Monday, July 25, 2011

Building

Building Android from source takes hours! Olga and I first built it on Friday, but dependency issues corrupted the output. I think I satisfied those this morning, so we should find out if the hardware was successfully unlocked by later today or tomorrow.

On a different note: I have five plane trips in August, and three of those are cross-country. I picked up A Dance with Dragons and Pattern Recognition to keep me company. Planes are perfect for catching up on reading.

Friday, July 22, 2011

Field Trip

All of the REU students at UMass went to Cambridge yesterday to check out Google, Microsoft Research, and the MIT Museum.

The most interesting stop was Google, where we talked with Steve Vinter, were led through the offices, and ate at the on-site cafeteria. Everyone was well-prepared and very nice, and I think I'll apply there soon.

The visit to Microsoft went okay.

There were a few neat exhibits at the museum; I never thought I'd see Kismet in person. (Nor Adi Shamir and Ron Rivest!) The collection of mechanized sculptures ate up most of my time when I was there.

Wednesday, July 20, 2011

Card Emulation

It looks like we'll have to modify the firmware for the phone in order to unlock additional features like CICC emulation. A few other people have done this successfully before and were kind enough to share their modifications. Hopefully we'll have a working device by the end of the week.

It couldn't hurt to apply to the Open Source Software World Challenge if we think we can finish in time.

On an unrelated note:
The weather here is so much more extreme than Oregon! Thunderstorms one day are followed by oppressively hot days the next. Even the temperature difference between day and night is crazy. No wonder the roads need repair so often.

Update: I forgot about a field trip to Boston on Thursday, so we'll probably have it done by next week.

Tuesday, July 19, 2011

Focus

We nailed down a project for our project last week: a man-in-the-middle attack. I completed the bridge between the reader and the tag simulator  yesterday, and Olga is working on how to get the device to simulate a tag. Today I'll start on the user interface and combine the bridge with the reader.

Only a month left! I hope I can contribute enough in time.

Thursday, July 14, 2011

So many refinements!

I've been tweaking the EMV library all week, and I can finally start reading records from contactless ICCs. For some reason, my code cuts out after the first record.

I figured out why I couldn't talk to some cards: they shut off after about 65,000 uses. If I can get my hands on some fresh cards, I may be able to communicate with them without raising that counter.

Olga and I will be giving a presentation today to the other REU students here about our project. Kind of nervous.

Update: My code successfully reads all available data from financial cards that follow the EMV standard. Hooray! Now time to deal with the issuers that like to tweak things.

Friday, July 8, 2011

Project Update

I've been working on an EMV library with contact-less cards in mind, and it's actually pretty fun to implement a specification. So far it can only talk with one type of credit card. I don't know whether this is because my reader doesn't supply enough power to the other cards or because the other card manufacturers' were too liberal in their application of the EMV standard. I think it may be both.

I made a very comprehensive error-messaging function yesterday that takes in Status Words (SWs) and make them human-readable. So far it's been a fantastic help.

I finally got a key to the building a few days ago, so I won't have to bother the very nice cleaning ladies that get here early in the morning.

Tuesday, July 5, 2011

Specifications

Dr. Ravi Pappu's talk on how standards are formed during RFIDsec was both enlightening and disheartening. An otherwise beautiful specification becomes bloated to massive proportions in order to support compatibility with existing systems in which the private sector has made considerable investment. I get to wade through 823+ pages of dry specification standards that are riddled with exceptions, and it's nice to know who's responsible for making them so horrible.