Nespresso smart cards hacked to provide infinite coffee after someone wasn't too perky about security
- Reference: 1612420808
- News link: https://www.theregister.co.uk/2021/02/04/nespresso_cards_hacked/
- Source link:
In a coordinated vulnerability [1]disclosure published this week, Polle Vanhoof, a security researcher, describes a vulnerability affecting unspecified Nespresso Pro machines [2]equipped with a smart card reader: the problem? Some rely on outdated Mifare Classic smart cards.
[3]
As Vanhoof explains, Mifare Classic smart cards have not been a particularly smart choice since 2008, when security researchers from Radboud University Nijmegen [4]reverse engineered the chip on the cards and [5]published their findings.
Perth SmartRider public transport cards popped by student researchers [6]READ MORE
[7]
At the time the disclosure was made, chip maker NXP Semiconductor advised customers to adopt its Mifare Plus cards, which rely on more robust encryption (AES-128). Some of Nespresso's coffee cards nonetheless have been based on the insecure Mifare Classic technology.
Using an NFC card reader, nfc-mfclassic (a Mifare Classic command line tool), a version of mfoc (a Mifare Classic offline key cracking tool) that he [8]patched to work properly, and a [9]Python analysis script , Vanhoof cracked the weak encryption and dumped the card's binary.
He then made a coffee purchase to see where the binary data changed, reflecting a credit deduction.
"We are working on the assumption that the value of the card is kept on the card itself rather than on some centralized server," said Vanhoof. "This is a much simpler and cost effective design, requiring less hardware and software to implement, making it a likely choice for anyone developing such a system unaware of the security weaknesses of the Mifare Classic."
Having identified the binary data on the card that changed with a purchase event, Vanhoof was able to alter the three bytes used to store monetary value and write the a value (€167,772.15) back to the card using the nfc-mfclassic tool. That would be a lot of coffee if he was unethical.
The Register emailed Vanhoof seeking comment but he declined.
Vanhoof, in his post, advised Nespresso to upgrade its smart cards and to store monetary value on a remote server rather than on the smart card itself. "After talking to Nespresso, it seems they already offer both of these options," he said.
[10]
We asked Nespresso to clarify which of its machines might still rely on Mifare Classic cards, but we've not heard back. ®
Get our [11]Tech Resources
[1] https://pollevanhoof.be/nuggets/smart_cards/nespresso
[2] https://www.nespresso.com/pro/be/fr/payment-solutions
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBvT0Dtwzm3TyEww9v9PfQAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2008/10/06/mifare_hack_finally_published/
[5] https://www.theregister.com/2008/10/06/mifare_hack_finally_published/
[6] https://www.theregister.com/2016/05/02/busted_students_pop_perth_smarttraveler_cards_get_free_rides/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBvT0Dtwzm3TyEww9v9PfQAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://github.com/pollev/mfoc
[9] https://pollevanhoof.be/files/nuggets/analyze_nespresso.py
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBvT0Dtwzm3TyEww9v9PfQAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: Coffee and Mifare Classic
Easy to spot the hacker, he's the one wide eyed hanging off the ceiling.
Absolutely appalling thinking that someone would do that: drinking coffee.
Better drinking coffee than teabagging.
Depends if you are the bagger or the baggee? And I thought this teabagging required one man, and two women to connect the dots?
Believe it or not, I've only had one cup of coffee in my life! When I was a kid it was expen$ive and not a children's drink. I never cared for the smell of coffee, throw a few morning ciggies from the parents on top of that... I'm glad they smoked ciggies and drank coffee then, I do neither as an adult because of it. The parents have long stopped both coffee and ciggies!
To be perfectly fair ...
,,, the bilge known as "Nespresso" is hardly coffee.
Re: To be perfectly fair ...
Dangerous ground (Ha!) for someone from the US...
Yes, I know, just as with the beer - you can have decent in the States..
Re: To be perfectly fair ...
At least here in the States we don't try to brew it like tea, with boiling water.
Yes there is good beer here in the States. When I have friends over from Europe and the UK, instead of taking them wine tasting (everybody does that!), I take them on a tour of the breweries here in Northern California's supposed "wine country". First timers are always quite shocked at the quality and variety of real beer around here. And no, contrary to popular belief, it's not all overly hopped IPAs.
Relax, Nespresso isn't coffee. Not really. Ask a real coffee drinker. I'm surprised Vanhoof admitted to this one.
Nespresso 'Smart Cards' - maybe not so smart then?
Especially if they can be hacked by what I can only imagine to be the student masses (as in later life the general stress of making a living and having to deal with incompetent bosses day in and day out is usually enough to keep me wide awake at night).
I worked temporarily at a firm that had smartcard entry system and used the same card for lunch payments. The HR bloke who was doing my hello welcome to the firm told me it meant it was quicker for everyone in the canteen. I was give my freshly printed card and immediately tested it with my phone and discovered twas a Mifare classic. I mentioned this to the HR bloke who listened to my explanation that these had been hacked and cracked. He said they knew but this wasn't a problem for the firm. Adding money onto the card was done by debit card and the cash value stored on a central computer not the card. Therefore they'd dealt with the threat of somebody 'adding' money to the card. Further to that it had been signed off as perfectly safe to use by DORM (the department of risk management).
It is fair trade ...
Mi Fare trade coffee
Nespresso...
For coffee lovers that wouldn't know a decent coffee if it bit them in the arse.
Re: Nespresso...
AKA "The English" with their high street coffee shops selling assorted tepid brews for eye-watering prices.
Only in Italy, Turkey and to some extent France and Spain can you get consistently good coffee from a variety of outlets.
Re: Nespresso...
Nah. They all ruin it with boiling water, just like the Brits.
Something something Java
Binary Dump
"He then made a coffee purchase to see where the binary data changed, reflecting a credit deduction."
I did the same thing in about 1984 with Zork to stop the burning branch going out.
Security matters, people. Wake up and smell the coffee
Coffee and Mifare Classic
Guaranteed to give sleepless nights.