Hotel room key cards everywhere could be at risk from RFID security flaw


Contactless cards used to open doors in hotels and offices around the world are flawed in a way that could allow any person to open practically any door, experts have warned.
Cybersecurity researchers from Quirkslab focused on FM11RF08S, a variant of the MIFARE Classic card that was released in 2020 by Shanghai Fudan Microelectronics, apparently the “leading Chinese manufacturer of unlicensed ‘MIFARE compatible’ chips.
The report claims the FM11RF08S features countermeasures “designed to thwart all known card-only attacks”, but worryingly, usage of the card is growing increasingly popular by the day.
Cracked in minutes
It reportedly took the researchers a “couple of minutes” to find an attack that cracks FM11RF08S sector keys – when the keys were reused across at least three sectors, or three cards.
Further analysis landed them a hardware backdoor that allows authentication with an unknown key, and when they cracked the card’s secret key, they found it to be “common to all existing FM11RF08S cards!”.
With the backdoor, the experts were able to design “several other” attacks, each of which was able to crack all the keys of any card in just a few minutes, without needing to know any initial keys (besides the backdoor one).
To add insult to injury, Quirkslab then shifted their attention to older models, and found a “similar backdoor” in the previous generation – FM11RF08 – which was protected with another key. After cracking the second key, they found it to be common to all FM11RF08 cards, as well as other Fudan references (FM11RF32, FM1208-10, and probably more), and even old cards from NXP1 (MF1ICS5003 & MF1ICS5004) and Infineon (SLE66R35), some of which date back to late 2007.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
To conclude, the researchers warned users to check their infrastructure and assess the risks. “Many are probably unaware that the MIFARE Classic cards they obtained from their supplier are actually Fudan FM11RF08 or FM11RF08S, as these two chip references are not limited to the Chinese market. For example, we found these cards in numerous hotels across the US, Europe, and India,” they said.
Via The Hacker News
More from TechRadar Pro
Contactless cards used to open doors in hotels and offices around the world are flawed in a way that could allow any person to open practically any door, experts have warned. Cybersecurity researchers from Quirkslab focused on FM11RF08S, a variant of the MIFARE Classic card that was released in 2020…
Recent Posts
- This 1.9-pound smartphone’s massive battery offers six months of standby
- Movie sales – including 4K Blu-ray – fell again last year, but if you’re going streaming only, you’re massively missing out
- A new and dangerous keylogger is on the loose – here’s how to stay safe
- iPhone 16E: all the news on Apple’s new $599 phone
- Pour one out for Apple’s dearly departed home button
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010