<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Relay attack featured on Dutch TV</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2009/12/17/relay-attack-featured-on-dutch-tv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2009/12/17/relay-attack-featured-on-dutch-tv/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:31:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mike Bond</title>
		<link>http://www.lightbluetouchpaper.org/2009/12/17/relay-attack-featured-on-dutch-tv/comment-page-1/#comment-42247</link>
		<dc:creator>Mike Bond</dc:creator>
		<pubDate>Sat, 19 Dec 2009 22:55:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=1460#comment-42247</guid>
		<description>Well done chaps, looks like it was challenging to do all that working against the clock, and interesting to read this technical summary of the issues you encountered.

It brings rather vividly to mind that when we were first considering relay attacks in 2006 that a chap from a POS vendor contacted us and told us we were talking nonsense and technically wrong... that the timing constraints were so tight that a relay attack that might sound good in theory just would be near impossible to pull off in practice without a really expensive custom radio link etc.

At the time I just poo-pooed his private advice, and indeed a year or so later the demo was up and running and really did work. But maybe he knew something we didnt at the time... that some terminals were pretty sensitive to timing. His conclusion was still ultimately wrong, but this at least explains in my head why this chap so earnestly believed that it wouldnt work.

Anyhow, thanks for posting the synopsis.

Mike</description>
		<content:encoded><![CDATA[<p>Well done chaps, looks like it was challenging to do all that working against the clock, and interesting to read this technical summary of the issues you encountered.</p>
<p>It brings rather vividly to mind that when we were first considering relay attacks in 2006 that a chap from a POS vendor contacted us and told us we were talking nonsense and technically wrong&#8230; that the timing constraints were so tight that a relay attack that might sound good in theory just would be near impossible to pull off in practice without a really expensive custom radio link etc.</p>
<p>At the time I just poo-pooed his private advice, and indeed a year or so later the demo was up and running and really did work. But maybe he knew something we didnt at the time&#8230; that some terminals were pretty sensitive to timing. His conclusion was still ultimately wrong, but this at least explains in my head why this chap so earnestly believed that it wouldnt work.</p>
<p>Anyhow, thanks for posting the synopsis.</p>
<p>Mike</p>
]]></content:encoded>
	</item>
</channel>
</rss>

