New Zealand's Hackable Transport Card Grants Free Bus Rides
mask.of.sanity writes "Kiwis could have their names, addresses, dates of birth and phone numbers exposed by flaws in the Christchurch public transport system that could also allow locals to travel on buses for free. The flaws in the MiFare Classic system allow anyone to add limitless funds to their transport cards and also buy cheap grey market cards and add them to the system. The website fails to check users meaning attackers could look up details of residents and opens the potential for someone to write a script and erase all cards in existence. Several flaws have been known to the operator since 2009."
There are two sets of problems: their website is not adequately secured, allowing identity harvesting attacks, and the transit cards themselves are easy to forge.
Why have you fallen
Why have I become
Why have you done this
I'm gonna shoot my cock into the deepest parts of your disgusting asshole and fill it with the stickiest goodies all around! Wow! It's overflowing with my disease-ridden cum! Vanish already, I say!
-----------
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in trouble. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh and depressing reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why the
Ignorance is a choice
-----------
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in trouble. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh and depressing reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why the
Ignorance is a choice
-----------
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in trouble. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh and depressing reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why the
Ignorance is a choice
There have been already a couple of mifrate classic public transport implementations where they discovered the card was abusable! eg http://en.wikipedia.org/wiki/OV-chipkaart#Technology
This was known in 2007.
frankly they should have used a software system that worked with phones with optional card if you wanted it rather than a phone
Oyster has been hacked again and again...
http://www.wired.com/autopia/2008/06/hackers-crack-l/
regards
John Jones
Good news everybody! Here in New Zealand such actions as hacking cards to add value, or taking personal information off websites, or even wiping data off someone else's computer system are all illegal.
Thus solving the problem once and for all.
Recycle PCs and build a wireless community network www.hillsborough.org.nz
So I get free rides on the bus and anyone can see my (fairly public) directory information... not such a bad deal.
Fifty years of Yippie! 1968-2018
Why is it that transit smart cards always seem to take longer to roll out than promised, cost more than promised, end up being more complex than promised and end up being less secure than they should be?
You dont even need to make the cards themselves "smart", you can make the cads just data storage devices that can store an encrypted data blob and do all the cryptography and stuff in the readers. And you can use good strong well-tested cryptography instead of inventing your own crypto.
Cards would be cheaper because they wouldn't contain much logic, just a memory chip, RFID/NFC/whatever antenna and some logic to read from and write to the memory chip. Anyone who builds a reader and reads their card out will simply get an encrypted/signed blob that they cant mess with.
they just had their city destroyed by an earthquake. let them have all the free bus rides they want.
... apparently don't make Smart Cards.
I'm all for subsidizing this kind of public infrastructure if only because the alternative is using tax money to deal with all the extra traffic. However, I don't believe that making it free is a good idea. Transportation, public or not, still costs money; with free public transport, all financial incentives for people to reduce unnecessary movements disappear, as do financial incentives for the operators to increase efficiency. This is asking for ever increasing costs of the public transport system.
Avantslash: low-bandwidth mobile slashdot.
Although there is no excuse for lousy security, the "security hobbyist" did fail to mention in the article that the city was hit by an earthquake in February 2011, which mostly destroyed the central city. I suspect that might have more to do with Ecan's delay in implementing a new system, rather than just "they wanted a new flashy-looking website".
Thankfully the new "Compass" card being forced onto Vancouver transit users will absolutely, positively have none of these problems.
Three Squirrels
MiFare classic was shown to be vulnerable long ago. What was it, 10 years ago? Transit systems with half a brain upgraded to newer versions back then!