Karsten Nohl
Graduate Student
Computer Science Department
University of Virginia

Contact Information

Mailing Address: Karsten Nohl
Department of Computer Science
School of Engineering, University of Virginia
151 Engineer's Way
Charlottesville, VA 22904
E-mail:
PGP: 0ECC 358C 2595 1058 7861 4400 7DE2 766E 787C 2265
CV

About me

I am a graduate student at the University of Virginia. Currently, I am working on my PhD thesis titled Implementable Privacy for RFID Systems. My research is centered around cryptography for small devices and touches on computer security, information privacy, and the economics of information. My advisor is David Evans.

Smartcard Security

Our research blog has the latest updates and references.

Henryk Plötz and Starbug from the CCC Berlin and I have recently announced the break of the crypto algorithm in Mifare Classic RFID smartcards (which are used in many micro-payment application including the Oyster card, the CharlieCard, and the OV-Chipkaart).

To address concerns about the secuirty of the Dutch OV-Chipkaart, we have issued this press release:

Jan 8th '08: Lost Mifare obscurity raises concerns over security of OV-Chipkaart (PDF).

In response to our work, the research agancy TNO assessed the security of the OV-chipkaart system and found our claims to be accurate in a report issued Feb 29th. We welcome the report's call for the currently used cards to be replaced with more secure cards, but question the estimate that an attack will not happen within two years.

To help further understand the security of Mifare Classic-based systems, we assess the strength of the underlying cryptographic cipher and find that secret keys can be recovered within minutes on a typical PC:

Mar 10th '08: Cryptanalysis of Crypto-1 (PDF).

NXP, the manufacturer of the Mifare cards, announced an improved version that addresses all recent points of critique: it's build around standard cryptography and even provides some level of privacy protection.

Mar 10th '08: NXP introduces Mifare Plus.

The smart-card group at Royal Holloway, University of London released a third (and final) assessment of OV-Chipkaart's security for the Dutch government. The assessment confirms our analysis and recommends operators of Mifare Classic-based systems to migrate to more secure cards with publicly scrutinized cryptography:

Apr 15th '08: Royal Holloway: Security assessment of Mifare Classic in public transport.

Through further analysis of Crypto-1, we found the cipher to be highly vulnerable to algebraic attacks. Our most efficient attack takes only seconds on a PC, can operate on passively sniffed data from meters away, and works despite strong random numbers in Mifare Plus. The results were first announced at EuroCrypt 2008's rump session.

Apr 15th '08: Algebraic Attacks on the Crypto-1 Stream Cipher in MiFare Classic and Oyster Cards.

Our technique of hardware reverse-engineering used to recover the Mifare Crypto-1 cipher will be presented at Usenix Security:

May 14th '08: Reverse-Engineering a Cryptographic RFID Tag.

Steve Ragan at The Tech Harald covers our story in great detail and with extensive technical expertise in a series of articles:

Mar 4th University students in Virginia crack smartcard chips
Mar 12th U.VA. researchers crack smartcard chips . Mifare Classic security proven weak
Mar 12th Did NXP finally acknowledge security problems in their Mifare chip?
Mar 14th Interview: Karsten Nohl - Mifare Classic researcher speaks up
Apr 15th Replacement suggested for NXP chips used in OV-Chipkaart
Apr 16th More trouble for the MiFare chips


Some recent news articles covering the story include:

Jan 21st Schneier: Dutch RFID Transit Card Hacked
Feb 26th UVa Today: Group Demonstrates Security Hole in World's Most Popular Smartcard
Feb 28th Daily Progress: Security code easy hacking for UVa student
Feb 29th WCAV TV: UVa Grad Student Cracks Smart Card Security Code (with video)
Feb 29th WSLS.com: UVA grad, 2 other hackers claim they cracked credit cards and security badges codes
These articles are derivatives of the stories run by the Associated Press and the Media General News Service:
|-- Mar 1st Daily Press: U.Va. student, hackers crack credit card security code
|-- Mar 1st WVEC-TV: UVA student hackers say they've cracked smartcard encryption
|-- Mar 1st WVIR NBC-29: UVA Student, Hackers Crack Credit Card Security Code
|-- Mar 2nd Washington Times: Student decodes security devices
|-- Mar 2nd WAVY-TV: UVA Student, Hackers Crack Credit Card Security Code
|-- Mar 2nd Culpeper Star Exponent: Smartcard encryption code hacked
Mar 5th Sc Magazine: Hackers claim RFID smart-card hack, but chip vendor disagrees
Mar 6th Boston Gobe: T card has security flaw, says researcher (with video)
Mar 6th Boston Herald: CharlieCard is far from hack-proof
Mar 6th WCVB ABC-5 Teh Boston Channel: Problem Surfaces With CharlieCard Security
Mar 7th PC World: Hackers Find a Way to Crack Popular Smartcard in Minutes
Mar 7th Computerworld UK: Questions raised about Oyster card security
Mar 7th PC World Australia: RFID encryption flawed in smart cards, researchers claim
Mar 9th Richmond Times-Dispatch: U.Va. student claims to have cracked smartcard encryption
Mar 10th Computerworld NZ: Hackers find a way to crack popular smartcard in minutes
Mar 10th Infrasite News (Netherlands): Security hole in world's most popular smartcard
Mar 12th The Register: Microscope-wielding boffins crack Tube smartcard
Mar 12th PC World: RFID-Hack Hits 1 Billion Digital Access Cards Worldwide
Mar 13th Contactless News (FL): Hacked smart card chips? Alliance says no
Mar 13th TechRadar.com (UK): Is your Oyster card safe from hackers?
Mar 14th Computerworld: RFID hack could crack open 2 billion smart cards
Mar 14th RFID Journal: NXP Announces New, More Secure Chip for Transport, Access Cards
Mar 14th Windows IT Pro: Countless RFID Cards At Risk
Mar 14th Schneier: London Tube Smartcard Cracked
Mar 18th Computerworld UK: 'Soldiers deployed' following RFID hack
Mar 19th Computerworld: How they hacked it: The MiFare RFID crack explained
Mar 19th CIO Today: Student Claims to Have Cracked Smartcard Encryption
Mar 21st The Chronicle of Higher Education: Computer-Science Researchers Expose Security Vulnerability of Some Electronic Key-Cards
Mar 23rd Tamil Star (Sri Lanka!): RFID-Hack Hits 1 Billion Digital Access Cards Worldwide
Mar 26th SecureIDNews: Interview with Mifare hacker Karsten Nohl (Podcast)
Apr 1st EETimes: NXP RFID encryption cracked
Apr 11th Brisbane Times (Australia): Go cards 'doomed' over security
Apr 15th Computerworld: MiFare RFID crack more extensive than previously thought
Apr 16th Brisbane Times (Australia): New report slams go card security
Apr 16th The Register: Dutch transit card crippled by multihacks
Apr 21st Heise: Is the MiFare Classic RFID system blown?
May 12th The Green Sheet: Fraud busting, electronic style

Please note that we have not compromised the security of credit cards as some of the articles suggest. From what we can see, RFID-enabled credit cards have no security (yet?), and hence there is nothing to compromise.

Further clarifications on our smartcard work have been posted to our research blog.

Google has a video of our talk at 24C3 (slides):