ArticleslgStudy

science

Wireless identity theft

Wireless identity theft is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Wireless identity theft rather than just read about it. In short: Wireless identity theft, also known as contactless identity theft or RFID identity theft, is a form of identity theft described as "the act of compromising an individual's personal identifying information using wireless (radio frequency) mechanics." Numerous articles have been written about wireless identity theft and broadcast television has produced several investigations of this phenomenon. According to Marc Rote…

Key takeaways

  • Wireless identity theft belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Wireless identity theft to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Wireless identity theft from memory before moving on to harder problems.

Reference excerpt

Wireless identity theft, also known as contactless identity theft or RFID identity theft, is a form of identity theft described as "the act of compromising an individual's personal identifying information using wireless (radio frequency) mechanics." Numerous articles have been written about wireless identity theft and broadcast television has produced several investigations of this phenomenon. According to Marc Rotenberg of the Electronic Privacy Information Center, wireless identity theft is a serious issue as the contactless (wireless) card design is inherently flawed, increasing the vulnerability to attacks.

Overview Wireless identity theft is a relatively new technique for gathering individuals' personal information from RF-enabled cards carried on a person in their access control, credit, debit, or government issued identification cards. Each of these cards carry a radio frequency identification chip which responds to certain radio frequencies. When these "tags" come into contact with radio waves, they respond with a slightly altered signal. The response can contain encoded personally identifying information, including the card holder's name, address, Social Security Number, phone number, and pertinent account or employee information. Upon capturing (or 'harvesting') this data, one is then able to program other cards to respond in an identical fashion ('cloning'). Many websites are dedicated to teaching people how to do this, as well as supplying the necessary equipment and software. The financial industrial complex is migrating from the use of magnetic stripes on debit and credit cards which technically require a swipe through a magnetic card swipe reader. The number of transactions per minute can be increased, and more transactions can be processed in a shorter time, therefore making for arguably shorter lines at the cashier.

Controversies Academic researchers and 'White-Hat' hackers have analysed and documented the covert theft of RFID credit card information and been met with both denials and criticisms from RFID card-issuing agencies. Nevertheless, after public disclosure of information that could be stolen by low-cost jerry-rigged detectors which were used to scan cards in mailing envelopes (and in other studies also even via drive-by data attacks), the design of security features on various cards was upgraded to remove card owners' names and other data. Additionally, a number of completely unencrypted card designs were converted to encrypted data systems.

RSA report The issues raised in a 2006 report were of importance due to the tens of millions of cards that have already been issued. Credit and debit card data could be stolen via special low cost radio scanners without the cards being physically touched or removed from their owner's pocket, purse or carry bag. Among the findings of the 2006 research study "Vulnerabilities in First-Generation RFID-Enabled Credit Cards", and in reports by other white-hat hackers:

some scanned credit cards revealed their owners' names, card numbers and expiration dates; that the short maximum scanning distance of the cards and tags (normally measured in inches or centimetres) could be extended to several feet via technological modifications; that even without range-extension technologies, Black Hatters walking through crowded venues or delivering fliers could easily capture card data from other individuals and from mail envelopes; that security experts who reviewed the study findings were startled by the breaches of privacy of the study (conducted in 2006); that other e-systems, such as ExxonMobil's Speedpass keychain payment device, used weak encryption methods which could be compromised by a half-hour or so of computing time; that some cards' scanned stolen data quickly yielded actual credit card numbers and didn't use data tokens; that data illicitly obtained from some cards was successfully used to trick a regular commercial card-reader (used by the study group) into accepting purchase transactions from an online store that didn't require the entry of the cards' validation codes; that while higher level security systems have been and continue to be developed, and are available for RFID credit cards, it is only the actual banks which decide how much security they want to deploy for their cardholders; that every one of the 20 cards tested in the study was defeated by at least one of the attacks the researchers deployed; another related security threat concerned a different product: new government issued ePassports (passports that now incorporate RFID tags similar to credit and debit cards). The RFID tags in ePassports are also subject to data theft and cloning attacks. The United States government has been issuing ePassports since 2006. In a related issue, privacy groups and individuals have also raised "Big Brother" concerns, where there is a threat to individuals from their aggregated information and even tracking of their movements by either card issuing agencies, other third party entities, and even by governments. Industry observers have stated that '...RFID certainly has the potential to be the most invasive consumer technology ever.' Credit card issuing agencies have issued denial statements regarding wireless identity theft or fraud and provided marketing information that either directly criticized or implied that:

beyond the card data itself, other data protection and anti-fraud measures in their payment systems are in place to protect consumers; the academic study conducted in 2006 used a sample of only 20 RFID cards, and was not accurately representative of the general RFID marketplace which generally used higher security than the tested cards; unencrypted plain text information on the cards was "...basically useless" (by itself), since financial transactions they were tied to used verifications systems with powerful encryption technologies; even if consumers were victims of RFID credit card fraud or identity theft, they would not be financially liable for such credit card fraud (a marketing strategy that ignores the other serious consequences to card holders after they've been associated with fraudulent transactions or have their identity stolen); After the release of the study results, all of the credit card companies contacted during the New York Times' investigative report said that they were removing card holder names from the data being transmitted with their new second generation RFID cards.

… excerpt ends here. Continue reading the full article.

Worked examples

Example 1 — a first encounter with Wireless identity theft

Start with the simplest possible case. Write down what Wireless identity theft claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Wireless identity theft before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Wireless identity theft ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Wireless identity theft

In research
Wireless identity theft appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Wireless identity theft in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Wireless identity theft is common in secondary-school and first-year university syllabi. It links to neighbouring topics Credit cards, Crime, Data security, so understanding it makes those chapters shorter.
In everyday life
Look for Wireless identity theft outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Wireless identity theft” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Wireless identity theft in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Wireless identity theft means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Wireless identity theft out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Wireless identity theft in simple terms?

Wireless identity theft, also known as contactless identity theft or RFID identity theft, is a form of identity theft described as "the act of compromising an individual's personal identifying information using wireless (radio frequency) mechanics." Numerous articles have been written about wireles…

Why does Wireless identity theft matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Wireless identity theft?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Wireless identity theft.

Tags

  • Credit cards
  • Crime
  • Data security
  • Identity theft
  • Radio-frequency identification

Keep exploring