Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Researchers Uncover Backdoor in Millions of Chinese RFID Smart Cards

    Researchers Uncover Backdoor in Millions of Chinese RFID Smart Cards

    August 21, 2024

    Security researchers have discovered a widespread hardware backdoor in the FM11RF08S variant of the MIFARE Classic RFID smart cards manufactured by the Chinese chip company Shanghai Fudan Microelectronics.

    The backdoor allows instantaneous cloning of the cards, posing a major security risk for businesses and consumers using the affected cards. The variant had been released around 2020 and touted as resistant to all known ‘card-only’ attacks – attacks that can be carried out on the card itself without access to its reader.

    Backdoor in Chinese FM11RF08S Smart Cards

    Through empirical research, the researchers from Quarkslab found a hardware backdoor that enables any entity with knowledge of it to compromise all user-defined keys on these cards without prior knowledge simply by accessing the card for a few minutes.

    The backdoor was discovered during an investigation into the card’s security features. The researchers successfully cracked the secret key, revealing that it is the same across all FM11RF08S cards. In the study, detailed in a research paper, they described steps to to successfully crack the sector keys of these cards within minutes if the same keys were reused across at least three sectors or cards.

    The FM11RF08S had earlier been introduced as a more secure alternative, featuring a countermeasure called ‘static encrypted nonce’ designed to thwart card-only attacks. The finding has significant implications for users, as it allows attackers to dump and clone these cards, even if all their keys are properly diversified.

    The presence of the backdoor raises several questions, particularly given that it is not limited to the Chinese market. In fact, the researchers found these cards in numerous hotels across the U.S., Europe, and India.

    MIFARE Classic’s Legacy

    In addition, the researchers uncovered another hardware backdoor key that was common across several older MIFARE Classic card models from various manufacturers, including NXP and Infineon.

    The MIFARE Classic card standard, developed and licensed by NXP, has long been known to be insecure, with numerous attacks demonstrated over the years. However, the cards remain widely used due to business inertia and the high cost of migrating to newer, more secure systems.

    The researchers emphasize that migrating to more robust alternatives is crucial to ensure the security of RFID-based systems.

    Consumers should check their RFID infrastructure and assess such potential risks, the researchers advised, as many could be unaware that the MIFARE Classic cards they had deployed within sensitive environments could be the Fudan FM11RF08 or FM11RF08S.

    However, the researchers warned that most RFID cards could be susceptible to recovery-based attacks if an attacker has access to matching readers, stating that while there were many more robust alternatives on the market, they could cannot guarantee the absence of hardware backdoors.

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleLet small fires burn
    Next Article North Korean Hackers Observed Deploying New ‘MoonPeak’ Malware Infrastructure

    Related Posts

    Machine Learning

    Salesforce AI Releases BLIP3-o: A Fully Open-Source Unified Multimodal Model Built with CLIP Embeddings and Flow Matching for Image Understanding and Generation

    May 16, 2025
    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Hugging Face Releases Open LLM Leaderboard 2: A Major Upgrade Featuring Tougher Benchmarks, Fairer Scoring, and Enhanced Community Collaboration for Evaluating Language Models

    Development

    Navigating Explainable AI in In Vitro Diagnostics: Compliance and Transparency Under European Regulations

    Development

    Reduce latency and cost in read-heavy applications using Amazon DynamoDB Accelerator

    Databases

    Snag this 85-inch TCL TV for just $900 this Labor Day weekend

    Development

    Highlights

    Artificial Intelligence

    Anthropic shows that Claude LLMs have become exceptionally persuasive

    April 9, 2024

    Anthropic research revealed that their latest AI model, Claude 3 Opus, can generate arguments as…

    Unlock Seamless Test Automation and Drive Quality with NG-TxHyperAutomate

    May 5, 2025

    Matrix3D: Large Photogrammetry Model All-in-One

    May 9, 2025

    CVE-2025-47287 – Tornado Multipart Form Data Denial of Service Vulnerability

    May 15, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.