Mobile // Mobile Devices
News
10/2/2008
08:43 AM
Connect Directly
RSS
E-Mail
50%
50%

California Bans RFID Skimming

Advocates of the bill say it will help maintain security for millions of state residents who use the technology in their everyday lives.

It's now illegal to surreptitiously read RFID tags in California.

The state's governor, Arnold Schwarzenegger, signed SB 31 into law Tuesday. The legislation makes it "illegal to take information from RFID tags" without an owner's knowledge and permission. Exemptions allow emergency medical workers and law enforcement to scan RFID tags to identify unresponsive people or solve crimes, as long as they have obtained a warrant.

"The problem is real," said State Sen. Joe Simitian, a Palo Alto Democrat who introduced the legislation. "Millions of Californians use RFID cards to gain access to their office, apartment, condo, day care center or parking garage. Our passports now use the technology, and there is continued discussion about the possible use of RFID in drivers' licenses. Yet, up till now, there's been no law on the books to prevent anyone from skimming your information, and it's surprisingly easy to do." Simitian conducted an experiment in which his access card for the State Capitol was skimmed and cloned by a hacker in a second.

"Minutes later, using that clone of my card, the hacker was able to walk right into the Capitol through a 'secure' and locked entrance," he said. "RFID technology is not in and of itself the issue. RFID is a minor miracle with all sorts of good uses, but it's easier than ever to steal someone's personal information. With an unauthorized reader -- technology that is readily available, off-the-shelf, and surprisingly inexpensive -- it's really quite simple to do." Simitian said the public would resist emerging technologies without privacy and security protections.

The new law drew support from a wide variety of groups, including: the American Civil Liberties Union, Gun Owners of California, Privacy Rights Clearinghouse, Citizens Against Government Waste, California State Parent Teacher Association (PTA), Republican Liberty Caucus, and the National Organization for Women (NOW). Nicole Ozer, technology and civil liberties policy director for the ACLU of Northern California, praised Schwarzenegger for signing the bill into law.

"Just like Californians wouldn't allow a stranger to sift through their wallet and take their driver's license or want their children or grandchildren to tell passers-by on the street who they are or where they live, our private information must not be read at a distance without our knowledge or consent," she said. "By signing SB 31, Governor Schwarzenegger has taken an important step to safeguard the privacy, personal and public safety, and financial security of millions of families."

Comment  | 
Print  | 
More Insights
Building A Mobile Business Mindset
Building A Mobile Business Mindset
Among 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps and it's past time for those with no plans to get cracking.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - August 27, 2014
Who wins in cloud price wars? Short answer: not IT. Enterprises don't want bare-bones IaaS. Providers must focus on support, not undercutting rivals.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Howard Marks talks about steps to take in choosing the right cloud storage solutions for your IT problems
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.