    <rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/">
     <channel>
        <title>ACCU  :: 48-bits sir? That'll do nicely!</title>
        <link>https://members.accu.org/index.php/blogs/1478</link>
        <description>Professionalism in Programming</description>
        <dc:language>en-us</dc:language> 
        <dc:creator>Administrator</dc:creator> 
        <admin:generatorAgent rdf:resource="http://www.xaraya.org" /> 
        <admin:errorReportsTo rdf:resource="mailto:webeditor@accu.org" />
       <sy:updatePeriod>hourly</sy:updatePeriod>
       <sy:updateFrequency>1</sy:updateFrequency>
       <docs>http://backend.userland.com/rss</docs>


        <h2>Blogs</h2>


<div class="xar-mod-head"><span class="xar-mod-title">Blogs</span></div>

<table border="0" cellpadding="1" cellspacing="0">
    <tbody>
    <tr>
        <td valign="top">
            Browse in :
       </td>
       <td valign="top">

                                            <a href="https://members.accu.org/index.php/blogs/">All</a>

                     &gt;                         <a href="https://members.accu.org/index.php/blogs/c73/">Blogs</a>
<br />
</td>
   </tr>
   </tbody>
</table>




<div class="xar-error">
   <p>
 <strong>Note:</strong> when you create a new publication type,
the articles module will automatically use the templates
<em>user-display-[publicationtype].xt</em>
and <em>user-summary-[publicationtype].xt</em>.
If those templates do not exist when you try to preview or display a new article,
you'll get this warning :-)  Please place your own templates in themes/<em>yourtheme</em>/modules/articles . The templates will get the extension .xt there. </p>
</div>
<div class="xar-norm xar-standard-box-padding">
   <h1><strong>Title:</strong>&nbsp;48-bits sir? That'll do nicely!</h1>
<p><strong>Author:</strong>&nbsp;</p>
<p>
<strong>Date:</strong> 16 March 2008 20:03:43 +00:00 or Sun, 16 March 2008 20:03:43 +00:00</p>
<p><strong>Summary:</strong>&nbsp;[16-03-2008] Alan muses on the dangers of hardwiring your encryption into card readers and the cards...</p>
<p><strong>Body:</strong>&nbsp;<p>
Bad news for those organisations using smart (aka 'idiot') cards fitted with NXP's Mifare chip. Researchers at Radbound University in Nijmegen have developed a method of easily cracking the chip's rather pathetic 48-bit key encryption. That may not sound earth shattering, until you realise that there are something like two billion cards around using this chip! They are used by a lot of public transport systems (London Transport's Oyster card, for instance), and in security swipe access cards used by governments and corporations.
</p>
<p>
It's going to be expensive to fix, since the encryption is in hardware in both the reader and the chip, both will have to be replaced. You can't just issue new cards. Rumour has it that some organisations are adding armed guards to their entry areas, though if the situation is that sensitive, one has to wonder why they were so stupid as to only rely on a card in the first place! I suspect this story may soon die, since all involved have an interest in hushing it up...
</p>
<p>
[Source: Risks Digest 25.08]
</p>
<p>
Alan produces a (nearly) weekly tech news newsletter. Find the details at http://www.ibgames.net/alan/winding/index.html
</p>
</p>
<p><strong>Notes:</strong>&nbsp;</p>
<p><em>More fields may be available via dynamicdata ..</em></p>
</div>
</channel>
</rss>
