California's Wireless Road Tolls Easily Hackable
An anonymous reader writes "Nate Lawson, a researcher at RootLabs, has found a way to clone the wireless transponders used by the Bay Area FasTrak road toll system. This means you can copy the ID of another driver onto your own device and, as a result, travel for free while others foot the bill. Lawson also raises the interesting point of using the FasTrak system to create false alibis, by overwriting one's own ID onto another driver's device before committing a crime. Luckily, Lawson wasn't sued before he could reveal his research, unlike those pesky MIT students."
I think I read about this in little brother.
And they can record license plates. I think this hack has little criminal viability. Anyone who used it extensively would be caught in short order. Though authorities might be willing to let the criminal conduct continue on until the criminal passed the felony threshold.
You've got it the wrong way around - people won't use this to create alibis before committing a crime, they'll use it to establish evidence of the target being in a certain area at a certain time even though he swears he was elsewhere
At any rate, certain requirements have to be met before something can be introduced as evidence. I'm assuming most things (like this) would, by default, not constitute evidence anyway. Email (at least in this country) needs to be provided along with an audit trail before it's accepted as evidence
I'm a minority race. Save your vitriol for white people.
Between the splash screen redirects and the ads, this article is nearly unreadable. Here's the text for those who don't want to put up with the crap.
----
Drivers using the automated FasTrak toll system on roads and bridges in California's Bay Area could be vulnerable to fraud, according to a computer security firm in Oakland, CA.
Despite previous reassurances about the security of the system, Nate Lawson of Root Labs claims that the unique identity numbers used to identify the FasTrak wireless transponders carried in cars can be copied or overwritten with relative ease.
This means that fraudsters could clone transponders, says Lawson, by copying the ID of another driver onto their device. As a result, they could travel for free while others unwittingly foot the bill. "It's trivial to clone a device," Lawson says. "In fact, I have several clones with my own ID already."
Lawson says that this also raises the possibility of using the FasTrak system to create false alibis, by overwriting one's own ID onto another driver's device before committing a crime. The toll system's logs would appear to show the perpetrator driving at another location when the crime was being committed, he says.
So far, the security flaws have only been verified in the FasTrak system, but other toll systems, like E-Z Pass and I-Pass, need to be looked at too, argues Lawson. "Every modern system requires a public security review to be sure there aren't different but related problems," he says. Indeed, in recent weeks, researchers announced flaws in another wireless identification system: the Mifare Classic chip, which is used by commuters on transport systems in many cities, including Boston and London. However, last week, the Massachusetts Bay Transportation Authority (MBTA) filed a lawsuit to prevent students at MIT from presenting an analysis of Boston's subway system.
The Bay Area Metropolitan Transport Commission (MTC), which oversees the FasTrak toll system, maintains that it is secure but says it is looking into Lawson's claims. "MTC is in contact with vendors who manufacture FasTrak lane equipment and devices to identify potential risks and corrective actions," says MTC spokesman Randy Rentschler. "We are also improving system monitoring in order to detect potentially fraudulent activity."
In the past, authorities have insisted that the FasTrak system uses encryption to secure data and that no personal details are stored on the device--just two unique, randomly assigned ID numbers. One of these is used to register the device when a customer purchases it, while the other acts as a unique identifier to let radio receivers at tolls detect cars as they pass by.
But when Lawson opened up a transponder, he found that there was no security protecting these IDs. The device uses two antennas, one to detect a request signal from the toll reader and another to transmit its ID so that it can be read, he says.
By copying the IDs of the readers, it was possible to activate the transponder to transmit its ID. This trick doesn't have to be carried out on the highway, Lawson notes, but could be achieved by walking through a parking lot and discreetly interrogating transponders.
What's more, despite previous claims that the devices are read only, Lawson found that IDs are actually stored on rewritable flash memory. "FasTrak is probably not aware of this, which is why I tried to get in touch with them," he says. It is possible to send messages to the device to overwrite someone's ID, either wiping it or replacing it with another ID, says Lawson.
"Access to a tag number does not provide the ability to access any other information," says MTC's Rentschler. "We also believe that significant effort would need to be invested in cloning tags." He adds, "If any fraudulent toll activity is detected on a customer's account, the existing toll-enforcement system can be used to identify and track down the perpetrator."
Lawson says that using each stolen ID just once would make it difficult to track
I don't know about California, but in New England they have cameras that can match up a vehicle with a FASTLANE transmitter. It would not be very hard to also hook up license plate scanners. This seems like a crime with very little payoff, and huge chance of getting caught.
When you have the ability to send the same data over and over again without any form of authentication or obfuscation - yes, it can be copied and used by anyone else.
There are ways to prevent this:
Use a rolling code, like my garage door, key fob, and online banking fob uses.
Use another form of authentication, like color of vehicle, plate number, or something else easily identifiable on the car.
These are about as secure as my Speedpass fob that I can use to purchase fuel and snacks at Mobil stations. If its stolen, anyone can use it.
Old wireless toll systems didn't event use encryption, such as the case of old Amtech 2.4GHz systems, which are limited to store information similar to a typical ISO Track #2 credit card (PAN, and some other info). However, modern system, such as the CESARE european standard (public information, no revealing secrets here, of course), includes modern security (realtime generated derivate key negotiation, etc.).
...given that almost all of the toll transponder systems in the US have cameras, and plate recognition is done. I once got a ticket from another state (NY), claiming a plate I had years ago had gone through one of their upstate tollbooths. Also, my father would get notices in the mail from our state's system when he moved the transponder to a vehicle that wasn't registered to use it. So. Useless hack, sensationalist article, film at 11.
Please help metamoderate.
Perhaps this can be used to create privacy clubs, where they all travel on cloned cards and all share the bill. Their movements couldn't be tracked via this system as long as multiple people were using it.
I hope this wasn't posted already... I searched the thread for "Anonymous" and then felt kind of silly.
When this story first broke a couple of weeks ago, they suggested a far more serious abuse than just taking someone's transponder ID as your own.
It was suggested that the reading and reprogramming could be accomplished so quickly that one could set up an antenna near a busy highway and read IDs from vehicles while assigning them the ID of the previous vehicle.
This would result in a huge shuffling of IDs that would be a bureaucratic nightmare for the state and a huge pain for FastTrac's customers. The state is trying to get as many people as possible to adopt this system, and a major hack like that could possibly reverse their momentum.
Maybe other democratic governments aren't quite as corrupt?
It's amazing to me that you can totally distrust your government to do anything right, yet think that private enterprise overseeing parts of your life is somehow better.
Okay, so less of your income is taxed. The flip side is that the company isn't accountable to anyone--you can't vote them out! And if they *are* accountable to someone... well guess what, it's probably to government oversight!
I trust the government to do a better job than a private company. Call me crazy, but the private company is in it SOLELY to make money. The government, while making money, would be doing it because it is a job that they are trusted to do fairly, and are held accountable by the people. Companies are held accountable by their shareholders, and will do anything and everything to make money, including screw over the general populace.
As for your condemnation of the 'promote the general welfare' clause, I ask, why not have these programs? Part of the government's job is to provide a safety net, because, believe it or not, sometimes shit happens. Part of living in a society means helping out others in that society. If someone in your community is needing help, you help them out. Having programs such as Social Security, Medicare, and other programs is so that, when the times get rough, there is something there to help you get back on your feet. This is called COMPASSION for those in need.
As for the commerce clause - Are you kidding me? Companies are being allowed to EASILY send all their jobs overseas, buying shoddy products from China to be sold here, to pollute as much as their money will let them, to use tax loopholes to screw workers out of benefits they have had for years, and God knows what else. And you think their the government is regulating with an iron fist? On the contrary. The government needs to start regulating commerce much, much more, to ensure that corporations do not trash the world and the people in it, simply for a better bottom line. While there is nothing wrong with a free market, an unregulated free market will bring about the downfall of civilization, and working man will suffer the most because of it.
As for your Ayn Rand fascination, you probably should know that she is all about herself, and screw everyone else. She was a selfish bitch who didn't give a damn about anyone else except herself.
And if you were thinking that running red lights is not illegal, and that you have a right to run them, please never drive near me. I'd rather not die because you felt it was your moral right to plow into me at 70 miles an hour.
I don't like Linux. This doesn't make me a troll.