Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those interested can read more https://security.stackexchange.com/questions/158167/mifare-d... here.

Modern fare systems (Vancouver Compass for example) use the DESfire EV1 and it's as secure as it gets.



Assuming they're using it properly. I remember cracking a Mifare Ultralight based bus fare system. It seemed sound as the Ultralight had write-once blocks or blocks that you could decrement depending on the card's configuration, so you could make it that a block has the number of trips remaining on the card, each time you validate the card it decrements it and there was no way to increment it.

The issue in their case was that 1) they didn't set the configuration of the card properly, so the blocks they were using weren't actually configured to be decrement only, and 2) the validation machines checked whether a card had enough trips and then decremented the block without checking whether the decrement was successful. I was able to make the remaining fares block read-only while the card was full, essentially making an infinite card.


As far as I am aware there's nothing on the Compass cards, just an id so it's impossible to do much about it. If you lose it, you can get a new one with balance intact which is telling.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: