Aussie Researchers Crack Transport Crypto, Get Free Rides
mask.of.sanity writes "Shoddy customised cryptography by a state rail outfit has been busted by a group of Australian researchers who were able to replicate cards to get free rides. The flaws in the decades-old custom cryptographic scheme were busted using a few hundred dollars' worth of equipment. The unnamed transport outfit will hold its breath until a scheduled upgrade to see the holes fixed."
Governments give these contracts to retarded companies, simply because they offer to do it for a lower price than "proper" companies would.
Same exact thing happened in the Netherlands, Trans Link Systems got the contract for the "Public transit chip card", it was hacked in a week. An improved, "unhackable" version was also cracked when it was released.
The problem with these companies mostly is that they think security through obscurity actually works, which is pathetic.
Can be found here.