Radio frequency identification (RFID) technology was first patented in the 1980s and made possible things that might have seemed like science fiction at the time. It permeates many aspects of our lives, enabling contactless card payments, helping businesses track inventory and helping identify lost pets. However, although it has been widely used for several decades, many myths and misunderstandings remain around RFID security.
Unless you know how it works, RFID might as well be magic. There are two main types of RFID tags. The first has its own power source, allowing it to broadcast data over extremely long distances, known as “active” RFID. The second RFID, “passive”, draws its energy from an RFID reader. When you tap to pay, for example, the terminal creates a small electromagnetic current, allowing your card details to be read.
Some of the security issues with RFID can arise from the fact that all devices can be read at long distances. With that in mind, let’s put an end to the most common misconceptions.
RFID skimming is less common than you might think
People have been concerned about RFID theft (theft of information stored on a passport, credit card, or other RFID-enabled device) for as long as this technology has been in use. Although this type of theft is possible, there are several functional limitations that make the task difficult, time-consuming and unprofitable for criminals.
Credit and debit cards use passive RFID and inductive coupling, meaning they are only capable of short-range communications. This is usually a few inches, with specialized equipment extending the range to almost 18 inches. In other words, a criminal has to get close to you, identify where the card is kept, and hope that it supports NFC. Even then, skimming success rates are reduced by RFID-blocking wallets, thick clothing, or carrying metal objects like keys in the same pocket.
This is not to say that skimming does not occur, because it does. However, all reports of credit cards being cloned from several meters away are fictitious. It’s simply much more effective to attach a card skimmer to an ATM than to target people individually. The problem is so widespread, in fact, that retailers like Costco reduce the risk of card theft by employing human fuel attendants.
Aluminum foil is not a foolproof way to block RFID signals
The idea of wrapping something in metal to block unwanted signals isn’t new: In 1836, a scientist named Michael Faraday invented the Faraday cage, a metal mesh designed for precisely this purpose. Since foil is cheap, flexible, and readily available, it’s a natural choice for anyone hoping to recreate this experience on a smaller scale. That said, while aluminum can block some RFID signals, it is not a reliable solution. Additionally, covering your bag with foil could put you in a sticky situation with loss prevention employees, as shoplifters often use the same tactic in hopes of thwarting electronic security tagging systems.
So why can’t we trust aluminum foil? To reliably block high- and ultra-high-frequency RFID signals, you need to provide full coverage, ideally with multiple layers of film. Any small gap or tear would render the entire activity useless, which is a problem considering that foil is not meant to be wrapped and unwrapped repeatedly. A longer-term solution would be to get a wallet that blocks RFID signals: these are more durable, require less work, and as a bonus, you can take them anywhere (even to the airport) without blinking.
RFID devices are not easily compromised
Most modern RFID devices are actually quite resistant to interference. For example, when you use your card to pay for something, the data sent from your card to the payment terminal is encrypted, making it unreadable to anyone monitoring radio traffic. An attacker could theoretically see your card details if they could crack the encryption, but they’d be better off clearing their schedule because it would take them millions of years to brute force a single 128-bit AES key.
With this in mind, it is actually easier to compromise the RFID implementation rather than the device. Rather than trying to decrypt a signal, an attacker could use a device such as a Flipper Zero to fully replicate the encrypted signal. These devices aren’t cheap, require some technical know-how, and wouldn’t work for payments since the signal is different each time, but it’s entirely possible to create your own key fob to access a building. Therefore, when RFID is used in sensitive applications, there should always be a secondary method of identity verification. Instead of relying exclusively on a key fob, you can use facial recognition checks, a PIN, or have someone at the front desk manually verify access eligibility.
Widespread adoption of RFID does not infringe on privacy
When RFID first emerged, just as with 5G, there were conspiracy theories circulating about how governments would use it to track their citizens. Decades later, RFID technology is primarily used to monitor shipments and inventory, not people. There are exceptions, of course: some hospitals use RFID bracelets to track patient movements, and the chip embedded in your passport keeps track of your travel history.
There are, however, perfectly innocent reasons for this. Hospitals have a duty of care to their patients and must know where they are. Likewise, countries need to know who is coming and going. Using RFID does not significantly weaken your privacy in these situations, since your movements can already be tracked via video surveillance, or even the Wi-Fi network you are connected to. Rather, these RFID implementations exist to save time, improve efficiency, and keep you safe.
What about unauthorized access? Organizations face hefty fines for sensitive data breaches, often costing them hundreds of thousands of dollars. It doesn’t matter whether it was stolen via RFID, the Internet or in person: if your data was mishandled or insufficiently protected, the company that lost it finds itself in serious trouble. Please be assured that special attention is paid to the information collected and how it is stored.
