Cracking Atlanta Subway's Poorly-Encrypted RFID Smart Cards Is a Breeze 139
McGruber writes "Seven metro Atlanta residents are facing theft, fraud, and racketeering charges for allegedly selling counterfeit MARTA Breeze cards. Breeze cards are stored-value smart cards that passengers use as part of an automated fare collection system which the Metropolitan Atlanta Rapid Transit Authority introduced to the general public in October 2006. Breeze cards are supplied by Cubic Transportation Systems, an American company that provides automated fare collection equipment and services to the mass transit industry. At the time of this slashdot submission, the Wikipedia page for the Breeze Card (last modified on 2 August 2013 at 14:52) says: 'The Breeze Card uses the MIFARE smart-card system from Dutch company NXP Semiconductors, a spin-off from Philips. The disposable, single-use, cards are using on the MIFARE Ultralight while the multiple-use plastic cards are the MIFARE Classic cards. There have been many concerns about the security of the system, mainly caused by the poor encryption method used for the cards.'"
Inevitable... (Score:5, Interesting)
Re: (Score:3, Funny)
It's a subsidy for smart people, that's obvious -.o;
Re: (Score:3)
Why do you blame OP? Shouldn't you blame the company for using really stupid and known to be flawed encryption?
Re: (Score:2)
For the same reason we blame burglars even though houses still use doors that can be easiny kicked it and window that break so easily.
Re: (Score:3)
A 'locksmith' who uses his skills where not authorized is a burglar.
Re: (Score:1)
is this a serious question? do you honestly need an answer to the question of "if a thief gets in a poorly defended house, who is overwhelmingly at fault?" is your moral compass so broken?
Re: (Score:2)
We're apparently surfing the fine line between "blaming the victim" and "professional incompetency."
Re: (Score:2)
is this a serious question? do you honestly need an answer to the question of "if a thief gets in a poorly defended bank, who is overwhelmingly at fault?" is your moral compass so broken?
See how quickly the moral compass can spin when we change the nature of the "victim"? In this case we're talking about a transit company funded (at least in part) by tax payers with the losses directly impacting other users instead of some bloke who's now short a plasma TV.
Re: (Score:2)
Why blame the guy that shot you in the face? Shouldn't you have been wearing a bulletproof mask?
Re:Inevitable... (Score:4, Insightful)
Re: (Score:1)
So according to your logic, it's ok to steal something if the security is poor? Or to use a resource if it's security is poor?
Can I also punch someone in the back of the head because they're weak?
Re: (Score:2)
Re:Inevitable... (Score:4, Insightful)
There is this thing called a "reasonable man" standard. If you run a business website, you're expected to run it behind a firewall, and have other security standards in place.
Otherwise, you end up like any one of those companies that get hacked. I had stated it incorrectly earlier - I do not mean to say criminals who hacked the system are not in the wrong. However, implementing shitting security is also wrong.
Just like a bank should have a reasonable security system, and the bank's vault should have something better than a $5 padlock. Bank robbers are wrong, but if a bank had only a $5 padlock on it, *THEY ARE WRONG TOO!*
WHY ARE YOU SO FORGIVING OF COMPANIES THAT IMPLEMENT SHITTY SECURITY OR PUTTING IN FAKE SECURITY?
Re: (Score:2)
Re: (Score:3)
Who is talking about perfect security? I'm talking about not deploying systems with *KNOWN* security problems.
Like how WEP was known flawed and yet deployed, because of people like you. No one is talking about perfect security. But at least put some effort into making it secure, damnit. And by that, I don't mean letting your damned intern throw some shit together, but getting some seasoned professionals in the security field to work on it.
Re: (Score:2)
well.. the real problem is that it really cuts down on where you can use the card. with such shit security it's really just only going to work as a public transportation token AND you're going to need some guys going through the buses and checking peoples cards..
HK has a public transport smartcard paying system... that is, you load cash on the card.
and you can buy beer/mcd/whatever with that money too.
needless to say that if the security was as shite then the system wouldn't be in use for a day..
Re: (Score:2)
Show me a crack for AES-128.
Thanks.
Re: (Score:1)
It's stealing. It IS fundamentally bad. End of.
Now, it may have some upsides (education, vuln exposure/disclosure, financial [for the their]), but fundamentally, it's bad.
Re: (Score:2)
Re: (Score:2)
I don't actually use public transport. I just do some NFC work for the day job and know how weak the keys are in old MiFare stuff. No wonder you posted AC with that outburst of verbal diarrhoea.
Re: (Score:1)
evil is a silly construct. Read: Howard K Bloom, The Lucifer Principle: A Scientific Expedition Into The Forces of History
why? (Score:4, Informative)
Re:why? (Score:5, Informative)
After spotting a police car with two huge boxes on its trunk — that turned out to be license-plate-reading cameras — a man in New Jersey became obsessed with the loss of privacy for vehicles on American roads. (He’s not the only one.) The man, who goes by the Internet handle “Puking Monkey,” did an analysis of the many ways his car could be tracked and stumbled upon something rather interesting: his E-ZPass, which he obtained for the purpose of paying tolls, was being used to track his car in unexpected places, far away from any toll booths.
Re:why? (Score:4, Informative)
E-ZPasses Get Read All Over New York (Not Just At Toll Booths) [forbes.com]
The plausible explanation is that they are simply using ez-pass as a means to assess traffic congestion, ie how long is it taking a car to traverse a section of highway. Of course I don't doubt that law enforcement wants access to track people, but generally cell phone tracking is more reliable and readily accessible. Wanna bet these are at the border as well?
Re: (Score:1)
The technology is created by a company called Cubic Transportation Systems, and it turns out there are a lot of open questions about who is behind this company.
http://www.genuinewitty.com/2012/08/22/will-vancouvers-new-transit-passes-be-spying-on-you-and-who-has-access/
"A story came out recently linking Cubic to Trapwire- but, Cubic came out with a denial that they were connected. But, according to research by Cryptome.org, Trapwire is headquartered at the same address as Cubic, and some of the same people
Re: (Score:2)
Cubic also are behind the Ventra fare system used here in Chicago, which is a one big joke.
Re: (Score:2)
Quote without relevance. When read elsewhere, they are not deducting a payment. That was the point, not putting the account on the card.
And, it seems to be part of traffic management, so I don't see a major security issue here.
Whatever point you had, it got missed completely.
Re: (Score:3)
It allows for fallback to the stored value on the card if the data connection between the authenticating device and the home station is unreliable, as would be expected in a wide-ranging bus system when these cards were initially deployed.
Also EZPass and the like have the additional advantage of being tied to either a registered name or an easily identifiable way to bill someone (via a photo of the license plate) in case their account is empty. You don't have that luxury when dealing with people getting on
you don't have an 100% live data link with systems (Score:2)
you don't have an 100% live data link with systems like this (lot's of metro systems have both bus and rail and there can be cell dead zones that have areas with no data link) and you don't really have a away to bill later if there is some kind of read error.
Re: why? (Score:1)
Stored value also has nicer anonymity. Nothing tying it back to your identity (ie buy it with cash). Drop it in the street and you've lost your money a la cash.
Re: (Score:3)
The same is true for an anonymously bought card with remotely stored value.
Re: (Score:2)
Re: (Score:1)
Account based systems are a privacy nightmare.
With an account based system, you can basically track every pass user everywhere all the time.
That depends. If it's post-paid or renewing-prepaid account, you are correct.
If it's a prepaid account that is purchased anonymously and not re-loaded when the money runs out or the number of pre-paid days expire, then the privacy issues are much less. All you can do then is say when the card was used. Unless you have something else to go by, such video camera coverage of one of the times it was used, you can't say who the card belongs to.
Subway tokens should be cash-like (Score:1)
If I am not going to use cash, I'd prefer to use a token that is cash-like:
* is transferable like cash
* can't be tied back to me
* isn't widely counterfeited, so I'm not subsidizing freeloaders
* is convenient to use
Except may be for the counterfeiting part, subway tokens and prepaid fair passes generally meet this requirement.
I don't have any inherent objection to something that operates like a prepaid debit card, as long as I can purchase it anonymously without any additional fees beyond the fair itself. J
Re: (Score:2)
I don't understand why these systems are set up like this, operationally it's not much different from EZ-Pass which works fine with an account based system, putting the value tracking on the cards is just asking for an upgrade treadmill even if it's well designed now, 10 years from now it will be easilly cracked. compare CPU vs GPU/FPGA/ASIC hashing advances
Because its expensive to run a lot of data over GSM links in every bus/tram in the city.
We use same system in Poland and recently a group of people (over 900!) got charged with fraud. They werent the ones selling cards, they were the users, and only stupid ones.
in polish http://niebezpiecznik.pl/post/900-wlascicieli-falszywych-warszawskich-kart-miejskich-bedzie-przesluchanych/ [niebezpiecznik.pl]
Someone also offers Android app that charges cards using phone buildin NFC. You pay with BTC (yes, bitcoins). Its only available over
Re: (Score:2)
Because its expensive to run a lot of data over GSM links in every bus/tram in the city.
You don't need to send a lot of data. Maybe, 1kb for each authentication event? Assuming 2 million authentications per day (a lot) that comes out to 2 gigabytes of data per day. Last I was in Poland I think that cost around 20 zloty ( $10) to get on a prepaid plan. Hell, you can have it send 100 times as much data and you'll still end up paying less than the cost of maintaining the hardware itself.
There's a lot of reasons to not go with a GSM based approach but data cost is not one of them.
Re: (Score:2)
a) It's not a lot of data per link, but it is a lot of links. That 20 zloty plan is one link. Marta has 554 buses and 38 rail stations.
b) You have supplied no dataon the reliability of that link.
c) Pricing in Poland is not particularly relevant to Altanta, Georgia, USA.
Re: (Score:2)
a) It's not a lot of data per link, but it is a lot of links. That 20 zloty plan is one link. Marta has 554 buses and 38 rail stations.
Since you can't do the math apparently I'll have to. $20 per bus per month comes out to under $150k per year to have GSM data everywhere. For comparison, the Breeze Card program had a $100 million budget and Marta has a yearly budget of $400 million.
So no it's not a lot of links or a lot of data or a lot of cost although it is sad how people can't do simple math and research anymore.
b) You have supplied no dataon the reliability of that link
What part of "There's a lot of reasons to not go with a GSM based approach but data cost is not one of them" is hard for you t
Re: (Score:2)
If you implement the security properly it still won't be decryptable in 10 or 100 years time, unless something like quantum computing becomes a common reality in which case we have much bigger problems than people getting free rides. Processing power has nothing to do with it; even the fastest possible conventional computer is constrained by the laws of physics and couldn't break it in a useful timeframe.
As an example the FeliCa system, developed by Sony of all people, has not been cracked. It is also one o
Security (Score:5, Informative)
Like everything:
If you can buy the readers, and someone obviously sells the writers somewhere, you can clone them.
As soon as you then rely on these tokens to hold individual data themselves (with no reference to a central database), then they become valued targets for attack.
If you had these cards hold nothing more than a code number, and wired all the readers to talk home, then the system can't be "scammed" as such - people can have their cards cloned, of course, but you can spot it, you can trace them, arrest them at your convenience, and give the original account holder a new card in the meantime as soon as they report the fraud. But because everything has to talk to a central database, the cards are not so much "cash" as a stolen "credit card" - traceable, and stoppable.
Then, it doesn't matter if you do use something as common as MiFare (a school I used to work in used Mifare entry systems - they weren't expensive or hard to get hold of at all and I used to program my Oyster - London Tube travel - card to open the door for me in the morning if I'd forgotten my ID card). As soon as the readers are that commonplace, the writers will be available even if that means people are building their own and making fake "cards" the size of a Raspberry Pi with some RF circuitry to pretend to be a card. The next step is just a matter of shrinking the device.
MiFare is long-cracked. You can buy the cards for pence each and the readers (direct to USB, etc.) for a pittance. The next step up is no harder than going from magstripe readers and cards up to magstripe writers with the correct magstripe "level" to read/write the banking data on an old magstripe credit card.
Don't put "value" into a chip that can be cloned. Put the value into a central, monitored, system, and provide people only with a codenumber to access it. That codenumber can be cloned still, sure, but then you can watch out for it, notice it, blacklist it, catch people red-handed. And they can't go spending "free money" offline from your system.
This is my biggest bugbear with London's Oyster system. It's just a number for the most part, but they try to store "value" on the cards and let you buy newspapers with them. Now you have an offline, valued, unmonitored, commodity on an easy-to-clone chip.
Re: (Score:2)
always allow, but record the transactions, and go back later to reconcile.
In other words, treat it like we used to treat credit cards back before instant verification.
Anyone else remember signing a multi-part credit card form and having the clerk run it through the "ker-chunker"?
Re: (Score:2)
There have been a number of studies over the years that show that "honor system" fare collection actually works pretty well, with random manual checks by transit police. Yes, there are people who cheat (but then, there are people who hop the turnstiles, too), but *most* people pay their fare.
It's actually called "proof of payment". You buy a ticket or a pass in the station, and have it available for inspection. if you don't have the ticket, they fine you.
I assure you there's nothing "honor" about it. You're required to have a ticket, and pay a penalty if you don't have one.
Re: (Score:1)
"honor system"
Don't live in ATL do you?
Re: (Score:3)
Oyster is mostly online. There is an offline backup, because if you use it on a bus, the bus may not have a network signal at your bus stop. If you do manage to hack an Oyster card, it will work for one day, but when the reconciliation is done overnight, your card will be blacklisted and it won't work the following day, even in offline mode.
Re: (Score:2)
Re: (Score:3)
Not true - it's a lot more "offline" than you think.
That's why you have to nominate a station to "collect" your top-up - basically they preload to that station in the morning and then you card gets an instruction that you have X pounds more on it now. The card knows how much you have and works when the system is out (done it many times). That's how the vendor purchases work too - they rely on the card to have an up-to-date record of how much PAYG credit they have.
But, that said, when it is networked - as
Re: (Score:2)
My work ID does door access, printing, loads of stuff. Spoof the UID onto a blank token, remove the chip/antenna,
Re: (Score:3)
Our Mifare card access system used to read data off of the latest PayWave-type phones. To our systems it was just a random long number but it uses the same frequencies, protocols, etc. as everything else RFID to power itself/send it.
Caused havoc with our systems when people started buying Galaxy S3's and holding them in their hands while they swiped their entry cards. We wondered what the hell was going on for a long time.
Re: (Score:2)
Don't put "value" into a chip that can be cloned. Put the value into a central, monitored, system, and provide people only with a codenumber to access it. That codenumber can be cloned still, sure, but then you can watch out for it, notice it, blacklist it, catch people red-handed. And they can't go spending "free money" offline from your system.
There's a problem with central database hookups, what happens when the link fails, what's the maintenance cost of a central database and all the links? In Brisbane they've all but given up on manual ticketing systems. I imagine the cost of a handful of people taking free rides is less than the cost of maintaining a central system, and less than the cost of what would happen when the system went down, or any kind of local database gets corrupted.
Yes there's ways around the value on the card problem, but are
Re: (Score:2)
Re: (Score:2)
You can't just read it, it's not a memory card. It is a microcontroller you talk to. Transactions require a cryptographic handshake. The only thing you can read is the current value and a transaction history, and you can't write anything.
The microcontroller has physical protection to stop you removing the top with acid and reading the memory directly. If you try it commits suicide and wipes itself. So far no-one has managed to read one.
The flaw here is the cryptographic handshake. Cloning is still impossib
Re: (Score:2)
See other posts - you can buy writeable tokens for next-to-nothing from China, and you can figure out the keys inside any such device using utilities available on Google Code and a bog-standard reader.
Re: (Score:2)
Re: (Score:2)
If you bought your Oyster card pre-2010, it's not a DESFire one. But it still works. Still holds credit. Hasn't been recalled. Hasn't been disabled. I have at least two that we use for visitors from my girlfriend's country, we used them last week. Saying "DESFire cards" are secure is no good if DESFire isn't a requirement of the transport system in question. My Oyster card goes back at least 7-8 years, I believe, and that's because I lost the one I used to use when I was in Uni.
Additionally, NXP are
How is this okay, but BitCoin is OMG Bad? (Score:2)
Re: (Score:2)
Re: (Score:2)
Oyster cards upgraded past the broken old MiFARE Classic chips some time ago, I believe. NXP make several generations of cards of which the Classic is the oldest and most broken. The more modern/expensive cards, not so trivial to crack.
Re: (Score:1)
Oyster has switched to DesFire cards which have MiFare emulation but better security.
Another card scam... (Score:4, Interesting)
.
Fare cards, gift cards, credit and debit cards used at Target, etc.,.etc,. etc...
When are we going to make our erzatz money secure?
Re: (Score:2)
Re: (Score:2)
When are we going to make our erzatz money secure?
When it becomes cheaper to pay for security than for damages. Same thing with banking websites.
Re:Any Detail, At All? (Score:5, Informative)
What about any detail at all about this? What "weak" encryption do they use? How was it broken? What was the value of the fraud? Can these cards be used for anything else, or cashed out, or does this fraud require very extensive MARTA ridership?
Seven people have been charged with fairly serious crimes, but I can't see the value of the fraud being more than a few hundred or few thousand dollars. It's like counterfeiting $1 bills, what's the point?
It appears that MARTA is just discovering the extend of the fraud, based upon the information in this article by the NBC affiliate in Atlanta: Atlanta Channel 11 TV News: 7 arrested for MARTA Breeze Card fraudl [11alive.com]
Some detail:
MARTA says the thieves spent $1 to buy the Breeze card, then reprogrammed the data on it to turn it into a 30-day pass. They then sold it to riders for $40, a deep discount of the real price of $96. That meant the thieves got to pocket $39, and the buyers got a cheap ride.
and
MARTA police chief Wanda Dunham says the cards were sold at MARTA stations and on Craigslist. But it was a suspicious buyer who purchased one at an area mall that contacted police. "He knew that wasn't the right fare so he called us, asked us to check into it," said Dunham.
As they investigated, the agency's Revenue Department noticed in November, a large number of cards were sold at its Chamblee and Lenox stations for only a dollar. Police started reviewing surveillance video to create a list of suspects.
MARTA won't say how many counterfeit cards the group sold, but says during the arrests it confiscated 400 fraudulent cards. Had the thieves sold them, their $400 initial investment, would have earned them $16,000.
MARTA says it's never had something like this happen before, but security expert Gregory Evans says MARTA needs to act fast, if wants to keep it from happening again. He says the hackers likely got away with their scheme using a simple card writer that costs just a few hundred dollars. "The crazy part, the scary part about this? MARTA would have never known if some had not gone back and told them what was happening. That's it," said Evans. Evans says the data on the card could be encrypted and an alert built into their software system. "If I go to use this card somewhere and all the sudden there's $100 on this card, their system should have caught that and said hold up," Evans said.
MAX-VALUE and EXP DATE hardcoding (Score:1)
And this is why stored-value cards should have MAX_VALUE and EXPIRATION_DATE hard-coded into them.
Re: (Score:1)
That doesn't help anything. Blank cards cost $1. You are supposed to add fares to them. The cards need to hold up to at least a 30 day pass. Max value would be a 30 day pass. That's what they were selling. They weren't selling $1000 credit or anything. Just a 30 day pass. Expiration dates are several years in the future. People want to keep their card and reload it as often as necessary. You would have to keep buying new fake cards every 30 days, to maintain the discount, so the expiration date is also irre
Re: (Score:3)
Seven people have been charged with fairly serious crimes, but I can't see the value of the fraud being more than a few hundred or few thousand dollars. It's like counterfeiting $1 bills, what's the point?
I spent $3,000 on Metrolink tickets last year in Los Angeles. I know many people who pay more. there is serious money in mass transit.
re MARTA (Score:1)
Like most of the other government run entities in Atlanta, Marta is run by inept management and awards bids to cronies and
relatives. I am not surprised the system was outdated and ineffective.
Does it really need to be secure? (Score:3)
Re: (Score:3)
In my view the system only need be marginally more secure than the honor system.
I couldn't agree more. And since there is an extreme lack of honor these days, I feel that the next step, rather than spend so much money to secure the transaction(s), is to simply utilize credit/debit cards. If that doesn't work, fuck it, shut the MARTA down; "Sorry folks, the people in this area are to wicked to have nice things."
Re: (Score:3)
Apparently they also do passes that are good for 30 days, which cost $96 (see the comment a few places above). The scam was to buy lots of $1 tickets and reprogram them into 30-day ones.
Re: (Score:1)
Marta sucks. If you're using Atlanta's public transit, it's probably because you can't afford a car. To a minimum-wage earner, it's not hard to imagine that $5 a day is worth cheating.
Re: (Score:1)
They were saving $56 every 30 days buying counterfeit cards. Less than $2 per day. Where did you get $5 from? Lots of people who ride MARTA have cars. You not only save on gas and save on parking, you also don't have to deal with the traffic. Additional benefits, you can read or whatever on MARTA, not while driving. Additional benefit, you can be drunk on MARTA. You can go to happy hour after work, no worries. Additional benefits, less pollution and less dependent on foreign oil. MARTA is pretty good especi
The world need more people like this (Score:1)
Quick question (Score:5, Interesting)
Out of curiosity, how much revenue comes in from fares, and how much expense goes out in fare maintenance?
A lot of metro systems charge fares in addition to getting public support from taxes. Has anyone thought to tally the costs of the fare system compared to the income? Things like cost of the machines, maintenance of the machines, maintenance of the turnstiles, accounting, law enforcement &c... all these things add up.
Even if the fares bring in revenue, it's probably minor. Most of the cost goes into collecting the fares, so most of that value is wasted.
The economy would get a boost if that money were freed up to be spent by consumers, and doing so would help the people who need it the most (ie - poor people).
This whole thing seems like a fabricated problem - a system that forces people to spend money just for the sake of spending it. Then spend more money reimplementing the system when the original system is found to have flaws, then spend countless hours and resources in enforcement and prosecution.
Just get rid of it. Let the money go into the economy.
Re: (Score:2)
While I am receptive to the concept that sometimes it is not worth it to collect the money (that why transit systems are moving to face cards, so that they don't have to handle change), fares also provide some demand management. Even if you are not applying demand-based fares, charging a non-zero amount the far end of the demand curve which would happily fill and overflow all capacity and will let you find when/where you really need to add new capacity.
Re: (Score:2)
While I am receptive to the concept that sometimes it is not worth it to collect the money (that why transit systems are moving to face cards, so that they don't have to handle change), fares also provide some demand management. Even if you are not applying demand-based fares, charging a non-zero amount the far end of the demand curve which would happily fill and overflow all capacity and will let you find when/where you really need to add new capacity.
Wow. Elliptical much?
Put it in terms of value. Does demand management have any value? Could demand be managed by another method, such as historical prediction, or simply by having people press a button to "call" trains to stations?
You can't make a case for options unless the value (or utility) of each option is known. Just referring to an amorphous ill-defined term "demand management" doesn't cut it.
Does demand management have any value? And if it does, is demand management by fares the best way?
Re: (Score:3)
That's a great question. From what I've read about the Minneapolis light rail system, fares cover about a third of the operating cost. I'm not sure what the fare collection costs are (machines, enforcement, etc) but its hard to see them being more than 10% of the fare revenue, especially when you consider that a lot of the collection costs are upfront (buying, installing machines, etc) and basically one-time costs.
You do wonder what would happen if they just made riding it free. It might mean more riders
Re: (Score:2)
I'm not sure what the fare collection costs are (machines, enforcement, etc) but its hard to see them being more than 10% of the fare revenue, especially when you consider that a lot of the collection costs are upfront (buying, installing machines, etc) and basically one-time costs.
I can't find a detailed budget for Minneapolis, but fare costs for other cities are always over 85% (for cities I've looked at to date) and can be higher than 100% in some cases. BTW, fares account for only 15% of the Minneapolis light rail revenue (source [patch.com]).
There are a lot of hidden costs, such as personnel to collect the coins/tokens/strips, empty and reload the machines, personnel to do maintenance, and such. Personnel are very expensive to maintain - did you include the pensions?
I don't know what the exp
Re: (Score:2)
I can't find a detailed budget for Minneapolis, but fare costs for other cities are always over 85% (for cities I've looked at to date) and can be higher than 100% in some cases. BTW, fares account for only 15% of the Minneapolis light rail revenue (source [patch.com]).
The difference is explained in that article: fares only account for 15% of the total cost for Minneapolis light rail, not 15% of the total revenue. Most cities only talk about fares collected vs operating expenses; they don't include capital expenditures and debt service, which together can be larger than operating expenses.
Re: (Score:2)
In that article the politician was saying that fares are 30% of the revenue used to offset operating expenses, but that excludes any mention of servicing the mortgage on the capital investments, which he argues doubles the actual cost of a ride, meaning fares provide only 15% of the cost of the ride. (I think it's a poor argument, by the way, because it completely ignores the benefits produced by a functioning mass transit system, but that's a giant political debate that we don't need to have here.)
The gra
Re: (Score:3)
There are indeed reasonable number of fare-free systems. But you neglect the core purpose of public transit as it is seen by most US governments—i.e. distributing cash. Even if a system has 10% farebox recovery, they still get to buy the equipment and employ people to collect the money. Sure, they could go to proof-of-payment (or drop fares entirely), and further reduce costs by putting the Buy America Act and Davis-Bacon out of their misery, but that would reduce the opportunity for graft.
3 questions (Score:2)
1.Why are these things so weak and easily broken
2.Why don't the companies that make them invest a bit more money in making them harder to break (instead of on lawyers to sue people who break them)
and 3.If the companies that make them wont fix them, why isn't someone else offering systems with stronger encryption?
Re: (Score:2)
I'd really like to know the answer to #3.
Off the top of my head, I don't understand why they don't have a private key known only to the bus/station equipment that does the reading/writing of the amount on the card and some kind of incrementing or rotating ID to prevent replay attacks/card cloning? Each bus could have an ID and a counter, then each morning distribute to a system on each bus the bus/counter combinations that have already been used maybe say in the past 3 or so months depending on how much da
Re: (Score:2)
Re: (Score:2)
The thing that comes to the top of my mind is customer throughput and system speed. Public key cryptography works on really big numbers, and RFID technology doesn't exactly operate at blazing megabit speeds. Long ago we tried a smart card (contact) system that took 1500 milliseconds to exchange an RSA encrypted message with the reader at 9600 baud. The four cryptographic exchanges the vendor had the device performing took a total of six seconds, and none of our customers liked it. For a transit system t
NYC born, recently moved to Atlanta (Score:2)
MARTA - Moving Africans Rapidly Through Atlanta (or so the locals call the system).
It's probably wrong to, but I applaud the hackers. It's really only the poor folks in Atlanta that use the system (everyone else drives) and every little bit they can save helps.
Re: (Score:1)
I find the abbreviation, MARTA, cute. Reminds me of a certain video game character.
Re: (Score:2)
Snopes:
Some years ago, the famous San Diego Zoo opened a second, larger branch called the San Diego Wild Animal Park. The Park is built around an enormous open-field enclosure where the animals roam free. To see the animals, visitors ride on a monorail called the Wgasa Bush Line which circles the enclosure. Here's the true story of how the Wgasa Bush Line got its name. They wanted to give the monorail a jazzy, African sounding name. So they sent out a memo to a bunch of zoo staffers saying, "What shall we call the monorail at the Wild Animal Park?" One of the memos came back with "WGASA" written on the bottom. The planners loved it and the rest is history. What the planners didn't know was that the zoo staffer had not intended to suggest a name. He was using an acronym which was popular at the time. It stood for "Who Gives A Shit Anyhow?"
Re: (Score:2)
It's funny how Northerners are the most racist people in the South these days.
Get real (Score:1)