save it. [19:31.140 --> 19:33.700] You just have to promise to tell me if it works or not. [19:33.700 --> 19:38.900] And then like next week when I saw them, they were like, oh, it works. [19:41.980 --> 19:45.200] The hotel room keys, these are high frequency. [19:46.960 --> 19:53.600] What you need to know is the unique identifier of the key because all the data that's encrypted is based on the unique identifier. [19:53.880 --> 19:55.920] Kind of like a salt near as I can tell. [19:56.580 --> 19:58.320] Again, not total expert. [19:58.480 --> 20:02.000] There are some really crazy experts and I hope none of you are in the audience. [20:03.600 --> 20:08.500] Although during the Q&A, you're welcome to come up and just rush the mic. [20:10.700 --> 20:16.720] And then you'll be dumping out the binary data from these things and then breaking the encryption. [20:18.140 --> 20:26.160] These things suffer from the same problem that we see all the time, which is don't invent your own encryption. [20:26.460 --> 20:27.720] What the heck are you thinking? [20:28.760 --> 20:29.500] But they do. [20:29.800 --> 20:30.620] So there are some attacks. [20:31.520 --> 20:33.520] And then you'll be writing it. [20:35.100 --> 20:47.240] Now, here was the fun thing for me leading up to this talk was I was like, well, I got 50 minutes and usually I can do this in 20 minutes. [20:49.500 --> 20:52.040] So let's get some RFID blockers. [20:52.180 --> 20:53.200] I'll try these a little bit later. [20:53.320 --> 20:54.660] I've got some paper ones. [20:55.320 --> 20:58.960] I've got, oh, these are active ones. [20:59.880 --> 21:03.080] I've got, oh, here are just cards. [21:05.060 --> 21:08.260] TSA had a really fun time when this thing went through. [21:12.540 --> 21:14.460] So RFID blockers. [21:14.920 --> 21:16.620] There are plenty of those out there. [21:17.920 --> 21:24.700] And the Amazon reviews usually are like, I don't know if it works, but it fits in my wallet. [21:24.900 --> 21:25.220] It's cool. [21:26.300 --> 21:27.900] I'm not even kidding. [21:28.120 --> 21:28.540] It's hilarious. [21:29.940 --> 21:30.820] Really hilarious. [21:32.860 --> 21:33.720] Or scary. [21:33.840 --> 21:34.240] I don't know. [21:34.460 --> 21:35.600] I'm just going to go with LOL. [21:38.220 --> 21:40.540] There are a few different types. [21:42.180 --> 21:44.640] And one of them is these paper guys. [21:45.980 --> 21:48.000] It's just like a sleeve. [21:48.880 --> 21:49.920] Paper sleeve. [21:50.400 --> 21:54.160] And you just stick your card in there and then it's safe from the elite haxers. [21:56.700 --> 22:01.100] I also brought RFID blocking fabric. [22:01.600 --> 22:02.320] Pretty cool. [22:02.620 --> 22:05.260] You could totally make a tin foil hat out of this. [22:05.460 --> 22:05.820] It's great. [22:06.400 --> 22:07.340] Buy it by the yard. [22:07.580 --> 22:09.320] So we'll figure out if this one works. [22:11.080 --> 22:11.880] I have... [22:11.880 --> 22:12.980] Oh, I have a little pouch. [22:13.620 --> 22:16.100] This is for your car key fob. [22:18.000 --> 22:18.400] Theoretically. [22:18.860 --> 22:23.680] So that nobody can do like a replayer person in the middle attack. [22:24.000 --> 22:24.900] So we'll try that guy. [22:26.280 --> 22:27.080] And then... [22:27.080 --> 22:28.260] Oh, and then I have these. [22:28.720 --> 22:31.940] Oh, also, by the way, I don't want to go home with any of this junk. [22:32.140 --> 22:33.400] It weighs... [22:33.400 --> 22:37.020] So when we're done, everybody just come and grab some of this junk. [22:37.020 --> 22:39.720] Um, and then I've got these active ones. [22:39.880 --> 22:41.120] Now, these are really cool. [22:41.900 --> 22:44.300] Um, so we'll try these out. [22:45.040 --> 22:50.660] Theoretically, these are RFID cards that when they get energy, all they do is they just kind of go... [22:51.480 --> 22:54.780] Um, and block anything from reading those. [22:55.460 --> 22:57.500] So we'll try those too, as well. [23:00.360 --> 23:01.060] Let's do it. [23:01.120 --> 23:01.620] Let's try it. [23:01.860 --> 23:02.380] All right. [23:07.950 --> 23:08.350] So... [23:08.830 --> 23:10.570] What I've got here... [23:14.480 --> 23:16.000] I'm running Proxmark. [23:16.180 --> 23:16.860] I've got one here. [23:17.580 --> 23:20.200] Um, pretty simple hardware. [23:20.740 --> 23:22.840] Uh, by the way, when you... [23:22.840 --> 23:30.140] When you get one, or if you do get one, and it's like, hey, flash the firmware and all that kind of junk, there's a lot of, like, stuff to do. [23:30.140 --> 23:35.240] If you get one that's been pre-flashed, you can kind of skip a lot of that stuff. [23:35.960 --> 23:41.500] Um, and I think Kali might actually ship with the Proxmark client on it. [23:41.680 --> 23:44.080] So you don't have to go totally crazy on day one. [23:44.380 --> 23:45.860] You don't have to, like... [23:45.860 --> 23:51.740] I mean, putting an ARM GCC compiler on there and cross-compiling can be a little daunting. [23:51.740 --> 23:54.940] You can get into this stuff pretty fast without flashing anything. [23:56.180 --> 23:56.940] All right. [23:57.300 --> 23:58.280] So let's take a look. [24:00.360 --> 24:02.060] Here's my blue... [24:02.800 --> 24:05.620] My blue key that was annoying the heck out of me. [24:06.500 --> 24:07.900] Let me put it on here. [24:07.900 --> 24:14.660] And all I have to do is tell Proxmark to search for a low frequency tag. [24:18.760 --> 24:19.600] All right. [24:19.920 --> 24:20.780] Demo gals love me. [24:21.620 --> 24:23.520] So what you're looking at here... [24:23.520 --> 24:26.060] Um, not my true codes. [24:26.780 --> 24:30.820] Uh, although it'll really only get you up to the pool and you're welcome to go to my swimming pool. [24:31.520 --> 24:34.400] Um, what you got here is a facility code. [24:35.700 --> 24:36.220] 206. [24:36.560 --> 24:38.400] Uh, and then a card number. [24:38.940 --> 24:40.520] Um, that's kind of cool. [24:40.640 --> 24:41.480] It's like a 404. [24:42.680 --> 24:43.480] Uh, and... [24:44.380 --> 24:46.720] It's telling me the data format is hid. [24:48.580 --> 24:50.220] So I kind of know what I'm doing there. [24:50.560 --> 24:53.980] And then it tells me that there's actually a T55 in there. [24:54.780 --> 24:58.400] Um, so this is probably what you're going to see the most when... [24:59.000 --> 25:03.940] When you try to do, like, those silly keys that get you to the swimming pool or something like that. [25:04.260 --> 25:05.600] Uh, or garage keys. [25:06.680 --> 25:08.320] There's not a lot to steal. [25:08.680 --> 25:11.180] So they go with the cheapest stuff they can find. [25:12.640 --> 25:14.600] And then what I can do... [25:15.220 --> 25:16.100] Let's see. [25:16.400 --> 25:17.620] Where are my cheat sheets? [25:17.940 --> 25:18.500] There we go. [25:20.920 --> 25:26.820] What I can do is from there, where all I have to do is have a rewritable card. [25:27.700 --> 25:28.220] Hmm. [25:28.640 --> 25:30.160] Oh, you're the RFID blocker. [25:30.240 --> 25:30.680] I don't want you. [25:32.420 --> 25:34.360] And just throw it on here. [25:39.320 --> 25:40.840] I got a tag here. [25:40.880 --> 25:42.100] So I'll just do that. [25:42.100 --> 25:47.440] This is the simplest, silliest, really silliest thing. [25:47.740 --> 25:51.800] Um, and this is why my friends, like, hide their cell phones when I'm around now. [25:54.200 --> 25:54.780] Is... [25:54.780 --> 25:57.000] But it's very short range. [25:57.600 --> 25:59.280] So that's also the cool thing. [25:59.680 --> 26:01.060] Is this is very short range. [26:02.220 --> 26:03.020] Um, so... [26:03.720 --> 26:10.460] I mean, if you want to go to, like, DEFCON and see people boasting that they can do this from a bunch of feet, that's great. [26:10.940 --> 26:11.980] It takes specialized hardware. [26:12.380 --> 26:17.340] But to actually clone one of these suckers, you really need to get up close and personal with it. [26:17.340 --> 26:20.140] Um, so, like, if anybody's... [26:20.140 --> 26:21.280] I mean, you can make... [26:21.280 --> 26:23.680] You're welcome with my tinfoil hat stuff after I'm done. [26:24.640 --> 26:26.580] But it's actually really simple. [26:26.740 --> 26:32.980] And all I have to do is just say, I'm going to do a low frequency HID card because that's what I've got here. [26:33.680 --> 26:39.440] And then what I'm going to do is I'm going to clone it with a facility code of, I don't know, whatever. [26:40.780 --> 26:43.520] And a card number of whatever. [26:46.000 --> 26:48.140] And here's where it gets interesting. [26:48.680 --> 26:53.780] You do need to know your data format, but this sucker is pretty much always it. [26:54.400 --> 26:55.560] Let's see if it works. [26:55.780 --> 26:56.320] Will it blend? [26:58.120 --> 26:59.200] Oh, for... [27:00.120 --> 27:01.800] Let me go with a better one then. [27:02.680 --> 27:04.580] I'm just going to go with... [27:04.580 --> 27:07.420] I'm just going to clone what I've got. [27:09.160 --> 27:11.800] And let's just call you 200. [27:14.120 --> 27:15.300] So close enough. [27:16.000 --> 27:17.100] And there you go. [27:17.340 --> 27:18.260] Like that was it. [27:19.140 --> 27:19.700] That... [27:19.700 --> 27:19.980] It's... [27:19.980 --> 27:20.360] We're done. [27:22.040 --> 27:23.740] And then I can read it. [27:26.740 --> 27:27.980] And it's written. [27:28.380 --> 27:31.540] And like this tag came with the reader. [27:32.020 --> 27:34.420] So those guys are real easy to do. [27:36.580 --> 27:38.320] Let's take a look at a high frequency. [27:38.320 --> 27:42.780] These are a little sneakier because the high frequency ones are smart. [27:43.080 --> 27:44.980] So they can actually do encryption. [27:45.200 --> 27:46.900] So we actually have to run through some attacks. [27:48.640 --> 27:52.880] But the folks who do the Proxmark 3 junk, they are so nice to us. [27:53.040 --> 27:54.340] They actually made it real easy. [27:54.340 --> 27:55.840] So let's see. [27:56.240 --> 27:56.960] Where's my... [27:56.960 --> 27:57.260] Oh! [27:57.480 --> 27:57.940] There you are. [28:00.400 --> 28:00.960] All right. [28:01.380 --> 28:02.320] There's my hotel key. [28:05.700 --> 28:08.000] Nobody takes screenshots as I do this. [28:11.240 --> 28:14.560] All I have to do is say, hey, tell me if there's anything out there. [28:15.020 --> 28:17.900] This will come in handy for the RFID blocking stuff too. [28:18.760 --> 28:19.380] And it says, hey, yeah. [28:19.600 --> 28:20.000] There you go. [28:20.220 --> 28:20.860] We've got something. [28:21.480 --> 28:23.180] Now this line up here, UID. [28:23.780 --> 28:25.100] This is going to be important. [28:26.840 --> 28:29.080] Everything is encrypted based on a UID. [28:29.260 --> 28:30.160] So I'm going to need that. [28:31.480 --> 28:34.240] And then it's telling me that it's a MyFair Classic 1K. [28:34.440 --> 28:37.480] So this is what I've seen with like my last 12 hotels. [28:38.900 --> 28:41.200] Hopefully, other hotels have fancier junk. [28:42.540 --> 28:43.600] But these don't. [28:43.740 --> 28:47.120] This is Fairfield Inn and Suites. [28:47.160 --> 28:49.320] I don't think they're really going to break the bank on that stuff. [28:50.840 --> 29:01.540] And so what I can do is, I can just say, they were so nice to us that they made an autopone function. [29:04.420 --> 29:05.980] And I can just tell it's a run through. [29:06.680 --> 29:08.240] And so now it's going to run through. [29:08.380 --> 29:11.600] It's going to try to do a couple of different brute force attacks. [29:13.300 --> 29:15.560] It's trying to find the encryption keys. [29:17.060 --> 29:21.700] And again, like don't invent your own darned encryption. [29:22.600 --> 29:24.840] We're actually being able to break into it. [29:25.500 --> 29:27.860] That actually sounds like a really fun party out there. [29:29.440 --> 29:33.600] I won't blame you if people want to like go hang out and have a party. [29:33.600 --> 29:35.760] But we're almost done here too. [29:38.080 --> 29:38.900] All right. [29:39.200 --> 29:40.780] It's giving me time remaining. [29:41.120 --> 29:41.680] Oh, yep. [29:41.840 --> 29:42.240] There we go. [29:42.780 --> 29:43.440] Is that it? [29:43.700 --> 29:45.520] Well, it thinks it's going to take two days. [29:45.760 --> 29:47.580] I don't have that much time. [29:48.600 --> 29:51.380] But then it's going to narrow it down a little bit. [29:51.540 --> 29:53.040] A little bit more. [29:54.560 --> 29:55.400] All right. [29:56.140 --> 30:01.800] See, this is really cool because like the Windows Update progress bar would be getting longer and longer. [30:01.920 --> 30:04.100] This one actually gets shorter and shorter. [30:04.480 --> 30:06.020] I think it's going to get it pretty soon. [30:06.860 --> 30:10.660] Point is, there are attacks to be done against these cards. [30:10.820 --> 30:12.040] It does not take very long. [30:14.800 --> 30:21.580] But also, even with the high frequency ones, you really do need to get up close and personal with them. [30:21.900 --> 30:25.240] So like, I'm going to give away all these. [30:25.400 --> 30:28.760] So if you are paranoid, you can like put your card in these. [30:28.940 --> 30:35.280] But pretty much somebody is going to have their hand on your butt before they can actually do it. [30:35.280 --> 30:38.020] And then all I have to do there now. [30:39.860 --> 30:40.500] Magic. [30:40.660 --> 30:41.700] Chinese magic card. [30:42.300 --> 30:43.820] Is say, okay. [30:49.620 --> 30:50.940] Here's my UID. [30:51.580 --> 30:52.920] Let's paste U. [30:54.580 --> 30:56.420] Let's take up these spaces. [30:58.320 --> 30:58.960] Boom. [30:59.200 --> 30:59.420] Okay. [30:59.580 --> 31:02.620] Now this has the unique identifier of my hotel key. [31:04.980 --> 31:05.940] And then... [31:09.120 --> 31:10.620] I really like that music. [31:10.820 --> 31:11.360] That's really fun. [31:14.220 --> 31:17.220] And then paste U. [31:17.240 --> 31:21.440] And I'm just going to say, hey, whatever I pulled out of there, just throw it right back on this card. [31:23.840 --> 31:25.180] Gets a little messy. [31:25.920 --> 31:28.240] Lots of interestingness on the way out. [31:29.180 --> 31:31.380] But I've had success with these. [31:31.380 --> 31:35.500] And so that actually should open the door. [31:38.480 --> 31:40.760] And that's the demo on those. [31:40.940 --> 31:42.940] Let's talk about RFID blockers though. [31:43.840 --> 31:44.320] So... [31:45.560 --> 31:46.740] Low frequency tag. [31:46.880 --> 31:47.280] Let's see. [31:47.440 --> 31:48.340] Let's see what happens. [31:48.480 --> 31:49.140] I've got a paper. [31:50.180 --> 31:51.160] There's a nice... [31:51.160 --> 31:52.080] Oh, there's a big one. [31:52.260 --> 31:54.620] Big one for protecting your passport. [31:55.960 --> 31:56.740] These are cool. [31:56.880 --> 31:57.280] They're retro. [31:57.660 --> 32:01.100] So it's like, hey, look, I'm a videocassette thing. [32:02.820 --> 32:03.380] All right. [32:03.520 --> 32:04.200] Let's try here. [32:04.340 --> 32:04.780] Let's see. [32:10.160 --> 32:10.600] Okay. [32:14.080 --> 32:14.820] Mm-hmm. [32:15.100 --> 32:15.640] Mm-hmm. [32:16.020 --> 32:16.360] All right. [32:16.500 --> 32:17.040] That one works. [32:17.980 --> 32:20.460] Let's try you on one of these little guys. [32:29.180 --> 32:31.220] And then I'm also going to do a high frequency. [32:31.560 --> 32:32.740] Oh dear. [32:33.500 --> 32:34.740] Oh, the little guy found it. [32:34.980 --> 32:35.240] All right. [32:36.020 --> 32:38.300] Let's try a high frequency on one of those. [32:51.090 --> 32:51.690] All right. [32:51.750 --> 32:53.690] So this one might be kind of effective. [32:53.970 --> 32:54.230] All right. [32:54.450 --> 32:58.930] So if you're going to take some of these free ones home, that one's a good one. [33:00.250 --> 33:01.810] Oh, let's try the car. [33:02.250 --> 33:03.970] The car key fob one. [33:04.190 --> 33:04.770] Let's try that. [33:04.970 --> 33:07.510] I'm going to try that with my actual apartment key here. [33:10.670 --> 33:17.670] Again, like all the Amazon reviews are like, I don't know if it works, but it looks cool and I use it. [33:18.530 --> 33:20.110] And it fits in my pocket. [33:21.030 --> 33:23.250] Also gets scanned through my pocket. [33:23.410 --> 33:23.590] All right. [33:23.690 --> 33:24.830] Let's try a high frequency one. [33:26.690 --> 33:30.150] Let's see if this thing's worth the $5.99 I spent on it. [33:30.150 --> 33:35.170] I limited myself to $25 budget for these blockers. [33:35.610 --> 33:37.470] I think that's about what they're worth. [33:41.710 --> 33:42.310] And... [33:42.310 --> 33:43.010] Nope. [33:43.350 --> 33:43.750] All right. [33:44.010 --> 33:51.550] So this one blocks high frequency, which hopefully saves your car from getting stolen. [33:52.970 --> 33:53.990] Oh, active. [33:54.210 --> 33:55.190] These are the active ones. [33:55.510 --> 33:57.210] So let's take a look at this. [33:59.170 --> 33:59.850] Let's see. [34:01.210 --> 34:02.510] Let's try you. [34:04.330 --> 34:05.310] Low frequency. [34:08.250 --> 34:08.810] Whoops. [34:09.290 --> 34:09.590] All right. [34:10.250 --> 34:11.950] Let's try you with the hotel key. [34:20.370 --> 34:21.730] Seems a little bit better. [34:22.370 --> 34:22.870] All right. [34:23.010 --> 34:24.330] So the active ones seem to work. [34:25.210 --> 34:25.650] And... [34:25.650 --> 34:25.930] Ooh. [34:26.190 --> 34:26.710] Tin foil hat. [34:26.910 --> 34:27.090] Oh. [34:29.030 --> 34:29.470] Oh. [34:30.210 --> 34:30.530] Oh. [34:30.530 --> 34:30.550] Oh. [34:30.790 --> 34:31.790] Sorry, active card. [34:32.350 --> 34:32.610] Okay. [34:34.770 --> 34:35.210] So... [34:35.210 --> 34:39.350] If you're going to pick up free stuff after the show, this is not the one. [34:40.730 --> 34:42.570] I think that was the most expensive one, too. [34:42.610 --> 34:44.130] I think I paid $7 for that card. [34:45.990 --> 34:47.930] Let's try tin foil hat. [34:48.990 --> 34:49.730] All right. [34:50.750 --> 34:51.750] I'm just going to... [34:51.750 --> 34:53.050] I'm not even going to double it up. [34:53.170 --> 34:54.650] I'm just going to go with one layer. [34:57.090 --> 35:00.950] If you make a hat, you might want to make it more than one layer. [35:03.530 --> 35:04.590] Oh, darn it. [35:04.950 --> 35:05.230] All right. [35:05.450 --> 35:06.630] Well, it reads through that. [35:08.730 --> 35:09.610] Let's try... [35:09.610 --> 35:11.350] Where did I put my hotel key? [35:11.490 --> 35:11.790] Right there. [35:12.550 --> 35:12.970] All right. [35:13.070 --> 35:13.950] Let's try hotel key. [35:26.700 --> 35:27.580] Looking good. [35:28.240 --> 35:29.100] All right. [35:29.680 --> 35:31.000] Tin foil hat for the win. [35:31.200 --> 35:31.620] All right. [35:32.100 --> 35:33.860] You can buy that stuff by the yard. [35:34.120 --> 35:35.980] It's a little expensive. [35:36.140 --> 35:37.180] It's not that expensive. [35:37.180 --> 35:39.000] But you can buy it by the yard. [35:39.000 --> 35:40.080] So you can make a hat. [35:40.280 --> 35:43.020] Maybe next year my talk will be how to make a tin foil hat. [35:45.500 --> 35:48.960] And that's all I've got. [35:48.960 --> 35:50.000] Except I've got... [35:50.860 --> 35:54.060] Like I borrowed one of my girlfriend's IPSY bags. [35:54.200 --> 35:54.880] Let's try that. [35:55.800 --> 35:56.360] Let's see. [35:56.840 --> 35:57.680] Hotel key. [35:59.340 --> 36:01.860] I'm just going to hang that there. [36:06.360 --> 36:07.240] All right. [36:07.560 --> 36:08.040] All right. [36:08.240 --> 36:09.680] So don't use an IPSY bag. [36:11.680 --> 36:12.560] Let's try... [36:12.560 --> 36:13.800] Let me see. [36:13.980 --> 36:16.120] I'm just going to put my driver's license in front of this. [36:16.800 --> 36:17.700] Let's try that. [36:20.540 --> 36:21.800] And this will be the last one. [36:23.920 --> 36:24.500] All right. [36:24.740 --> 36:25.740] So it reads through there. [36:25.980 --> 36:26.480] That's fine. [36:26.780 --> 36:30.240] So as you can see, kind of like interesting results, body results. [36:30.760 --> 36:31.920] Some of these block things. [36:32.060 --> 36:32.680] Some of them don't. [36:33.360 --> 36:35.260] But you have to get really close. [36:36.300 --> 36:41.920] But really close to someone's butt to actually scan the card that's in their wallet. [36:44.280 --> 36:44.680] So... [36:46.220 --> 36:50.340] Now that you know about all that, I'll show you a couple of other things you can do. [36:52.240 --> 36:52.960] NFC tags. [36:53.240 --> 36:54.840] They work in this range as well. [36:55.620 --> 37:00.060] And I have a bunch of those up here as well that I don't want to take home. [37:00.280 --> 37:01.560] So you all are welcome to have them. [37:02.620 --> 37:04.480] EMV is for your credit cards. [37:06.120 --> 37:06.480] The... [37:06.480 --> 37:07.720] Just these frequencies. [37:07.980 --> 37:09.040] You can play around with that stuff. [37:09.520 --> 37:11.040] EMV is pretty darn secure. [37:12.720 --> 37:14.500] It's really cool stuff. [37:15.320 --> 37:17.120] Because we didn't come up with it here. [37:17.280 --> 37:18.880] We came up with it with like scientists. [37:20.540 --> 37:21.800] E-paper displays. [37:22.360 --> 37:23.660] These are really neat. [37:23.840 --> 37:35.280] These e-paper displays, there are ones, especially the ones they use in supermarkets, that use RFID frequencies and the energy to rewrite the display. [37:36.220 --> 37:37.280] So you can get them. [37:37.440 --> 37:40.420] I've actually got a couple that I'm just playing around with. [37:41.380 --> 37:43.880] Naturally, you have to have the reader to update it. [37:43.980 --> 37:48.320] So it's not like your e-paper display that's connected to a Raspberry Pi or something. [37:48.600 --> 37:50.300] But it's really kind of fun. [37:52.200 --> 37:57.480] And then one of the things that more and more people are talking about is Java cards. [37:57.480 --> 38:03.040] The high-frequency cards get smart enough that you can actually run Java applets on them. [38:03.320 --> 38:05.540] And so there actually are cards that will run it. [38:06.260 --> 38:14.940] And so similar to the way that like the old Greybeards, when we were all plugging Arduinos into everything, they were like, well, you know, firmware is better. [38:15.080 --> 38:16.300] I don't know why you run software. [38:16.440 --> 38:16.860] That's terrible. [38:17.320 --> 38:18.720] Java cards are the same trick. [38:19.240 --> 38:23.240] Is now we can tell Greybeards like, hey, I'm just going to write something in software. [38:23.240 --> 38:24.260] I don't care about hardware. [38:24.940 --> 38:26.400] So that's really cool. [38:27.200 --> 38:29.800] And then UHF, ultra-high frequency. [38:30.220 --> 38:31.900] These are totally different tags. [38:32.240 --> 38:36.380] They use them for like toll passes, stuff like that. [38:36.520 --> 38:38.360] My Proxmark 3 won't deal with them. [38:39.280 --> 38:41.840] But kind of fun stuff to be done in there. [38:43.200 --> 38:47.420] My garage, actually, there's a UHF tag you can use for that. [38:47.420 --> 38:48.660] But it's a different reader. [38:49.900 --> 38:53.940] And there are a bunch of places that you can go to get more information. [38:54.820 --> 38:59.020] This stuff is kind of like, it's sort of spread around a little bit. [39:02.280 --> 39:06.720] And there's a bit of a RTFM kind of thing. [39:06.980 --> 39:10.920] Like, don't go into these communities and just be like, I want to copy a key. [39:11.140 --> 39:11.760] What are the commands? [39:13.160 --> 39:14.400] Because I showed them to you. [39:14.400 --> 39:24.080] But also because like people see right through anytime somebody joins and they're like, I'm trying to copy this thing because I need a copy for my own personal use. [39:24.780 --> 39:27.520] Everybody sees that for what it is. [39:27.520 --> 39:30.540] But there's a Discord for RFID hackers. [39:30.880 --> 39:32.240] There are forums out there. [39:33.300 --> 39:40.300] The tags themselves, the data sheets tend to be open and publicly out there. [39:40.460 --> 39:46.960] So if you can read that kind of junk, which I can't, the data sheets are out there. [39:47.120 --> 39:47.880] It's all public. [39:49.820 --> 39:54.920] One other thing I found really useful is that vendors explain this stuff. [39:54.920 --> 39:57.160] They have little like explainer videos. [39:57.620 --> 40:02.460] So they're trying to sell you something, but they have to educate you first. [40:02.840 --> 40:06.140] So there are plenty of videos out there from vendors themselves. [40:06.920 --> 40:12.040] Typically of the readers that will explain this stuff in pretty simple terms. [40:12.260 --> 40:13.020] It's pretty cool. [40:15.000 --> 40:22.100] Naturally, you can go totally crazy on a shopping spree and have fun and just pick some stuff up. [40:22.100 --> 40:27.880] You know, whether it's whatever your site of choice is. [40:28.520 --> 40:33.020] And the walkthroughs, the how-tos are really, really fun. [40:33.360 --> 40:34.420] Just really fun. [40:34.840 --> 40:38.740] And really, you just need to just kind of dive in. [40:38.900 --> 40:42.240] Which is what I did to solve my problem. [40:45.060 --> 40:47.620] Which, let me just bring it around to that. [40:48.060 --> 40:54.660] Is my problem, by the way, was motorcycle, need to get in the garage, clipped hands, clutch and throttle. [40:55.840 --> 41:01.640] And it turns out that one of the form factors is a ring. [41:01.640 --> 41:08.960] And so I've got a ring that has a low frequency chip and coil in it. [41:09.340 --> 41:12.680] And I can actually open my garage door with it. [41:21.190 --> 41:22.050] And that's it. [41:22.310 --> 41:22.930] Have fun. [41:31.310 --> 41:33.290] Yeah, we've got time for questions if you want. [41:34.610 --> 41:35.750] You are the first hand. [41:43.610 --> 41:47.290] He says, the key concept is skin depth. [41:48.150 --> 41:49.590] How a [41:52.770 --> 41:53.410] lot of things look. [41:57.130 --> 41:57.650] Online. [41:58.190 --> 41:58.830] Oh, interesting. [41:59.050 --> 41:59.830] So it's about just... [42:01.730 --> 42:04.970] Like physics is adding depth, distance. [42:05.270 --> 42:05.830] You look up, [42:16.590 --> 42:17.210] there's doors. [42:17.770 --> 42:18.690] It's flexible. [42:18.950 --> 42:19.330] It's better. [42:19.810 --> 42:22.170] Copper siding is going to be hard to make a hat out of. [42:23.510 --> 42:25.390] You form it into a little box. [42:25.390 --> 42:25.830] Uh-huh. [42:30.670 --> 42:31.110] Okay. [42:31.530 --> 42:33.550] So you can do this stuff from the hardware store. [42:33.830 --> 42:34.010] Yeah. [42:34.130 --> 42:35.210] The RFID blockers. [42:35.290 --> 42:35.430] Yeah. [42:35.770 --> 42:36.450] Very cool. [42:38.750 --> 42:39.630] All right. [42:39.990 --> 42:40.670] Thank you. [42:40.850 --> 42:41.010] Yeah. [42:41.190 --> 42:46.670] So you can just go to the hardware store and find copper and just make your own pouches. [42:47.370 --> 42:50.470] Did the copper one work for the low frequency cards for you? [42:50.670 --> 42:52.290] Oh, did it work for the low frequency? [42:53.010 --> 42:53.450] That's [42:56.680 --> 42:57.000] embarrassing. [42:57.420 --> 42:59.580] I haven't actually gotten around before. [43:06.820 --> 43:10.340] So for the low frequency you might need like corrugated steel or something. [43:10.540 --> 43:16.380] Well, my thought on it is the low frequency cards are probably doing no steel. [43:16.520 --> 43:17.700] It's actually magnetic. [43:17.960 --> 43:18.820] We were afraid of coupling. [43:19.100 --> 43:19.600] Interesting. [43:20.360 --> 43:22.240] Ah, so magnetic would go through it. [43:22.240 --> 43:22.680] All right. [43:22.680 --> 43:23.160] All right. [43:24.040 --> 43:25.240] That one in that... [43:25.960 --> 43:27.740] What was the old frequency for the high frequency one? [43:27.860 --> 43:28.220] Thirteen. [43:28.440 --> 43:28.840] Yeah, thirteen. [43:28.980 --> 43:30.220] That's an ISM there. [43:30.240 --> 43:30.600] Ah. [43:31.160 --> 43:32.200] That's why they have it there. [43:32.360 --> 43:34.900] Because that frequency is reserved for industrial science. [43:35.000 --> 43:35.360] All right. [43:35.900 --> 43:39.460] So the frequency makes a big difference because of the way that it's done. [43:39.480 --> 43:43.500] But the thing is that frequency is probably more an e-field, the electric field. [43:43.500 --> 43:46.760] And things like productive things like copper or aluminum foil. [43:47.560 --> 43:50.780] But that's why that works better for the high frequency cards. [43:50.960 --> 43:51.360] Thank you. [43:51.540 --> 43:51.740] All right. [43:52.140 --> 43:53.960] What other questions did I have out there? [43:54.100 --> 43:54.280] Yes. [43:54.600 --> 43:59.420] The learning curve is actually not that bad. [44:00.820 --> 44:04.820] I mean, if you're like a weekend project kind of person, it's pretty cool. [44:05.280 --> 44:06.180] It's pretty good. [44:06.760 --> 44:08.500] There are how to's out there. [44:08.660 --> 44:10.940] There are how to's included in the source code. [44:12.400 --> 44:16.280] And you really just need to like look around a little, play a little. [44:17.880 --> 44:21.240] Everybody who's done like how to's is like me. [44:21.400 --> 44:23.000] They don't really know what they're doing. [44:23.860 --> 44:26.600] But you'll find the right commands that make it work. [44:26.600 --> 44:30.480] And then you can play around and then you can go on to the discord or the forums. [44:30.840 --> 44:36.900] And, you know, once you've done your RTFM, they're really helpful people out there. [44:37.240 --> 44:37.340] Yeah. [44:37.440 --> 44:37.860] It's not bad. [44:38.380 --> 44:38.540] Yeah. [44:38.860 --> 44:39.060] Another. [44:46.180 --> 44:46.980] Oh, yes. [44:47.160 --> 44:49.200] The Proxmark 3 does look like a desktop device. [44:49.400 --> 44:50.680] It actually is pretty portable. [44:51.440 --> 44:54.260] The USB, you can charge it off USB power. [44:54.440 --> 44:55.660] So you just need a battery pack. [44:56.420 --> 44:57.940] They make one... [44:57.940 --> 44:59.860] You've got the RDB4, right? [45:01.860 --> 45:02.400] Yeah. [45:03.800 --> 45:04.340] Yeah. [45:04.900 --> 45:07.880] So they make smaller ones than the one that I have. [45:08.040 --> 45:11.740] But they are designed to run in standalone mode. [45:12.280 --> 45:13.680] Not something I've messed with. [45:13.820 --> 45:16.940] But they can emulate a card right out of the Proxmark. [45:17.320 --> 45:20.100] They can also emulate a reader right out of the Proxmark. [45:20.100 --> 45:25.320] I was just wondering, like, if you've got the Proxmark that is good for emulating a variety of... [45:26.920 --> 45:27.360] Yeah. [45:27.640 --> 45:30.040] The Proxmark 3 is fantastic for emulating things. [45:30.780 --> 45:33.260] The other one that I see mentioned is the Chameleon. [45:33.980 --> 45:37.260] I think that's only for high frequency, but don't quote me on it. [45:38.220 --> 45:41.780] And we're recording this, so now somebody will quote me on it. [45:41.780 --> 45:44.060] But yeah, there are other tools. [45:44.200 --> 45:46.720] But the Proxmark is a nice Swiss army knife for that kind of stuff. [45:46.920 --> 45:47.040] Yeah. [45:47.820 --> 45:51.960] Can the Proxmark or any other tools actually emulate an RFID? [45:52.040 --> 45:54.520] Or do you always need to write to a card? [45:54.740 --> 45:55.280] Like, could I scan it? [45:55.280 --> 45:56.300] Yeah, they can emulate it. [45:56.340 --> 45:56.760] Yeah. [45:56.900 --> 45:59.140] Like, emulate one. [45:59.140 --> 45:59.420] Yeah. [45:59.720 --> 46:01.820] Yeah, and there are some attacks that require that. [46:02.160 --> 46:05.440] For you to hold it up and watch reads happening. [46:06.060 --> 46:06.360] Cool. [46:06.360 --> 46:07.000] Yeah. [46:07.300 --> 46:08.560] Yeah, it's pretty darn cool. [46:09.760 --> 46:12.240] Those Hoopy Fruits really know where their towel is. [46:13.280 --> 46:13.740] Yes. [46:19.420 --> 46:20.380] Oh, yes. [46:20.480 --> 46:22.600] I want my flipper to get here. [46:23.520 --> 46:27.460] From what I've seen, the Flipper Zero is pretty darn amazing. [46:27.740 --> 46:29.760] I have one right here if anybody wants to see one. [46:29.900 --> 46:30.480] Oh, yeah. [46:30.680 --> 46:31.520] Hit those dudes up. [46:31.620 --> 46:34.280] Hit you up to check them out. [46:34.400 --> 46:34.480] Yeah. [46:34.960 --> 46:37.360] The Flipper Zero looks really fantastic. [46:37.400 --> 46:38.820] I don't have one yet. [46:39.380 --> 46:41.960] And I wasn't willing to pay $800 on eBay yet. [46:43.000 --> 46:44.060] They're available again. [46:44.680 --> 46:44.940] Yeah. [46:45.300 --> 46:46.280] They are available again. [46:46.460 --> 46:46.740] Yeah. [46:46.900 --> 46:47.800] I put in my order. [46:48.380 --> 46:50.140] It gets here in August or something. [46:50.500 --> 46:51.020] So, yeah. [46:51.140 --> 46:52.720] You don't have to pay $800 on eBay. [46:53.300 --> 46:57.980] Or be the early adopter who luckily got in there before the rest of us knew about it. [46:58.360 --> 46:59.700] I only found out about it now. [47:00.220 --> 47:00.660] Oh. [47:00.980 --> 47:03.740] They're pretty quick. [47:03.900 --> 47:04.540] All right. [47:04.800 --> 47:06.820] So, they do have orders going pretty quickly. [47:07.660 --> 47:09.200] Hopefully, mine's there when I get home. [47:09.200 --> 47:10.240] One more question? [47:18.660 --> 47:19.760] I have not. [47:20.300 --> 47:20.560] I have not. [47:21.460 --> 47:22.860] I had one friend. [47:23.360 --> 47:27.540] I had one friend where I was like, hey, do you have any of these key fobs? [47:27.740 --> 47:31.580] And she was like, yeah, I have one to get into my office. [47:31.640 --> 47:32.620] And I was like, oh, cool. [47:32.800 --> 47:33.880] Let me see if I can copy it. [47:33.880 --> 47:36.880] And then looked at it and it was like a Pico pass thing. [47:37.600 --> 47:43.460] And I was like, well, good news is nobody's going to be able to copy that anytime soon. [47:44.380 --> 47:50.020] I don't know where they stand on the whole Desfire stuff and what they're doing with that yet. [47:50.600 --> 48:00.520] But hopefully, with any luck, the harder encryption algorithms they invented themselves instead of relying on cryptographers and we'll be able to break it. [48:04.330 --> 48:04.970] All right. [48:05.190 --> 48:05.770] That's it. [48:05.970 --> 48:06.810] Have fun. [48:06.970 --> 48:07.510] Go out there. [48:07.650 --> 48:08.490] You can do it. [48:08.530 --> 48:09.050] I did it. [48:09.050 --> 48:11.350] So have a good night and enjoy. [48:11.650 --> 48:12.110] All right. [48:12.190 --> 48:12.690] Thank you, Gabe. [48:17.680 --> 48:23.540] For everyone, the last talk of the night here in this track will be practical steps to improve privacy. [48:23.540 --> 48:26.640] So if you're up for one more at 10 o'clock, we'll be doing the last talk. [48:27.260 --> 48:27.840] Oh, yeah. [48:28.140 --> 48:28.440] Yeah. [48:28.720 --> 48:30.100] This one blocks the lower frequency. [48:30.460 --> 48:31.560] I'm just wondering what... [48:31.560 --> 48:31.580] Thank you.