[00:00.000 --> 00:03.160] You're about to hear about RFID and privacy. [00:03.540 --> 00:05.520] Before that a few programming announcements. [00:06.940 --> 00:10.900] Later today at 1700 we had scheduled Exploring Dusty Corners of the Web. [00:11.020 --> 00:12.760] Unfortunately that talk will not happen. [00:13.080 --> 00:15.560] We've replaced it with a sci-fi talk. [00:15.760 --> 00:17.960] I'll have more information on that in a little bit. [00:18.460 --> 00:19.220] Stay tuned. [00:19.820 --> 00:25.060] We've also had to change Kevin Mitnick Unplugged later today in track A with Off the Hook. [00:25.200 --> 00:27.220] They'll both be still happening, they're just reversed. [00:27.500 --> 00:29.980] So Kevin Mitnick tomorrow, Off the Hook in DCN. [00:30.000 --> 00:30.660] Today. [00:32.580 --> 00:36.520] Then without further ado, I should introduce number 76. [00:37.200 --> 00:39.340] He's a PhD candidate in computer science. [00:39.860 --> 00:44.980] And he's about to talk to you about all sorts of things you probably didn't think of with RFID and privacy. [00:45.920 --> 00:46.680] Karsten Nohl. [00:52.680 --> 00:53.960] Thanks for the introduction. [00:54.620 --> 00:58.700] Welcome to HOPE Number Six and welcome to my talk on RFID privacy. [00:59.880 --> 01:01.240] I'm impressed by the turnout. [01:01.480 --> 01:02.240] Thank you all for coming. [01:03.560 --> 01:11.120] I'm Karsten, PhD student at the University of Virginia and my research is in the area of cryptography. [01:11.480 --> 01:15.080] Dealing mainly with RFID privacy and security at the moment. [01:16.340 --> 01:19.260] I want to have this as interactive as possible. [01:19.580 --> 01:23.280] So interrupt me at any time with questions or if you need clarifications. [01:23.740 --> 01:23.840] Okay? [01:25.420 --> 01:28.400] I'll briefly go over the basics of RFID. [01:28.560 --> 01:32.240] I assume that all of you know what RFID is about. [01:32.760 --> 01:43.100] So RFID tags, I'll mainly be concerned with passive RFID tags, are very small silicon chips attached to antenna. [01:43.700 --> 01:51.400] In this upper right picture, the silicon chip is really only the tiny black dot. [01:52.460 --> 01:57.760] The lower limit on that used to be about a square millimeter. [01:58.600 --> 02:01.820] Then that went down to half a square millimeter. [02:02.400 --> 02:04.340] Nobody really thought we could do smaller. [02:04.580 --> 02:07.460] I talked to somebody of Philips last week. [02:07.600 --> 02:10.900] They are down to a quarter square millimeter and shrinking. [02:11.180 --> 02:12.620] So these are tiny, tiny. [02:12.980 --> 02:14.660] Which makes them very cheap. [02:14.660 --> 02:21.380] If you have a waiver of silicon, you can put tens of thousands, hundreds of thousands chips on one waiver for that one. [02:22.120 --> 02:25.580] We are talking five cents at the moment. [02:26.320 --> 02:26.320] We are talking five cents at the moment. [02:26.320 --> 02:29.080] A square millimeter of silicon costs about four cents. [02:29.340 --> 02:33.200] So if you are down to a quarter, the silicon itself costs you a cent. [02:33.360 --> 02:34.460] So you can sell it for five. [02:34.680 --> 02:36.260] But that is decreasing too. [02:37.920 --> 02:44.960] Another reason why these tags are extremely cheap is they don't have a battery or any source of power on them. [02:45.220 --> 02:48.120] So they must be powered by the reading device. [02:48.260 --> 02:49.600] Passively powered through induction. [02:50.380 --> 02:51.060] You know? [02:51.420 --> 02:54.840] Which makes them not operate if there is no reader around it. [02:56.220 --> 02:57.460] RFID tags are everywhere. [02:58.460 --> 03:01.740] Who of you uses the SpeedPass ExxonMobil? [03:02.960 --> 03:05.980] Who of you has an American Express credit card? [03:07.060 --> 03:09.600] So maybe you already have an RFID tag. [03:09.720 --> 03:11.620] Maybe you will get it with your next card. [03:11.920 --> 03:15.340] But all American Express credit cards have it at the moment. [03:15.480 --> 03:16.900] So it's getting ubiquitous. [03:16.900 --> 03:20.400] Who has a car later than 2002? [03:21.820 --> 03:23.460] All car keys. [03:23.720 --> 03:26.040] The theft protection have RFID tags. [03:26.340 --> 03:28.000] So it's really everywhere already. [03:28.560 --> 03:31.880] And we read many headlines on RFID. [03:32.060 --> 03:37.660] Walmart requires all their supplies to put RFID tags on the pallets and the packages. [03:37.660 --> 03:39.340] Not on the items itself. [03:39.980 --> 03:41.780] So far, that's too expensive. [03:42.400 --> 03:45.040] Same for the DOD, the Department of Defense. [03:45.720 --> 03:50.360] They are concerned with logistics and, let's say, rough environments. [03:50.600 --> 03:54.960] Iraq, Afghanistan, and they want to smooth that out through more automation. [03:56.920 --> 03:58.940] Gillette, major play in RFID. [03:59.500 --> 04:02.080] All that half a billion, they haven't received all of them yet. [04:02.240 --> 04:07.320] But they are not so much concerned with logistics, but with theft protection. [04:07.520 --> 04:11.900] If you can track every single item, you know when you lost one, right? [04:12.240 --> 04:17.760] And razor blades are the most commonly stolen good in the world. [04:22.120 --> 04:26.640] The RFID market this year is worth close to three billion already. [04:26.840 --> 04:28.000] And we are just starting. [04:28.240 --> 04:30.460] It grew 39% from last year. [04:30.640 --> 04:34.260] And this is an estimate by some consultant agency. [04:34.620 --> 04:38.540] We will hit the double-digit billions soon. [04:41.540 --> 04:45.320] My talk is going to be concerned with RFID privacy. [04:45.320 --> 04:48.320] And I already talked a little bit on RFID background. [04:48.320 --> 04:52.020] I'll give you some more basics as we go along to help you understand. [04:52.780 --> 05:01.180] I will next talk about two threats that arise from RFID use. [05:01.840 --> 05:05.700] And we'll then look into solutions on a protocol level. [05:06.020 --> 05:12.320] This is not an academic talk, but I'll try to relate it as much as possible to recent research. [05:14.380 --> 05:16.620] Mainly in the area of protocols. [05:16.620 --> 05:26.560] We'll then look into other layers, the physical and the system level, where more privacy issues arise. [05:28.060 --> 05:32.120] What is the most commonly sought threat in RFID? [05:32.260 --> 05:36.700] It's that you carry tags that disclose information about you. [05:36.700 --> 05:44.980] And if you have seen any talk on RFID privacy ever, you probably know Mr. Jones by Ari Jules from RSA Security. [05:46.020 --> 05:51.060] Mr. Jones lives in the future where RFID has been deployed large-scale. [05:51.240 --> 05:53.260] And he carries several RFID tags. [05:54.120 --> 06:00.200] These RFID tags might disclose information that he would consider private. [06:00.200 --> 06:07.640] So everybody who has a scanning device can learn these things about them. [06:07.760 --> 06:13.000] And a scanning device, Nokia for example, already puts reading devices in cell phones. [06:13.160 --> 06:16.560] So very soon everybody will carry an RFID reader. [06:18.140 --> 06:21.660] You could learn that he wears a wig and has a replacement hip. [06:22.100 --> 06:27.340] You could learn about his political interest by which books he checked out from the library. [06:28.900 --> 06:38.660] A proposal by the European Federal Bank was to make banknotes more counterfeit resistant through putting RFID tags in them. [06:38.660 --> 06:46.280] So if you could digitally sign something, put it on the banknote, that's much harder to counterfeit than the banknote itself. [06:47.200 --> 06:51.760] But as Ari Jules points out, this allows for extremely efficient mugging. [06:53.780 --> 06:56.580] You don't have to guess anymore who has most money. [06:56.740 --> 06:58.120] You just probe it. [06:58.380 --> 07:01.380] So all this information you might want to keep private. [07:01.380 --> 07:08.900] And what's the problem with RFID tags so far? [07:08.900 --> 07:11.680] If you read the number, you know what product it is. [07:11.760 --> 07:14.220] And that's called the electronic product code. [07:14.380 --> 07:18.880] So usually RFID tags have a 96 bit ID. [07:19.100 --> 07:19.980] That's all they can do. [07:20.080 --> 07:22.260] They can submit that ID, that's it. [07:22.500 --> 07:23.600] Super small chip. [07:25.000 --> 07:29.200] The information itself is then stored in some computer network. [07:29.200 --> 07:32.260] And the product code is broken into... [07:32.260 --> 07:41.880] And this is kind of similar to the MAC address, Ethernet, into a manufacturer ID that is assigned to different manufacturers by the EPC global organization. [07:42.640 --> 07:49.040] And then the manufacturer itself can assign product IDs that must stay the same for a group of products. [07:49.100 --> 07:51.180] Say like a shirt, that size, that color. [07:51.580 --> 07:53.440] And then a unique item ID. [07:53.640 --> 07:57.480] So the first two, the manufacturer ID and the product ID, you would find in barcode. [07:57.480 --> 08:00.780] But that last year number, that's the unique number. [08:01.000 --> 08:05.060] So this is what allows for very efficient logistics. [08:06.340 --> 08:21.100] And having like a rogue reader who can get the manufacturer ID and the product ID allows to look that up, to know that is a bank note of that value, this is a WIC, so on. [08:21.100 --> 08:24.660] The solution to this is easy and straightforward. [08:25.220 --> 08:27.280] Just don't use structured identifies. [08:27.620 --> 08:28.700] Use random numbers. [08:28.880 --> 08:32.880] Use those to point into a database and look up your information. [08:33.140 --> 08:41.460] So the EPC code is the reason why RFID takes this close information. [08:41.720 --> 08:46.580] And there's discussion in which scenarios we would use that. [08:47.440 --> 08:50.020] So that problem is kind of solved. [08:50.400 --> 08:52.680] Only industry has to understand that too. [08:53.500 --> 08:57.580] There's a second threat for RFID privacy, people tracking. [08:57.800 --> 09:08.380] So the scenario being that innocent Alice roams in some environment and she doesn't disclose any information directly. [09:08.380 --> 09:10.500] We have random identifies. [09:10.920 --> 09:19.440] So her RFID tags give numbers out that unless you own the tag, you don't get information. [09:19.640 --> 09:21.140] But the number stays the same. [09:21.400 --> 09:26.300] So different reading events can be linked and you can build a trace of Alice. [09:26.920 --> 09:27.020] Right? [09:27.440 --> 09:32.760] So that's of less privacy concern for most people. [09:33.680 --> 09:39.180] Well, it's hard to see how this penetrates anonymity. [09:39.380 --> 09:46.820] But combining this with other information that is collected already allows for very good profiling and data mining. [09:47.100 --> 09:49.540] So this information should be kept private. [09:50.960 --> 09:54.000] What are naive solutions to that problem? [09:54.440 --> 09:57.340] There's many things implemented and proposed so far. [09:57.340 --> 10:10.260] The EPC organization itself has the opportunity to kill tags at checkout time so that you don't give functional RFID tags to customers. [10:10.540 --> 10:14.440] Once you sell the tag or the good that it's attached to, you kill it. [10:15.040 --> 10:23.480] That requires a password that has to come from the manufacturers to the wholesale to the retail so that there's some issues there of key management. [10:23.480 --> 10:29.620] Other proposals were to just wrap RFID tags in metal foil. [10:30.480 --> 10:36.620] So, physics class tells us Faraday cages don't allow radio communication. [10:37.420 --> 10:37.540] Right? [10:38.760 --> 10:41.600] Or you could actively disturb the protocol. [10:41.760 --> 10:51.280] Another proposal by Aaron Jules is the blocker tag where you carry another tag that disturbs the reader. [10:51.280 --> 10:53.160] It confuses the reader basically. [10:53.360 --> 11:03.820] Once the reader tries to probe you or asks for identifiers, it generates pseudo-text and the reader is not going to find out anything about you. [11:04.800 --> 11:06.240] And then the last option. [11:06.700 --> 11:12.140] Obviously, it's a radio technology so if you just jam the radio frequency, it's not going to work anymore. [11:12.340 --> 11:14.680] Which might be illegal in most legislations. [11:14.680 --> 11:24.140] All these proposals effectively prohibit the use of RFID. [11:24.900 --> 11:32.840] So, there's a trade-off between comfort and privacy here and as we know from... [11:32.840 --> 11:35.120] How many of you use credit cards rather than cash? [11:36.560 --> 11:38.660] Well, you decided for comfort, right? [11:38.780 --> 11:42.300] And I guess the same would happen with RFID. [11:42.520 --> 11:44.920] So, people don't want their tags to be killed. [11:45.180 --> 11:48.560] People don't want to wrap them in aluminum foil or carry them as a device. [11:51.580 --> 11:58.120] So, let's look into what solutions research gives us. [11:58.120 --> 12:01.860] And here we come to cryptography, the field I'm working in. [12:03.160 --> 12:10.780] The scenario now is that we want the tag to respond in a way that you can't link different reading events. [12:10.960 --> 12:14.400] So, each time you query the tag, it responds with a different number. [12:14.580 --> 12:16.180] That's the goal, right? [12:17.200 --> 12:23.020] And now Alice is the reader or the legitimate database that owns the tags. [12:24.040 --> 12:27.600] And Alice shares one key with each tag. [12:27.800 --> 12:32.780] So, she has a list of keys, meaning secret binary strings. [12:33.240 --> 12:36.040] And every tag has one key. [12:37.380 --> 12:47.620] The tag now being probed, being asked to reveal its ID, generates a number used once, a random string of bits again. [12:48.040 --> 12:49.640] Each time a different string. [12:50.680 --> 12:53.580] And uses a hash function, a keyed hash function. [12:53.740 --> 12:56.700] That is a function that you can easily compute in one way. [12:57.360 --> 13:01.420] So, given the input, you can easily compute the output, but not the way around. [13:01.520 --> 13:04.460] Given the output, it's almost impossible to get the input. [13:04.660 --> 13:06.760] It's a trapdoor function, a one-way function. [13:07.220 --> 13:13.460] She generates, using her secret key and that random number, the hash output. [13:13.460 --> 13:17.300] And sends the random number and the hash output over to Alice. [13:18.460 --> 13:21.320] Who now... can you see how that protocol would work? [13:21.460 --> 13:26.640] How does Alice now see what tag generated this response? [13:27.160 --> 13:32.480] What she does is she uses the hash function with every possible key on that random number. [13:32.640 --> 13:34.620] And sees whether the output matches, right? [13:34.960 --> 13:36.940] So, the first key doesn't, the second does. [13:36.940 --> 13:40.200] So, Alice knows which tag she's talking to. [13:40.640 --> 13:44.320] Somebody who doesn't have the keys does not know anything. [13:44.500 --> 13:45.940] It's two random looking numbers. [13:46.140 --> 13:49.000] One is really random and the hash output is pseudorandom. [13:50.560 --> 13:52.080] There's two problems with that. [13:52.500 --> 13:56.480] One being the unsolved big problem of computer security, key management. [13:56.480 --> 13:58.820] How do you get the keys on the reader? [13:59.160 --> 14:05.080] How do you share control if different authorities need to read the tag? [14:05.300 --> 14:05.780] All these things. [14:05.980 --> 14:09.020] But that left aside, there's the second problem. [14:10.300 --> 14:12.980] In this case, Alice had to do two hash operations. [14:13.340 --> 14:16.360] But what if there is more tags? [14:16.780 --> 14:18.320] Like, really more tags. [14:18.420 --> 14:20.000] And we're talking billions of tags. [14:20.640 --> 14:25.940] Alice would have to do billions of hash operations in order to find the right tag. [14:25.940 --> 14:27.920] So, that doesn't scale. [14:28.060 --> 14:31.940] Here's a problem of scalability to real world. [14:32.500 --> 14:35.940] In academia and research, it looks nice, small scale. [14:36.180 --> 14:41.100] But then, when we talk deploying this to Walmart, every item being tagged, that's billions. [14:41.340 --> 14:42.240] So, that's not going to work. [14:44.720 --> 14:52.620] The next step to make this same protocol more scalable is the so-called tree of secrets. [14:52.620 --> 14:57.040] So, the idea now being, we run the protocol several times. [14:57.400 --> 15:01.960] And each time, we move down one level of the tree. [15:02.240 --> 15:04.640] So, we have a tree of nine tags here. [15:06.720 --> 15:08.520] And the protocol runs twice. [15:09.000 --> 15:13.600] So, on the first run, we again run this protocol with three keys. [15:13.600 --> 15:17.120] We find out that the purple key has been used. [15:17.320 --> 15:17.660] Yeah? [15:17.900 --> 15:19.100] And we run the protocol again. [15:19.560 --> 15:21.580] Find out, say, the... [15:21.580 --> 15:27.920] And now we know that the tag we are probing must be in the left third of the tree. [15:27.980 --> 15:29.220] We don't know which tag it is yet. [15:29.360 --> 15:31.800] But we can run the protocol again. [15:32.000 --> 15:35.840] And we find the tag that we are looking for. [15:35.840 --> 15:39.880] So, this tag obviously has to store both keys. [15:40.040 --> 15:45.260] It has to be able to generate both responses for both rounds of the protocol. [15:47.220 --> 15:49.720] The scalability is extremely improved. [15:49.920 --> 15:53.320] We don't have a linear number of hash operations anymore. [15:53.320 --> 15:58.440] Meaning, if we have billions of tags, billions of hash operations, we have a logarithmic number. [15:58.820 --> 16:00.320] Depending on the tree structure. [16:00.900 --> 16:04.920] What does putting a crypto processor on the tag do to the price? [16:05.760 --> 16:06.840] Good question. [16:08.820 --> 16:15.640] Using hash function as we know it, like some MD5 or SHA01, that's not going to work. [16:15.820 --> 16:17.860] That at least doubles the price. [16:17.980 --> 16:21.860] Plus, much more concerning, quarters the reading distance. [16:22.240 --> 16:25.400] Because you have to passively power the text. [16:25.400 --> 16:30.680] So, the more you compute, the more power you have to get to the tag. [16:30.860 --> 16:33.640] And since it's coming through induction, you have to get closer then. [16:34.240 --> 16:39.680] However, we might not really need hash functions in a computer science sense. [16:39.840 --> 16:42.420] What we do need is one-way functions. [16:42.780 --> 16:43.200] Yeah. [16:43.440 --> 16:48.620] And there's some proposals how to construct very cheap one-way functions. [16:48.620 --> 16:52.940] And so, we do, yes, we do have a communication overhead. [16:53.200 --> 16:55.820] But it might still be feasible. [16:56.160 --> 16:56.220] Yeah. [16:57.560 --> 16:58.720] Good question, thanks. [16:59.000 --> 17:00.140] Any more questions on that? [17:00.860 --> 17:01.820] Everybody with me? [17:02.460 --> 17:02.880] Good. [17:04.420 --> 17:10.660] So, this protocol allows us to scale to a large system. [17:11.360 --> 17:13.360] There is one issue with this protocol. [17:13.880 --> 17:15.240] Can anybody see an issue here? [17:17.960 --> 17:20.560] We share secrets among several tags. [17:20.840 --> 17:23.840] So, all the left tags have the purple key, right? [17:24.420 --> 17:29.000] That means if you can get the keys from the tags. [17:29.120 --> 17:30.520] And that's not too difficult, actually. [17:30.980 --> 17:31.660] You can... [17:31.660 --> 17:32.420] It's silicon. [17:34.020 --> 17:38.360] Well, I just noticed you have two keys on the tag for each level of protocol. [17:38.620 --> 17:40.620] What if you have, you know, a thousand... [17:40.620 --> 17:42.340] What if your tree is humongous? [17:43.240 --> 17:45.140] What you do is you... [17:45.140 --> 17:48.440] The branching factor is not three. [17:49.080 --> 17:49.560] It's... [17:49.560 --> 17:50.460] You can... [17:51.640 --> 17:53.100] With a tree... [17:53.100 --> 17:57.300] With like three to five tree levels, you can scale to billions of tags. [17:57.500 --> 17:59.200] So, you won't ever get over five. [17:59.440 --> 18:02.680] But still then, even five is extra cost. [18:02.880 --> 18:04.860] It's five times more memory for the keys. [18:05.020 --> 18:07.520] It's five times more communication back and forth. [18:07.520 --> 18:08.100] Yeah. [18:08.280 --> 18:08.680] So, yes. [18:08.920 --> 18:10.840] There is cost associated with it. [18:11.340 --> 18:11.860] But... [18:11.860 --> 18:12.340] It... [18:12.340 --> 18:12.900] It's feasible. [18:13.700 --> 18:18.400] Is reading these tags going to take longer than reading one with a single key? [18:18.600 --> 18:19.120] Yeah. [18:19.220 --> 18:19.860] The question is... [18:19.860 --> 18:21.700] Is reading going to take longer? [18:22.740 --> 18:23.260] Well... [18:23.260 --> 18:23.960] Yes. [18:24.420 --> 18:24.880] If... [18:25.300 --> 18:29.120] If you have three levels of the tree, it's going to take three times as long. [18:29.620 --> 18:30.140] Yeah. [18:32.380 --> 18:40.800] So, the issue with this tree, other than the associated extra cost, is you share secrets among several tags. [18:40.960 --> 18:43.280] And so, you can extract the keys from some of the tags. [18:43.820 --> 18:45.100] And you can... [18:45.100 --> 18:50.020] If you had already broken the tag on the left side, then you could... [18:50.020 --> 18:56.900] If you see the protocol going on, you could say whether the tag is using the purple key or not. [18:57.060 --> 18:58.240] Because you know the purple key now. [18:58.400 --> 18:59.280] So, you know whether the... [18:59.280 --> 18:59.660] The... [18:59.660 --> 19:02.620] The key is in the left third or not. [19:02.840 --> 19:03.140] Right? [19:03.400 --> 19:03.680] So... [19:03.680 --> 19:05.420] So, we did some math there and... [19:05.420 --> 19:06.200] And... [19:07.200 --> 19:07.660] Um... [19:07.660 --> 19:09.620] Looked into how many keys... [19:09.620 --> 19:12.760] How many tags you would need to break in order to... [19:12.760 --> 19:13.420] To... [19:13.420 --> 19:15.640] To get a sufficient information about the... [19:15.640 --> 19:16.220] The tags. [19:16.380 --> 19:17.140] And so, how... [19:17.140 --> 19:21.960] We define the information leakage as given in this graph is... [19:21.960 --> 19:26.660] If we can divide the group of tags into two subgroups... [19:26.660 --> 19:28.120] And put every... [19:28.120 --> 19:30.900] Place every tag in one of the groups, that's one bit. [19:31.180 --> 19:31.260] Yeah? [19:31.680 --> 19:33.280] If you have four groups, that's two bit. [19:33.460 --> 19:33.840] Three. [19:34.000 --> 19:37.080] So, if you could say male, female, that's one bit. [19:37.380 --> 19:37.680] Okay? [19:38.000 --> 19:44.280] If you could say male and female and above or below median salary, that's two bits. [19:45.840 --> 19:46.360] Um... [19:46.360 --> 19:47.560] It turns out that... [19:47.560 --> 19:49.540] This is highly simplified, but... [19:49.540 --> 19:49.940] If... [19:49.940 --> 19:54.260] If you break 20 tags under certain assumptions, you can track half of... [19:54.260 --> 19:55.300] Of tags in... [19:55.300 --> 19:57.560] Half of the tags in... [19:57.560 --> 19:58.460] Reasonable... [19:58.460 --> 19:59.180] Um... [19:59.180 --> 20:00.100] Attacker scenarios. [20:00.580 --> 20:01.600] So, that's... [20:01.600 --> 20:02.440] Very feasible. [20:02.880 --> 20:05.160] For somebody who wants to launch a... [20:05.160 --> 20:05.700] Um... [20:05.700 --> 20:06.760] Large scale attack. [20:08.820 --> 20:09.540] Um... [20:09.540 --> 20:11.980] So, we've seen... [20:11.980 --> 20:14.060] What do you mean by track in this case? [20:14.200 --> 20:18.140] Do you mean you could actually identify an individual tag? [20:18.140 --> 20:21.760] Or you could just sort of guess that it's probably the same tag as all that? [20:21.880 --> 20:22.380] Um... [20:22.380 --> 20:24.780] What you can do is you can break the... [20:24.780 --> 20:25.080] The... [20:25.080 --> 20:27.620] The tree of secrets into small groups. [20:28.100 --> 20:28.520] Yeah? [20:29.020 --> 20:29.400] Not... [20:29.400 --> 20:32.140] Not necessarily groups of one tag, but small groups. [20:32.400 --> 20:38.280] And then, if you have only one tag in this group, in your environment, you can uniquely identify it. [20:38.280 --> 20:45.120] So, it's not really seeing that tag, but distinguishing that tag from every other tag that you want to track. [20:45.340 --> 20:45.760] Okay? [20:46.860 --> 20:49.620] Which allows for linking to reading events. [20:50.460 --> 20:57.500] So, we've seen that on the protocol level, we have a scalability, a privacy trade-off. [20:57.500 --> 21:05.840] That's not really thought through yet, what the best tree setup would be if there is another option than the tree. [21:06.000 --> 21:07.200] It doesn't look like it. [21:07.600 --> 21:11.880] There has been research going on for several years now, and the tree is the best that we have so far. [21:12.180 --> 21:13.620] But there might be hope. [21:15.180 --> 21:26.000] But still, even if we had a protocol that would not allow for tracking at all, we would still be concerned with other levels of an RFID system. [21:26.680 --> 21:28.400] Privacy can leak at different levels. [21:28.820 --> 21:30.480] And what an RFID... [21:30.480 --> 21:34.380] Oh, we'll first talk about the physical level of privacy. [21:34.920 --> 21:43.280] So, the problem here is that if you have two different tags, you don't want them to be distinguishable, because if they were, you could link them. [21:43.620 --> 21:43.800] Right? [21:44.620 --> 21:46.860] On a physical level, that's difficult. [21:47.060 --> 21:49.200] Tags can look very different. [21:49.780 --> 21:52.760] These are some tags by alien technologies. [21:52.760 --> 21:55.440] They have extremely weirdly-looking antennas. [21:55.600 --> 21:59.960] But all of these tags must not be distinguishable. [22:01.100 --> 22:04.200] I don't see any way in which that would be possible. [22:04.480 --> 22:06.120] We did some experiments. [22:07.440 --> 22:13.100] You send some high-frequency radio waves, basically, to the tag. [22:13.100 --> 22:15.200] And you measure the reflection and absorption. [22:15.480 --> 22:17.520] And all of these tags look very different. [22:17.980 --> 22:19.400] And then, the ultimate difference. [22:19.660 --> 22:22.060] This is a schematic of a wedge. [22:22.300 --> 22:23.180] An RFID wedge. [22:23.580 --> 22:26.780] The antenna is a coil around the ferret core. [22:26.880 --> 22:28.700] So, it's a thicker tag. [22:29.020 --> 22:30.980] That is what is in your car keys. [22:31.140 --> 22:32.160] It's more reliable. [22:32.160 --> 22:38.220] And there's no way in which you can make this indistinguishable from, like, a printed tag. [22:38.600 --> 22:38.920] Right? [22:39.660 --> 22:42.260] So, big issues with RFID privacy here. [22:42.480 --> 22:44.440] Nobody really has a solution to that yet. [22:45.960 --> 22:51.060] Another level at which we can attack privacy is the system level. [22:51.060 --> 22:56.220] And an RFID system looks as this slide shows you. [22:56.520 --> 22:59.840] You've already seen the tags on the left and the reading devices. [23:00.060 --> 23:06.700] But the reading devices itself are only connecting into a bigger network. [23:06.700 --> 23:09.060] So, the probes of a bigger network. [23:09.500 --> 23:11.300] The reading device gets the number. [23:11.300 --> 23:12.920] It has to make use of it. [23:12.920 --> 23:16.100] So, it has to find the database. [23:16.100 --> 23:17.760] It has to look up a database. [23:20.240 --> 23:23.840] And then get the information on that tag from the database. [23:24.120 --> 23:25.880] So, the object namespace. [23:26.100 --> 23:31.260] It's not only a very similar name to the DNS, the domain namespace service. [23:31.760 --> 23:33.340] It's basically the same service. [23:33.500 --> 23:36.020] So, the ONS is built on top of the DNS. [23:36.020 --> 23:44.040] And how the ONS works is given this three-part identifier. [23:44.040 --> 23:45.420] The manufacturer ID. [23:45.520 --> 23:46.220] The product ID. [23:46.380 --> 23:47.840] And the unique serial number. [23:48.080 --> 23:49.720] The tag sends that to the reader. [23:50.120 --> 23:52.800] The reader now wants to look up information on the product. [23:52.820 --> 23:54.900] Which is stored at the manufacturer site. [23:55.360 --> 23:57.580] The unique information is stored locally. [23:57.940 --> 23:58.680] So, on the product. [23:58.980 --> 24:03.140] Therefore, it discards the serial number. [24:04.540 --> 24:08.660] Sends that remaining piece of information. [24:08.820 --> 24:09.760] The manufacturer ID. [24:09.940 --> 24:10.540] And the product ID. [24:10.900 --> 24:11.760] Into the ONS. [24:11.920 --> 24:14.420] And the ONS is really doing a DNS query. [24:14.580 --> 24:16.940] It resolves a name to an IP address. [24:17.340 --> 24:17.420] Right? [24:17.800 --> 24:20.620] So, we want to get an IP address for a database. [24:20.820 --> 24:22.080] That we can get information from. [24:22.360 --> 24:24.680] And it does that by just looking up. [24:24.800 --> 24:27.680] Which server is associated with that manufacturer ID. [24:28.240 --> 24:29.980] And then querying that server. [24:31.260 --> 24:35.500] And querying what databases associated with that product. [24:35.640 --> 24:36.860] A hierarchical system. [24:37.060 --> 24:39.120] Again, for the reason of scalability. [24:39.560 --> 24:40.460] Billions of tags. [24:40.640 --> 24:41.500] Millions of readers. [24:41.840 --> 24:43.220] Our idea is going to be huge. [24:43.500 --> 24:45.360] So, we need something hierarchical here. [24:46.200 --> 24:48.760] The ONS is going to point to some database. [24:48.900 --> 24:50.040] Given the IP address. [24:50.420 --> 24:53.880] And then the reader sends over that identifier. [24:54.300 --> 24:56.100] And gets the product specific information. [24:56.500 --> 24:56.720] Right? [24:56.720 --> 25:02.320] So, this is what EPC Global envisions large scale systems to look like. [25:03.320 --> 25:06.060] Here's an attack on the ONS. [25:06.200 --> 25:07.540] A privacy intruding attack. [25:08.040 --> 25:10.960] Again, Alice is roaming. [25:11.340 --> 25:12.960] And her tags are being queried. [25:13.480 --> 25:17.180] And now the reading devices have to go into the ONS. [25:17.320 --> 25:21.480] And find a server that has the pointer that they need. [25:21.760 --> 25:21.880] Okay? [25:21.880 --> 25:23.720] So, they get the pointer. [25:23.940 --> 25:25.340] They might use different servers. [25:25.560 --> 25:26.940] Different readers might use... [25:26.940 --> 25:28.020] Actually, they will. [25:28.340 --> 25:29.120] They have to. [25:29.500 --> 25:30.020] Because... [25:30.020 --> 25:31.320] For reasons of scalability. [25:31.720 --> 25:33.300] That's why we have DNS. [25:33.560 --> 25:33.660] Right? [25:34.060 --> 25:34.580] Scalability. [25:35.260 --> 25:35.780] Not... [25:35.780 --> 25:38.520] Millions of readers can't use the same server. [25:38.760 --> 25:42.500] So, what if now the attacker controls this... [25:43.660 --> 25:44.300] Um... [25:44.300 --> 25:44.880] This server. [25:45.140 --> 25:47.560] That the information is looked up from. [25:48.520 --> 25:49.160] Um... [25:49.160 --> 25:52.380] He will see incoming queries from different DNS servers. [25:52.680 --> 25:52.780] Right? [25:53.340 --> 25:53.980] So... [25:53.980 --> 25:54.780] And based on that. [25:54.980 --> 25:58.440] Having a linking between reading location and DNS server. [25:58.940 --> 26:01.040] The server knows where Alice is. [26:01.420 --> 26:03.920] It's delivered to your door for free. [26:04.060 --> 26:04.560] That information. [26:05.060 --> 26:07.180] Queries are coming in from different locations. [26:07.180 --> 26:08.060] And... [26:08.060 --> 26:08.620] You can... [26:08.620 --> 26:09.220] You can track. [26:09.500 --> 26:10.260] Just based on that. [26:11.840 --> 26:12.440] This... [26:12.440 --> 26:13.460] Um... [26:13.460 --> 26:17.620] This scenario has two assumptions that might not be legitimate. [26:17.860 --> 26:20.740] And we'll relax those assumptions and see that the tag still works. [26:20.940 --> 26:25.380] The first assumption being that the attacker does control one of these servers. [26:25.600 --> 26:25.660] Yeah? [26:26.780 --> 26:30.840] It's kind of likely since every small manufacturer who... [26:30.840 --> 26:35.120] Who somehow is involved with RFID will need their own servers. [26:35.120 --> 26:38.500] So chances are everybody has access to it. [26:38.580 --> 26:39.120] Or... [26:39.120 --> 26:39.960] Can hack into one. [26:40.560 --> 26:41.000] Um... [26:41.000 --> 26:43.120] The second assumption is that we can... [26:43.120 --> 26:44.540] We can... [26:44.540 --> 26:45.640] Give Alice a tag. [26:46.100 --> 26:46.740] That... [26:46.740 --> 26:48.560] That resolves to that server. [26:48.780 --> 26:50.260] That might be less likely. [26:50.420 --> 26:52.040] So we would really have to... [26:52.040 --> 26:52.880] To... [26:52.880 --> 26:53.460] Tag her. [26:53.780 --> 26:53.940] Right? [26:55.260 --> 26:55.900] Um... [26:55.900 --> 26:58.520] Relax those and advance the tag on the ONS. [26:58.760 --> 27:01.320] In which again, Alice... [27:01.320 --> 27:02.080] Um... [27:02.080 --> 27:03.520] Is queried by reading device. [27:04.440 --> 27:05.080] Um... [27:05.120 --> 27:07.540] The reading device looks up the information and... [27:07.540 --> 27:09.700] So the ONS returns the pointer. [27:09.960 --> 27:10.260] Right? [27:10.380 --> 27:11.020] First to the... [27:11.020 --> 27:12.620] To the querying DNS server. [27:12.960 --> 27:13.880] And then back to the reader. [27:15.720 --> 27:16.240] Um... [27:16.240 --> 27:17.340] And now this attack base... [27:17.700 --> 27:18.700] Is based on... [27:18.700 --> 27:21.640] Something that I've seen by Dan Kaminsky last year. [27:21.900 --> 27:23.960] Who has seen Dan Kaminsky's talk last year? [27:24.880 --> 27:25.240] Yeah? [27:25.480 --> 27:26.860] Where he played around with DNS. [27:28.180 --> 27:28.700] Um... [27:28.700 --> 27:29.180] So what... [27:29.180 --> 27:30.160] What he did was he... [27:30.160 --> 27:30.520] He... [27:30.520 --> 27:32.640] Did build a list of all DNS servers. [27:32.900 --> 27:33.140] And I... [27:33.140 --> 27:34.340] I mean all DNS servers. [27:34.440 --> 27:34.680] He... [27:34.680 --> 27:38.280] Just sent out queries to all IP addresses possible. [27:38.920 --> 27:39.360] And... [27:39.360 --> 27:41.360] Look whether there was a DNS server. [27:42.420 --> 27:42.980] Um... [27:42.980 --> 27:44.980] What he used this list for was... [27:44.980 --> 27:45.720] When the... [27:45.720 --> 27:46.640] The Sony... [27:46.640 --> 27:47.060] Um... [27:47.060 --> 27:47.640] Audio CDs. [27:47.960 --> 27:48.840] Had the rootkit. [27:49.320 --> 27:50.140] And Sony claimed... [27:50.140 --> 27:52.540] There's only so few computers infected. [27:52.900 --> 27:54.980] He queried all these DNS servers. [27:55.280 --> 27:57.420] All publicly accessible DNS servers. [27:57.640 --> 27:58.220] For whether... [27:59.600 --> 28:00.200] The... [28:00.200 --> 28:02.680] The domain name of that rootkit was cached. [28:02.900 --> 28:04.600] And it's cached for like... [28:04.600 --> 28:05.540] An hour or something. [28:05.700 --> 28:06.400] Maybe ten minutes. [28:06.700 --> 28:07.300] That's... [28:07.300 --> 28:08.620] That's different for different names. [28:08.840 --> 28:10.120] So what he found that... [28:10.120 --> 28:12.440] There's more servers that cache that name. [28:13.340 --> 28:13.940] Than... [28:13.940 --> 28:15.140] Sony would admit... [28:15.760 --> 28:16.880] Computers were infected. [28:16.880 --> 28:17.560] Right? [28:19.040 --> 28:20.020] So what... [28:20.020 --> 28:21.680] What we can use this attack for now. [28:23.240 --> 28:23.920] The... [28:23.920 --> 28:23.940] The... [28:24.640 --> 28:25.320] Um... [28:25.320 --> 28:25.600] The... [28:25.600 --> 28:26.180] The... [28:26.180 --> 28:28.760] Once we did resolve an RFID tag. [28:29.220 --> 28:30.140] With that system. [28:30.500 --> 28:30.940] Um... [28:30.940 --> 28:31.360] The... [28:31.880 --> 28:34.740] The information is cached for some time period. [28:35.260 --> 28:35.940] Um... [28:35.940 --> 28:38.680] On all DNS servers on the way to... [28:38.680 --> 28:41.280] To the DNS server that the information actually came from. [28:41.640 --> 28:43.520] So an attacker can now... [28:43.520 --> 28:46.860] Query different DNS servers for whether that piece of information... [28:46.880 --> 28:47.500] Is cached. [28:47.680 --> 28:48.100] Right? [28:48.680 --> 28:50.060] It's a totally passive attack. [28:50.180 --> 28:50.880] We don't control... [28:51.760 --> 28:52.080] Any... [28:52.400 --> 28:52.580] Computer. [28:52.720 --> 28:53.440] We didn't hack... [28:53.440 --> 28:54.540] We didn't... [28:54.540 --> 28:55.980] Attach anything to Alice. [28:56.180 --> 28:57.740] We just ask... [28:57.740 --> 29:00.140] Different DNS servers whether they cache that... [29:00.140 --> 29:00.960] That record. [29:01.840 --> 29:02.160] And... [29:02.460 --> 29:03.880] A scenario could be... [29:04.820 --> 29:05.140] Hmm... [29:05.460 --> 29:05.940] Say... [29:05.940 --> 29:07.320] Who uses easy pass? [29:07.600 --> 29:09.300] Or who knows easy pass? [29:09.300 --> 29:09.380] Yes. [29:10.420 --> 29:11.140] So... [29:11.140 --> 29:15.700] They already use RFID technology active tags for more reading range. [29:15.840 --> 29:16.220] But... [29:16.220 --> 29:17.780] Let's say that they would... [29:17.780 --> 29:21.200] For some reason start probing RFID tags for... [29:21.200 --> 29:21.960] Say... [29:21.960 --> 29:25.400] Governmentally induced surveillance or... [29:25.400 --> 29:26.120] Whatever. [29:27.940 --> 29:28.660] Um... [29:28.660 --> 29:30.440] If we now had a... [29:30.440 --> 29:30.880] Um... [29:30.880 --> 29:31.660] Unique... [29:31.660 --> 29:32.300] Car. [29:32.640 --> 29:34.240] And the car being four wheels. [29:34.400 --> 29:35.600] They have RFID tags already. [29:35.600 --> 29:36.600] The car itself. [29:36.800 --> 29:37.640] Maybe the model number. [29:37.920 --> 29:38.860] If we knew... [29:38.860 --> 29:39.020] This... [29:39.020 --> 29:39.580] This car type. [29:39.680 --> 29:40.460] Alice's car type. [29:40.860 --> 29:41.160] And... [29:41.160 --> 29:42.440] Easy pass... [29:42.440 --> 29:44.100] Passing through each of these gates. [29:44.320 --> 29:45.480] Would resolve the name. [29:45.700 --> 29:46.960] Of all these tags. [29:47.120 --> 29:48.900] We would just query the DNS servers. [29:49.080 --> 29:50.140] At these locations. [29:50.380 --> 29:51.840] For whether they cached... [29:51.840 --> 29:52.640] These... [29:52.640 --> 29:53.160] Five records. [29:54.140 --> 29:54.460] Right? [29:55.060 --> 29:55.580] So... [29:55.580 --> 29:56.200] We could... [29:56.200 --> 29:56.860] We could... [29:56.860 --> 29:58.820] By just sending out few DNS queries. [29:59.040 --> 29:59.560] Every... [29:59.560 --> 30:00.360] Five or ten minutes. [30:00.700 --> 30:02.380] Know where Alice is driving. [30:03.040 --> 30:03.500] Okay? [30:06.220 --> 30:06.740] Well... [30:09.020 --> 30:10.060] To conclude... [30:11.400 --> 30:11.920] On... [30:11.920 --> 30:13.320] The physical layer. [30:13.820 --> 30:15.820] There is no hope whatsoever. [30:16.080 --> 30:16.880] That we could... [30:17.520 --> 30:18.040] Ever... [30:18.040 --> 30:19.960] Not leak any information. [30:21.120 --> 30:23.000] Tags will be distinguishable. [30:23.160 --> 30:24.580] And if you only get out... [30:24.580 --> 30:25.700] Like say two bits. [30:26.100 --> 30:27.760] Breaking the tags into four groups. [30:27.860 --> 30:29.080] The small ones and the big ones. [30:29.180 --> 30:30.440] The wedges and some other group. [30:30.580 --> 30:31.340] You get two bits. [30:31.340 --> 30:31.680] Then... [30:31.680 --> 30:33.160] You run the tree protocol. [30:33.420 --> 30:34.480] We have seen the... [30:34.480 --> 30:35.060] The chart. [30:35.280 --> 30:36.960] You get another four or five bits. [30:37.240 --> 30:38.260] That's enough for... [30:38.260 --> 30:38.800] For an attack. [30:39.000 --> 30:39.280] So... [30:39.280 --> 30:39.640] These... [30:39.640 --> 30:40.920] These layers can add up. [30:41.100 --> 30:41.820] And then... [30:41.820 --> 30:42.480] The system layer. [30:42.600 --> 30:42.720] Okay. [30:42.780 --> 30:44.300] That's just very naive too. [30:44.400 --> 30:45.760] To think we can... [30:45.760 --> 30:46.820] Use the DNS. [30:47.200 --> 30:48.400] For reasons of scale. [30:48.880 --> 30:49.440] Without... [30:49.440 --> 30:50.820] Much of a change. [30:51.300 --> 30:51.660] And... [30:53.620 --> 30:55.560] Use RFID on that. [30:55.780 --> 30:55.980] It... [30:55.980 --> 30:56.540] It... [30:56.540 --> 30:57.520] It will leak information. [30:57.740 --> 30:58.040] And... [30:58.040 --> 30:59.020] If you... [30:59.020 --> 30:59.840] If we only... [30:59.840 --> 31:01.420] Program our front end. [31:01.720 --> 31:02.920] As an RFID application. [31:03.120 --> 31:04.760] And then use infrastructure that exists. [31:05.220 --> 31:05.780] That's... [31:05.780 --> 31:07.140] Not gonna... [31:07.140 --> 31:08.220] Work privately. [31:09.060 --> 31:09.580] Um... [31:09.580 --> 31:10.620] The only... [31:10.620 --> 31:12.680] Forces that I can see that would... [31:13.720 --> 31:15.380] Enforce RFID privacy. [31:15.380 --> 31:16.460] Obviously there's three of them. [31:17.000 --> 31:17.520] First... [31:17.520 --> 31:18.380] Would be legislation. [31:19.260 --> 31:20.320] California for example. [31:20.500 --> 31:21.020] Passed law. [31:21.440 --> 31:21.960] Legislation. [31:22.140 --> 31:23.680] This year I believe that... [31:23.680 --> 31:25.180] This allows the... [31:25.180 --> 31:27.660] The use of RFID and governmental IDs. [31:28.280 --> 31:29.940] Including driver's license and all that. [31:30.020 --> 31:31.560] But it's only for the next two years. [31:31.660 --> 31:32.520] Then they will reconsider. [31:32.820 --> 31:33.420] So there... [31:33.420 --> 31:35.380] There is hope that lawmakers... [31:36.300 --> 31:38.120] Understand the problematic and... [31:38.120 --> 31:38.900] And we'll work on that. [31:39.140 --> 31:40.340] Maybe not big hope. [31:41.640 --> 31:42.160] Um... [31:42.160 --> 31:44.380] The second force would be customer demand. [31:44.380 --> 31:45.420] That people... [31:45.420 --> 31:46.140] Say... [31:46.140 --> 31:47.780] We're not gonna buy at Walmart anymore. [31:47.900 --> 31:48.460] Unless you... [31:48.460 --> 31:50.200] You guarantee us that you kill the tax. [31:50.340 --> 31:51.660] Or do something else to it. [31:52.340 --> 31:54.140] I don't think that's gonna work either. [31:54.820 --> 31:55.960] People don't care. [31:57.500 --> 31:59.000] People use credit cards. [32:00.300 --> 32:01.740] I do use credit cards. [32:02.360 --> 32:03.180] The third... [32:03.180 --> 32:04.680] The third force would be... [32:04.680 --> 32:05.280] Um... [32:05.280 --> 32:06.420] Corporate intelligence. [32:07.500 --> 32:08.420] Something that... [32:08.420 --> 32:09.020] That... [32:09.020 --> 32:10.900] Many companies haven't thought about yet. [32:11.320 --> 32:11.540] The... [32:11.540 --> 32:13.200] The threat would be that... [32:13.200 --> 32:15.560] Say some target employee... [32:15.560 --> 32:16.640] Walks through Walmart... [32:16.640 --> 32:17.460] Twice a day... [32:17.460 --> 32:18.020] Scans all their... [32:18.020 --> 32:19.700] All their aisles... [32:19.700 --> 32:21.640] For which products they have on stock. [32:22.040 --> 32:22.500] So... [32:22.500 --> 32:23.080] Um... [32:23.080 --> 32:23.900] They would see... [32:23.900 --> 32:25.080] How much they sold... [32:25.080 --> 32:26.540] From the morning till the afternoon. [32:26.760 --> 32:27.280] And so they... [32:27.280 --> 32:28.120] They could... [32:28.120 --> 32:28.780] Um... [32:28.780 --> 32:30.320] Get internal business data. [32:30.560 --> 32:30.760] Right? [32:30.920 --> 32:32.760] If companies understand that... [32:32.760 --> 32:34.180] This threat exists... [32:34.180 --> 32:35.760] The companies might request it. [32:36.120 --> 32:36.680] Then... [32:36.680 --> 32:38.400] That and legislation... [32:38.400 --> 32:39.320] Are really the only... [32:39.320 --> 32:40.000] Two... [32:40.000 --> 32:40.980] Things that I see... [32:40.980 --> 32:42.720] That we will get RFID privacy. [32:44.160 --> 32:44.600] Well... [32:44.600 --> 32:45.140] Thank you... [32:45.520 --> 32:46.320] So much for your attention. [32:46.640 --> 32:47.080] And... [32:47.080 --> 32:48.660] I'll be happy to take some questions now. [32:50.740 --> 32:52.200] From what you just showed... [32:52.200 --> 32:53.440] With the multi-layer... [32:56.680 --> 32:57.120] Uh... [32:57.120 --> 32:58.000] From what... [32:58.000 --> 32:58.260] Uh... [32:58.260 --> 33:00.140] You just showed with the multi-layer... [33:00.140 --> 33:00.360] Uh... [33:00.360 --> 33:01.020] Problems for... [33:01.020 --> 33:02.000] With the privacy... [33:02.880 --> 33:03.320] Um... [33:03.320 --> 33:04.480] It seemed like... [33:04.480 --> 33:04.980] Uh... [33:04.980 --> 33:06.000] There... [33:06.000 --> 33:06.600] You know... [33:06.600 --> 33:08.020] Other than the protocol layer... [33:08.020 --> 33:09.440] That there is no privacy... [33:09.440 --> 33:10.340] And... [33:10.340 --> 33:11.200] Yeah... [33:11.200 --> 33:12.080] At research... [33:12.080 --> 33:12.340] So... [33:12.340 --> 33:12.800] Well... [33:12.800 --> 33:13.940] On the protocol layer... [33:13.940 --> 33:15.140] There is no privacy either. [33:15.440 --> 33:16.660] These are research results... [33:16.660 --> 33:17.420] Things that... [33:17.420 --> 33:18.840] We, academia... [33:18.840 --> 33:19.540] Would... [33:19.540 --> 33:20.780] Want to see... [33:21.320 --> 33:21.800] Nobody... [33:21.800 --> 33:23.420] Pays an extra cent... [33:23.420 --> 33:24.300] A cent for that yet. [33:25.000 --> 33:25.620] Um... [33:25.620 --> 33:27.720] Research has not really been done... [33:27.720 --> 33:28.600] In the other fields. [33:29.600 --> 33:30.220] Plus... [33:30.220 --> 33:31.400] There is no obvious... [33:31.400 --> 33:32.560] Straightforward solutions... [33:32.560 --> 33:33.180] To be honest. [33:37.490 --> 33:38.410] I know... [33:38.410 --> 33:38.870] Uh... [33:38.870 --> 33:40.310] Some states are going to... [33:40.310 --> 33:41.550] Using RFIDs... [33:41.550 --> 33:42.030] And... [33:42.650 --> 33:43.130] Licenses... [33:43.130 --> 33:43.610] Or at least... [33:43.610 --> 33:44.230] That's a consideration. [33:44.770 --> 33:45.110] Yeah. [33:45.430 --> 33:46.890] If they start enforcing... [33:46.890 --> 33:48.030] The use of those... [33:48.030 --> 33:48.750] Tags... [33:49.270 --> 33:50.230] Are there gonna be... [33:50.230 --> 33:51.370] Any known consequences... [33:51.370 --> 33:52.670] For jamming those signals... [33:52.670 --> 33:53.570] If you did not want... [33:53.570 --> 33:54.530] Your information out there? [33:54.930 --> 33:55.810] Jamming the signals... [33:55.810 --> 33:57.130] Or even just... [33:57.130 --> 33:57.710] Blocking... [33:58.370 --> 33:58.630] Like... [33:58.630 --> 33:59.710] When you put it in your wallet... [33:59.710 --> 34:00.690] Blocking it from... [34:01.310 --> 34:01.550] From... [34:01.550 --> 34:02.690] You can block it. [34:02.870 --> 34:04.730] What you can also do is... [34:04.730 --> 34:05.550] Um... [34:05.550 --> 34:06.830] You're not required... [34:06.830 --> 34:06.990] To... [34:06.990 --> 34:07.530] To have... [34:07.530 --> 34:09.010] A working tag in your IDs. [34:09.270 --> 34:10.030] European passports. [34:10.090 --> 34:10.590] I'm from Germany. [34:10.730 --> 34:12.230] My passport has an... [34:12.230 --> 34:13.010] RFID tag in it. [34:14.110 --> 34:14.550] Um... [34:14.550 --> 34:15.010] There is... [34:15.570 --> 34:16.110] Unmanufacturing time... [34:16.110 --> 34:16.670] That put one in. [34:16.770 --> 34:17.850] That doesn't mean that... [34:17.850 --> 34:19.150] Once you pass a border... [34:19.150 --> 34:19.890] It still has to work. [34:20.090 --> 34:21.290] Two seconds of microwave. [34:21.590 --> 34:22.490] Do a good job there. [34:22.850 --> 34:23.290] So... [34:24.710 --> 34:26.370] Passports are valid for ten years. [34:26.370 --> 34:26.890] I... [34:26.890 --> 34:28.190] I don't believe... [34:28.190 --> 34:29.310] Many RFID tags... [34:29.310 --> 34:30.450] Will work for ten years. [34:30.810 --> 34:31.070] That... [34:31.070 --> 34:32.270] The connection between the chip... [34:32.270 --> 34:33.710] And the antenna is kind of... [34:33.710 --> 34:34.250] Fragile. [34:34.490 --> 34:34.750] And... [34:34.750 --> 34:35.690] That's gonna break... [34:35.690 --> 34:36.170] At some point. [34:36.250 --> 34:37.410] So you can just speed that... [34:37.410 --> 34:37.990] Process up. [34:37.990 --> 34:38.510] Yeah. [34:38.850 --> 34:39.130] I was... [34:39.130 --> 34:40.530] Just curious about that. [34:40.710 --> 34:41.490] Because, you know... [34:41.490 --> 34:42.010] I think... [34:42.770 --> 34:43.170] If... [34:43.170 --> 34:45.030] You have a long line of people... [34:45.030 --> 34:45.850] With RFIDs... [34:45.850 --> 34:46.890] And you're picking up a signal... [34:46.890 --> 34:47.570] From every one of them. [34:47.630 --> 34:48.690] And suddenly somebody... [34:48.690 --> 34:49.470] Doesn't have a signal. [34:49.730 --> 34:51.010] It would look kind of suspicious. [34:51.270 --> 34:51.610] But I... [34:51.610 --> 34:52.710] That was my only thought. [34:53.210 --> 34:53.550] Mm-hmm. [34:53.690 --> 34:54.090] That... [34:54.090 --> 34:54.890] That might... [34:54.890 --> 34:56.150] That might be the case then. [34:56.510 --> 34:56.910] That... [34:56.910 --> 34:57.130] Yeah. [34:57.490 --> 34:58.130] That you... [34:58.130 --> 34:59.610] You are double checked... [34:59.610 --> 35:00.730] At the border crossing then. [35:00.850 --> 35:02.570] If your RFID tag isn't working probably. [35:03.110 --> 35:03.270] Yeah. [35:03.430 --> 35:04.470] But jamming too. [35:04.530 --> 35:05.710] To come back to your first question. [35:06.030 --> 35:06.870] Jamming is illegal. [35:06.870 --> 35:09.470] So every device that operates in these frequencies... [35:09.470 --> 35:10.250] Um... [35:10.250 --> 35:11.070] Does need some... [35:11.070 --> 35:12.710] Some FCC approval. [35:13.270 --> 35:13.350] Yeah. [35:13.450 --> 35:15.090] And they won't approve jamming devices. [35:15.190 --> 35:15.930] They won't like that. [35:16.190 --> 35:16.290] Yeah. [35:17.010 --> 35:17.310] Mm-hmm. [35:17.590 --> 35:18.470] Any further questions? [35:18.550 --> 35:19.310] Come up here. [35:19.370 --> 35:20.110] If you have a question. [35:21.850 --> 35:22.410] Well... [35:22.410 --> 35:27.830] What about the possibility of duplicate RFIDs as forgeries for God knows what? [35:28.190 --> 35:28.490] Yeah. [35:29.950 --> 35:30.510] Um... [35:30.510 --> 35:32.230] Companies as Gillette that... [35:32.870 --> 35:33.270] That... [35:33.270 --> 35:34.610] Now use... [35:35.950 --> 35:36.510] Um... [35:36.510 --> 35:38.570] Use RFID tags to track every single item. [35:38.690 --> 35:39.890] Or companies like Prada. [35:40.150 --> 35:40.430] Who... [35:40.430 --> 35:42.670] Who wants to put RFID tags in the hand bags. [35:42.890 --> 35:43.410] In the purses. [35:43.850 --> 35:44.110] Um... [35:44.110 --> 35:44.650] To... [35:44.650 --> 35:45.210] To... [35:45.210 --> 35:46.310] To make them... [35:47.110 --> 35:47.650] Um... [35:47.650 --> 35:49.070] Cloning resistant basically. [35:49.670 --> 35:51.510] They so far rely on... [35:51.510 --> 35:51.930] The... [35:51.930 --> 35:53.830] The not understanding RFID technology. [35:54.110 --> 35:56.510] Nobody can make a tag that sends out the same number. [35:56.730 --> 35:57.350] Sure they can. [35:57.490 --> 35:58.170] So that's the... [35:58.170 --> 36:00.370] The issue of RFID security. [36:00.370 --> 36:02.470] You can use the same protocols. [36:02.650 --> 36:03.230] The protocol... [36:03.230 --> 36:04.030] The privacy... [36:04.030 --> 36:04.550] Um... [36:04.550 --> 36:05.070] Protocol... [36:05.070 --> 36:05.550] Oh... [36:05.550 --> 36:06.050] That I... [36:06.050 --> 36:06.950] That I showed you. [36:08.950 --> 36:09.590] Um... [36:09.590 --> 36:10.710] Not only... [36:11.290 --> 36:11.610] Um... [36:12.350 --> 36:12.670] Oh... [36:13.370 --> 36:15.130] This allows tracking. [36:15.510 --> 36:17.730] It also guarantees security. [36:18.030 --> 36:20.230] Because you prove that you have the key. [36:20.650 --> 36:20.850] Right? [36:21.210 --> 36:22.290] So it's... [36:22.290 --> 36:22.490] The... [36:22.490 --> 36:24.070] The response... [36:24.070 --> 36:26.530] Relies on the secrecy of the key. [36:26.530 --> 36:27.490] For both privacy. [36:27.670 --> 36:28.830] But also for authenticity. [36:30.490 --> 36:31.010] So it is... [36:31.010 --> 36:31.650] It is possible. [36:31.790 --> 36:32.350] And privacy. [36:32.450 --> 36:33.190] So far. [36:33.370 --> 36:34.870] Seems like the bigger challenge. [36:35.110 --> 36:36.250] If you achieve privacy. [36:36.510 --> 36:38.130] You automatically get authenticity. [36:41.390 --> 36:41.870] Um... [36:41.870 --> 36:43.010] Kind of a two part question. [36:43.290 --> 36:43.570] Uh... [36:43.570 --> 36:44.710] First off on the... [36:44.710 --> 36:45.850] Like passive jamming. [36:45.910 --> 36:47.690] Or having a random number generating tag. [36:48.350 --> 36:49.030] Are those all... [36:49.030 --> 36:50.830] Are the tags themselves FCC? [36:51.570 --> 36:53.090] Do they have to be FCC certified? [36:53.270 --> 36:54.910] Or is it only the broadcaster boxes? [36:54.910 --> 36:56.010] The readers. [36:56.250 --> 36:57.210] That have to be FCC. [36:58.130 --> 36:58.390] Um... [36:58.390 --> 37:00.490] Usually you get a verification on the whole system. [37:00.670 --> 37:00.930] There's... [37:00.930 --> 37:03.110] There's no company that just makes RFID tags. [37:03.250 --> 37:04.410] They always... [37:04.410 --> 37:06.450] Sell you the whole package. [37:07.090 --> 37:07.390] But... [37:07.870 --> 37:09.690] So the FCC approval. [37:10.110 --> 37:10.490] Um... [37:10.490 --> 37:12.890] Basically checks whether you... [37:12.890 --> 37:15.430] You stay below certain thresholds. [37:16.370 --> 37:17.050] Of... [37:17.050 --> 37:17.670] Ray... [37:17.670 --> 37:18.030] Radio waves. [37:18.390 --> 37:19.350] And since the... [37:19.350 --> 37:20.510] The reading device. [37:20.970 --> 37:22.970] Blasts out a lot of energy. [37:22.970 --> 37:24.410] And the tag only responds. [37:24.590 --> 37:25.350] Very, very silent. [37:25.570 --> 37:25.810] There... [37:25.810 --> 37:28.310] There's no way in which you could build an RFID tag. [37:28.470 --> 37:30.410] That doesn't get FCC approval. [37:31.290 --> 37:31.570] Yeah. [37:31.690 --> 37:32.190] So it's... [37:32.190 --> 37:33.190] You're more concerned with... [37:33.190 --> 37:34.210] With reading ranges. [37:34.410 --> 37:36.570] And making the reader as powerful as possible. [37:36.710 --> 37:36.850] Okay. [37:36.950 --> 37:39.670] And the second question I had was about the encryption systems. [37:40.370 --> 37:40.650] Uh... [37:40.650 --> 37:41.330] Error checking. [37:41.570 --> 37:42.470] That's gonna be... [37:42.470 --> 37:44.130] Throwing in a lot of problems. [37:44.350 --> 37:44.710] If you know... [37:44.710 --> 37:47.830] If they're not getting accurate bits back from the tags. [37:47.830 --> 37:48.710] You're... [37:48.710 --> 37:49.390] The... [37:49.390 --> 37:51.110] The readers are not gonna have all sorts of problems. [37:51.290 --> 37:51.710] Yeah. [37:51.770 --> 37:52.590] Error checking. [37:53.730 --> 37:54.190] Um... [37:54.190 --> 37:54.530] In... [37:54.530 --> 37:55.390] In most standards, that's... [37:55.390 --> 37:57.230] That's a level below the protocol level. [37:57.430 --> 37:58.570] Like a data link layer. [37:58.910 --> 38:01.550] Which then again could leak information. [38:02.090 --> 38:02.190] There... [38:02.190 --> 38:03.070] There's a problem there. [38:03.190 --> 38:03.390] Sure. [38:03.550 --> 38:03.650] Yeah. [38:03.790 --> 38:04.230] So you... [38:04.230 --> 38:04.510] You would... [38:04.510 --> 38:06.430] You would put some red... [38:06.430 --> 38:06.910] And see... [38:06.910 --> 38:07.470] And it... [38:07.470 --> 38:10.030] Submit some more bits to make sure it's understood well. [38:10.890 --> 38:11.070] Okay. [38:11.210 --> 38:13.570] A couple questions about the powering system. [38:13.570 --> 38:14.010] Uh... [38:14.010 --> 38:16.430] I take it they blast it with RF and then... [38:16.430 --> 38:18.710] And then it's rectified or something that... [38:18.710 --> 38:19.210] And they... [38:19.210 --> 38:20.830] And it transmits off that... [38:20.830 --> 38:21.570] Uh... [38:21.570 --> 38:23.350] DC power from the rectified RF. [38:23.810 --> 38:24.070] Is... [38:24.070 --> 38:26.650] Is there any frequency range that they use... [38:26.650 --> 38:26.850] Uh... [38:26.850 --> 38:27.890] That's common for... [38:27.890 --> 38:28.610] For the... [38:28.610 --> 38:29.230] The blast... [38:29.230 --> 38:31.950] I think the easy pass is usually use 900 megahertz. [38:32.310 --> 38:34.610] There is tags that use 900 megahertz. [38:34.810 --> 38:37.510] More common is 13.56 megahertz. [38:37.710 --> 38:37.890] Oh. [38:38.150 --> 38:38.590] Um... [38:38.590 --> 38:38.970] That's... [38:38.970 --> 38:40.150] That's the... [38:40.770 --> 38:41.350] Um... [38:41.350 --> 38:43.210] ISO 14443 standard. [38:43.530 --> 38:44.690] That Philips introduced. [38:45.090 --> 38:45.270] Basically. [38:46.190 --> 38:46.770] Um... [38:46.770 --> 38:47.310] The... [38:47.310 --> 38:50.280] The trade-off with lower and higher frequencies is... [38:51.310 --> 38:51.890] Um... [38:51.890 --> 38:52.330] The... [38:52.330 --> 38:54.150] The higher you go in your frequencies... [38:55.710 --> 38:56.290] Um... [38:56.290 --> 38:56.570] The... [38:56.570 --> 38:58.050] The more costly the tag is. [38:58.410 --> 38:58.770] But... [38:58.770 --> 38:59.250] The... [38:59.250 --> 39:00.770] The longer the reading range is too. [39:00.830 --> 39:01.910] So the cheapest tags. [39:02.030 --> 39:04.070] The ones in the car key for example. [39:04.310 --> 39:06.490] They use 125 kilohertz. [39:06.790 --> 39:07.310] But... [39:07.310 --> 39:08.070] They only... [39:08.070 --> 39:08.410] They... [39:08.410 --> 39:10.250] They must only be extremely close... [39:10.250 --> 39:10.910] Close to the reader. [39:11.090 --> 39:11.310] You... [39:11.310 --> 39:12.610] You stick the key into... [39:12.610 --> 39:13.110] To... [39:13.110 --> 39:13.910] To... [39:13.910 --> 39:14.030] To... [39:14.030 --> 39:14.790] Your driving wheel. [39:14.910 --> 39:14.990] Right? [39:15.130 --> 39:15.430] So... [39:15.430 --> 39:15.830] You're... [39:15.830 --> 39:17.450] You're talking few centimeters there. [39:17.650 --> 39:19.150] In the 900 megahertz range. [39:19.590 --> 39:19.930] Uh... [39:19.930 --> 39:21.430] We are at about 8 meters. [39:21.870 --> 39:22.110] Right? [39:22.190 --> 39:23.010] That we can achieve. [39:25.710 --> 39:26.350] Uh... [39:27.090 --> 39:27.310] Uh... [39:27.310 --> 39:29.150] We have seen that the... [39:29.150 --> 39:31.330] The data contained into a... [39:31.330 --> 39:32.370] An RFID card. [39:32.710 --> 39:35.290] An RFID chip is done by the... [39:35.670 --> 39:35.830] Uh... [39:35.830 --> 39:36.410] An identification. [39:36.870 --> 39:37.890] And the manufacturer. [39:38.150 --> 39:38.910] And the serial number. [39:39.070 --> 39:39.470] So... [39:39.470 --> 39:41.510] The verification is done via the... [39:41.510 --> 39:41.810] DNS. [39:42.030 --> 39:42.390] Or whatever. [39:43.410 --> 39:44.050] External... [39:44.050 --> 39:44.290] System. [39:44.510 --> 39:45.590] Okay for... [39:45.590 --> 39:46.450] Polluting the... [39:46.450 --> 39:47.710] That sort of... [39:47.710 --> 39:48.290] Uh... [39:48.790 --> 39:49.110] External... [39:49.110 --> 39:50.110] Check for data. [39:50.630 --> 39:51.130] But... [39:51.130 --> 39:53.090] Is it eventually possible to have... [39:53.090 --> 39:56.050] A larger payload in the chip itself? [39:56.350 --> 39:57.070] Uh... [39:57.070 --> 39:57.470] So... [39:57.470 --> 39:59.410] Further data... [39:59.410 --> 39:59.990] Uh... [39:59.990 --> 40:00.850] Only readable. [40:01.250 --> 40:01.470] Uh... [40:01.470 --> 40:02.370] Not writable. [40:02.710 --> 40:05.230] Can be used without any external check. [40:05.510 --> 40:06.170] That... [40:06.170 --> 40:07.170] That is certainly possible. [40:07.590 --> 40:08.890] What we see for example... [40:08.890 --> 40:09.710] For instance... [40:09.710 --> 40:11.950] Like what is in the larger barcode. [40:12.110 --> 40:13.370] The AIN128. [40:13.550 --> 40:13.590] Uh... [40:13.590 --> 40:15.190] When it can store also... [40:15.190 --> 40:16.770] Expiration date or whatever. [40:17.630 --> 40:17.650] Yeah. [40:17.650 --> 40:19.510] Inside without an external... [40:19.510 --> 40:19.770] Yeah. [40:19.770 --> 40:20.750] That is certainly possible. [40:21.510 --> 40:22.030] Um... [40:22.030 --> 40:22.430] The... [40:22.430 --> 40:22.630] So... [40:22.630 --> 40:25.010] So-called contactless smart card solutions. [40:25.330 --> 40:25.630] So... [40:25.630 --> 40:25.870] You... [40:25.870 --> 40:26.730] You have a big chip. [40:26.890 --> 40:28.330] Usually in a credit card or something. [40:28.730 --> 40:29.030] And you... [40:29.030 --> 40:30.490] You get really close to the reader. [40:30.630 --> 40:31.230] So there's no... [40:31.230 --> 40:32.610] No problem with powering. [40:32.710 --> 40:35.790] They have up to 64 kilobyte of... [40:35.790 --> 40:36.470] Of data storage. [40:37.010 --> 40:39.270] So in applications such as public transportation. [40:39.850 --> 40:40.050] Um... [40:40.050 --> 40:41.050] Data is like... [40:41.050 --> 40:42.370] Actively stored on the tech. [40:42.550 --> 40:43.310] If you get... [40:43.310 --> 40:43.610] Uh... [40:43.610 --> 40:43.930] Like a... [40:43.930 --> 40:45.710] A transportation card from Tokyo. [40:46.370 --> 40:46.830] Um... [40:46.830 --> 40:47.230] You can... [40:47.230 --> 40:48.830] You can see your record of the last year. [40:48.990 --> 40:49.310] Where you... [40:49.310 --> 40:50.170] Where you... [40:50.170 --> 40:50.970] Got onto the metro. [40:51.110 --> 40:51.730] And where you left. [40:51.950 --> 40:53.230] And that's not even encrypted. [40:53.290 --> 40:54.930] So everybody can get that information. [40:55.530 --> 40:55.630] Yeah. [40:56.070 --> 40:56.610] So yeah. [40:56.790 --> 40:57.250] But... [40:57.250 --> 40:58.010] It's expensive. [40:58.310 --> 40:59.230] We're talking $20. [40:59.950 --> 41:00.410] Right? [41:00.530 --> 41:00.710] For... [41:00.710 --> 41:01.410] For one card. [41:01.570 --> 41:02.570] Maybe five cents. [41:02.850 --> 41:03.670] But not a cent. [41:04.070 --> 41:04.370] Never. [41:05.910 --> 41:13.910] Do you ever see a point where the computational power on the chip is able to keep up with Moore's Law and just a normal PC? [41:14.490 --> 41:19.110] I'm thinking of cases like the Johns Hopkins work on the TI-DST tags and speed pass. [41:19.210 --> 41:19.350] Yeah. [41:19.550 --> 41:25.690] Where there's so little computing power on there they had to use a crappy proprietary algorithm, 40-bit key. [41:27.050 --> 41:27.650] Um... [41:27.650 --> 41:32.430] Modern PCs are now able to build a table of all possible lookups for a tag and... [41:32.430 --> 41:32.530] Good. [41:32.770 --> 41:33.250] Good question. [41:33.730 --> 41:34.150] Um... [41:34.150 --> 41:44.250] The Moore's Law is certainly valid for all silicon including RFID tags meaning that every 18 months you get twice as many transistors for the same size. [41:44.250 --> 41:48.130] What RFID manufacturers do now, they shrink it. [41:48.790 --> 41:48.870] Right? [41:49.210 --> 41:51.450] They take the same number of transistors... [41:51.450 --> 41:52.690] And put it in a smaller package. [41:53.310 --> 41:53.830] Quarterly... [41:53.830 --> 41:54.590] Yeah. [41:54.790 --> 41:57.550] The computational power isn't increasing at the same rate. [41:57.590 --> 42:04.710] Well, we might hit some lower limit there where handling of the tiny, tiny tag... [42:04.710 --> 42:08.490] You have to attach it to an antenna, you have to package it, all that. [42:09.430 --> 42:09.950] There's... [42:09.950 --> 42:11.950] Philips is awesome there. [42:11.950 --> 42:19.150] They have floating techniques where the chip loads on some liquid to the antenna and assembles itself. [42:19.550 --> 42:21.370] But that will hit a lower limit. [42:21.510 --> 42:26.370] Once you hit that limit, you can't build smaller and Moore's Law kicks in again. [42:26.770 --> 42:29.610] Then you get twice as many transistors for the same price. [42:29.790 --> 42:30.030] Yes. [42:30.130 --> 42:33.870] At that point, we can put more sophisticated security in it. [42:33.870 --> 42:48.350] I'm just wondering if they're ever going to reach a point where the RFID chips are able to give you a certain level of security that is required and not be, like in the TI case, six years later, after the deployment of the system. [42:48.510 --> 42:48.830] Yeah. [42:48.830 --> 42:48.870] Yeah. [42:49.270 --> 42:50.170] You know, it's useless. [42:50.590 --> 42:51.830] Well, you could... [42:52.670 --> 42:53.270] You can... [42:53.270 --> 42:55.310] You can get more longevity in any case. [42:55.830 --> 43:02.070] And RFID tech has a complexity on the order of 5,000 gigs at the moment. [43:02.230 --> 43:10.150] And there is an implementation by the University of Graz in Austria that builds an AES cipher with 3,000 gates. [43:10.290 --> 43:11.290] So you have 5,000 already. [43:11.570 --> 43:14.490] Then you add another 3,000, you have AES on the tech. [43:14.730 --> 43:15.830] So that... [43:15.830 --> 43:19.570] We're talking half more cost, 50% more. [43:19.710 --> 43:19.850] Yeah? [43:20.170 --> 43:21.290] That is certainly possible. [43:21.450 --> 43:21.570] Yes. [43:21.790 --> 43:22.050] Okay. [43:24.970 --> 43:26.370] I'm absolutely fascinated. [43:26.570 --> 43:28.210] I mean, I'm a village idiot on this topic. [43:29.450 --> 43:34.310] But I'm wondering about connecting improvised explosive devices to reading RFIDs. [43:34.310 --> 43:39.070] So I want to blow up every Buick LeSabre that passes or every M1 tank. [43:39.070 --> 43:40.190] Where are we on that? [43:42.070 --> 43:48.770] The American passport, as far as I understand it, doesn't mandate access control. [43:48.770 --> 43:52.030] So the reader doesn't have to prove it's legitimate. [43:52.870 --> 43:53.050] And... [43:53.050 --> 43:55.070] No, but I'm talking about automobiles. [43:55.390 --> 43:55.990] Automobiles. [43:56.110 --> 43:56.470] Okay, so... [43:56.470 --> 44:00.590] An improvised explosive device is something that blows up a tank as it goes past. [44:00.850 --> 44:01.150] Okay. [44:01.150 --> 44:12.070] So where are we in relation to being able to read specific RFID from the side of the road so that all the American effort to put logistics information into its vehicles is in fact empowering the enemy? [44:14.150 --> 44:22.050] Reading range is typically two meters for most commonly used text in logistics. [44:22.350 --> 44:23.030] And in four years? [44:23.770 --> 44:24.350] Same. [44:24.690 --> 44:24.990] Okay. [44:26.310 --> 44:26.790] They... [44:27.370 --> 44:27.850] They... [44:27.850 --> 44:28.050] They... [44:28.050 --> 44:30.630] The radio characteristics don't change. [44:31.030 --> 44:31.510] We... [44:31.510 --> 44:34.090] We might tweak a little bit better antennas, all that. [44:34.230 --> 44:35.170] Maybe three, four meters. [44:35.390 --> 44:36.270] But the... [44:36.270 --> 44:40.450] The commonly used frequency, 13 points on megahertz, they don't allow for like a mile. [44:40.450 --> 44:41.910] So it's not a major threat at this point? [44:42.190 --> 44:43.250] Well, there is a threat. [44:43.410 --> 44:44.690] As I said, passports. [44:44.870 --> 44:49.950] The threat being that you deploy a bomb somewhere and wait until an American walks by. [44:53.430 --> 44:53.870] Yeah. [44:54.370 --> 44:55.130] Thank you. [44:58.450 --> 44:59.110] Hello again. [45:00.570 --> 45:02.150] Now to an evil side of my brain. [45:02.330 --> 45:05.490] I've always wondered the possibilities of... [45:05.490 --> 45:11.710] You're talking about kill codes on tags and the fact that a couple of seconds in a microwave is enough to kill anything like that. [45:11.710 --> 45:23.390] The possibilities of just overpowering the tags, blowing out the capacitor on them with something like a backpack-mounted battery and a transmitter and just go click and your entire inventory system goes nuked. [45:24.110 --> 45:24.670] Easy. [45:25.250 --> 45:25.510] Yeah. [45:26.190 --> 45:27.930] For cheap tags, very easy. [45:28.150 --> 45:33.950] With devices that don't get FCC approval, but then you commit other crimes anyway and it doesn't... [45:33.950 --> 45:35.230] Well, if you're doing something like that... [45:35.230 --> 45:35.610] Yeah. [45:35.630 --> 45:36.370] No, it's easy. [45:36.570 --> 45:38.210] You can easily overpower them. [45:38.210 --> 45:43.730] You need like a maybe 15, 20 watt sender and you kill tags. [45:44.170 --> 45:51.310] There could be countermeasures to that if that became a huge threat, vandalism in like Walmarts, then they... [45:51.310 --> 45:53.630] I was actually thinking the gap, but close enough. [45:53.970 --> 46:00.930] The only countermeasure really would be to have a resistor on the tag that could burn that extra energy. [46:01.230 --> 46:03.470] How much extra would that cost per tag, I guess? [46:04.870 --> 46:07.350] Resistors are actually hard to manufacture in silicon. [46:07.570 --> 46:12.210] So if you don't want to put an external transistor, we're talking doubling the price. [46:12.630 --> 46:22.550] And even then, wasting the radio frequency, the extra power that you don't want to destroy your tag with means you create heat, right? [46:22.870 --> 46:26.090] So you overheat the tag and then it breaks after a minute or two. [46:26.290 --> 46:31.690] Just not in a second, but there is really no good countermeasure that would protect the tag. [46:36.150 --> 46:38.530] That was basically my question. [46:39.110 --> 46:44.790] But moving on to temporary countermeasures to exposing your privacy. [46:44.970 --> 46:49.030] You mentioned wrapping in foil as one type. [46:50.570 --> 46:53.230] Are there any others that you can share? [46:53.330 --> 47:01.350] Or how much does it take to protect, for example, like a credit card from sending its signal out? [47:01.350 --> 47:03.130] Or like, what would you have to... [47:03.130 --> 47:05.350] What types of materials would you have to... [47:05.890 --> 47:07.350] Could you put... [47:07.870 --> 47:08.370] Wrap it in your... [47:08.370 --> 47:13.290] Well, in the case of the credit card, the RFID tag is just in addition. [47:13.450 --> 47:18.950] I've never seen a checkout terminal where I could actually pay other than at Exxon mobile station. [47:19.170 --> 47:23.510] So if you don't want the functionality and it just comes with it, then microwave again. [47:23.510 --> 47:28.750] But if you really want the functionality, but only sometimes, you wrap it in foil. [47:28.890 --> 47:31.230] That's the only solution that I'm aware of. [47:32.130 --> 47:33.310] Just tinfoil works? [47:34.110 --> 47:34.550] Or you just... [47:34.550 --> 47:35.630] Any metal. [47:35.950 --> 47:36.030] Yeah. [47:36.730 --> 47:37.450] Any metal. [47:37.790 --> 47:37.870] Yeah. [47:38.150 --> 47:38.370] Thank you. [47:38.370 --> 47:42.910] They sell wallets that have a metal foil in it already. [47:43.210 --> 47:43.270] Yeah. [47:43.730 --> 47:44.110] Brilliant. [47:46.670 --> 47:49.270] I was just going to plug, they're downstairs. [47:57.400 --> 48:13.140] About overloading an RFID tag, a small RFID tag, will eventually a piezoelectric lighter or whatever could damage it without external notice. [48:13.560 --> 48:14.480] Okay. [48:14.640 --> 48:26.980] Using a piezoelectric lighter, because it generates a lot of radio noise all around. [48:27.840 --> 48:31.380] It can be dangerous also for a PC using that way. [48:31.380 --> 48:40.480] So having a piezoelectric charger near the chip quite... [48:40.480 --> 48:40.780] Uh-huh. [48:41.100 --> 48:44.460] ...can eventually overload as he was asking for. [48:44.680 --> 48:47.040] Without using a portable microwave. [48:47.820 --> 48:48.620] Unlikely. [48:48.940 --> 48:49.460] Unlikely. [48:50.280 --> 49:03.800] Devices that are not supposed to emit radio waves, but that just do it anyway, like computers, they have much lower thresholds on emitting privacy, on emitting radio. [49:04.120 --> 49:14.180] So if a reading device can survive an RFID, if the RFID tag can survive the RFID reader, it can certainly survive all external noise. [49:15.060 --> 49:15.740] Yeah. [49:17.500 --> 49:18.680] Any more questions? [49:20.600 --> 49:22.440] Well, thanks a lot for the discussion. [49:22.540 --> 49:23.200] I was... [49:23.200 --> 49:23.280] Thank you. [49:23.420 --> 49:23.780] Thank you.