Suchen

Archiv der 'Thoughts' Kategorie

8th door – RFID Firewall deutsch

m.schmidt 8. December, 2006

There are a lot of discussions worldwide about the pro’s and con’s of RFID, what it brings, how safe it is, is it a blessing or a curse. Well, one can’t deny that it’s quite comfortable. You can move freely in your Company’s buildings, and doors you’re allowed to pass will be opened by a magic hand. You have not to wait at the checkout in the supermarket, and your microwave knows in which way your meal have to be prepared. On the other hand, there are also many disadvantages. If banknotes are equipped with RFID tags, every bad guy knows instantly if I’m a valuable target. My daily routine, my route of moving, can possibly become known by anybody, and so can my social status (the clothes I wear, the credit cards I own and so on). And at least, the dustman knows if packing of your microwave meal is in the right garbage can.
Well, we can in some way protect ourselves, by either limiting thees tags with some sort of Faraday shield or destroy them completely. But this is can be complex, or in the last case, even irreversible.
Andrew S. Tanenbaum is a guy who’s quite familiar with this topic, and he presented a quite interesting approach. The RFID Guardian was once created to warn the user if his RFID tags are getting read by someone else. By now, this device has been developed to be a ‘personal firewall’ (in the best sense of the word) for RFID, giving the user control about what information tho share, when and who is allowed to access.

I see this as a very interesting approach. Maybe this is able to keep the advantages and the comfort of RFID and reduces the dangers, and the potential of misuse. For further information, the main page of the project is very useful.

Security 2.0 deutsch

m.schmidt 28. November, 2006

After Web 2.0, there’s now security 2.0, according to Symantec. Some say, Symantec is going to publish all their work as a sort of „anti-pattern“, calling this security 2.0 ;)
Well, Symantec itself claims security 2.0 to be a shiny new bunch of Software for the automation of security tasks, especially when it comes to dealing with all the new laws awaiting us.
By now, google has more than half a million results for security 2.0, but most of these articles are screaming for BullshitBingo2.0, the rest is Bashing 2.0.

It seems that marketing comes over know-how, while security 1.0 has still beta status. :) Or shoul we all migrate to 3.0?