Skip to content
Search AI Powered

Latest Stories

rfidwatch

how secure is your RFID credit card?

The next time you pull up to the drive-through window at McDonald's, you might want to reach into your pocket for some good-old fashioned cash. The "swipe free" credit card you've gotten accustomed to using to pay for a Big Mac and fries might actually be putting your personal information at risk.

In tests conducted this fall, researchers from the RFID Consortium for Security and Privacy were able to hack into the information stored on first-generation "swipe free" credit cards that use RFID technology. Though the information is supposedly encrypted, the group reported that all of the cards it tested revealed important personal information whose disclosure could lead to identity fraud and theft.


Nearly 20 million of the RFID-enabled cards have been issued by credit card companies like American Express and MasterCard, and are now being used by consumers at a growing number of retail outlets, including CVS drug stores and McDonald's.

Researchers from the consortium, which includes members from both industry and academia, found problems with all of the cards they tested, although they tested fewer than two dozen cards. "Every single RFID credit card and debit card that I have seen in my lab has revealed at the least the full user name and card expiration date, and the vast majority also revealed the full credit card number," says Tom Heydt-Benjamin, a graduate student at the University of Massachusetts and one of the study's architects.

Because the information is transmitted via radio waves, the cards can be read through a wallet, an item of clothing or an envelope. To illustrate how easily personal data could be skimmed from cards, Heydt-Benjamin outlined a scenario in which somebody posing as a campaign volunteer walked the streets stuffing fliers into mailboxes. It would be a simple matter for that person to use a concealed RFID reader to skim information from any credit cards that happened to be in those mailboxes, he said.

Privacy advocates called for credit card issuers to recall all of the cards in question and replace them with more secure versions. The group Consumers Against Supermarket Privacy Invasion and Numbering (CASPIAN) advised consumers to remove the credit cards from their wallets immediately and request an RFID-free replacement card. The group is cautioning consumers not to mail the cards back because of the risk that their personal information might be exposed.

Although he acknowledges that RFIDenabled cards have security flaws that must be addressed, Heydt-Benjamin says that when it comes to the overall risk of identity theft, "leaky" cards pose only a minor risk. Practices like phishing, he says, represent a much bigger threat to individual consumers.

"I hope this doesn't set the whole technology back," says Heydt-Benjamin. "We firmly believe that RFID is not a dangerous technology. Our research is about bringing appropriate security and privacy mechanisms into the RFID world. Our message is that while this issue is something that very much should be part of the RFID privacy debate, we don't see it as indicating that RFID technology is an evil or dangerous technology."

The Latest

More Stories

autonomous tugger vehicle

Cyngn delivers autonomous tuggers to wheel maker COATS

Autonomous forklift maker Cyngn is deploying its DriveMod Tugger model at COATS Company, the largest full-line wheel service equipment manufacturer in North America, the companies said today.

The deal was announced the same week that California-based Cyngn said it had raised $33 million in funding through a stock sale.

Keep ReadingShow less

Featured

photo of self driving forklift
Lift Trucks, Personnel & Burden Carriers

Cyngn gains $33 million for its self-driving forklifts

photo of a cargo ship cruising

Project44 tallies supply chain impacts of a turbulent 2024

Following a year in which global logistics networks were buffeted by labor strikes, natural disasters, regional political violence, and economic turbulence, the supply chain visibility provider Project44 has compiled the impact of each of those events in a new study.

The “2024 Year in Review” report lists the various transportation delays, freight volume restrictions, and infrastructure repair costs of a long string of events. Those disruptions include labor strikes at Canadian ports and postal sites, the U.S. East and Gulf coast port strike; hurricanes Helene, Francine, and Milton; the Francis Scott key Bridge collapse in Baltimore Harbor; the CrowdStrike cyber attack; and Red Sea missile attacks on passing cargo ships.

Keep ReadingShow less
diagram of transportation modes

Shippeo gains $30 million backing for its transportation visibility platform

The French transportation visibility provider Shippeo today said it has raised $30 million in financial backing, saying the money will support its accelerated expansion across North America and APAC, while driving enhancements to its “Real-Time Transportation Visibility Platform” product.

The funding round was led by Woven Capital, Toyota’s growth fund, with participation from existing investors: Battery Ventures, Partech, NGP Capital, Bpifrance Digital Venture, LFX Venture Partners, Shift4Good and Yamaha Motor Ventures. With this round, Shippeo’s total funding exceeds $140 million.

Keep ReadingShow less
grocery supply chain workers

ReposiTrak and Upshop link platforms to enable food traceability

ReposiTrak, a global food traceability network operator, will partner with Upshop, a provider of store operations technology for food retailers, to create an end-to-end grocery traceability solution that reaches from the supply chain to the retail store, the firms said today.

The partnership creates a data connection between suppliers and the retail store. It works by integrating Salt Lake City-based ReposiTrak’s network of thousands of suppliers and their traceability shipment data with Austin, Texas-based Upshop’s network of more than 450 retailers and their retail stores.

Keep ReadingShow less
photo of smart AI grocery cart

Instacart rolls its smart carts into grocery retailers across North America

Online grocery technology provider Instacart is rolling out its “Caper Cart” AI-powered smart shopping trollies to a wide range of grocer networks across North America through partnerships with two point-of-sale (POS) providers, the San Francisco company said Monday.

Instacart announced the deals with DUMAC Business Systems, a POS solutions provider for independent grocery and convenience stores, and TRUNO Retail Technology Solutions, a provider that powers over 13,000 retail locations.

Keep ReadingShow less