RFID blocking - security questions

To be absolutely clear, ISO14443 requires anticollision support for transponders. That means all systems can differentiate tags, but not all systems do or bother to. I know it’s a tedious exercise but it’s fundamentally important to understand that anti-collision is built into the protocol itself and it’s trivial to literally cycle through all tags in the field and read them all. Placing multiple ISO 14443 or ISO 15693 cards together will absolutely not protect against readers being able to access the cards.

In those scenarios where systems… that means the readers and the middleware and the application layer… systems do not bother to iterate through cards or check for multiple cards in the field, oftentimes it comes down to random chance which card is actually read. If you have ever experienced placing a wallet up to a reader in an elevator or access control system and having it deny you because there were multiple cards in your wallet, there’s a good chance that you could just keep repeatedly presenting your wallet until the proper card is picked up first and read.

3 Likes