Log In   |  Register Free Newsletter Subscription
Skip navigation
Zibb
Subscribe to Consulting-Specifying Engineer
RSS
Reprints/License
Print
Email

Smart-card hackers expose dumb flaws

College students crack a relatively simple code in frequently used access technology to expose major security weakness.

Jenni Spinner -- Consulting-Specifying Engineer, 8/26/2008 8:37:00 AM MT

Three Massachusetts Institute of Technology (MIT) students hacked into Boston’s mass transit system earlier this year. Once in the system, they cracked the flimsy code guarding the data, enabling users to add money to fare cards without paying a penny. The act adds up to more than a prank—it exposes the inherent weakness in a security technology used in door-swipe badges, fare cards, and other security and access systems worldwide.

In 2006, the Massachusetts Bay Transportation Authority (MBTA) spent nearly $200 million upgrading its fare collection system. Because the Mifare Classic chip the new system uses a quickly crackable cipher (as demonstrated by the MIT students), MBTA officials are faced with the possibility of having to scrap that system and spend yet more revenue on a new, better-guarded technology.

Other departments have responded to the exposed security flaw. In the United Kingdom, London Underground officials installed a stopgap measure to secure the system while a permanent upgrade is being developed. In the Netherlands, government officials have placed security guards at doorways once guarded only by smart cards.

RSS
Reprints/License
Print
Email
Related Content
Also by Jenni Spinner

Reed Business Information Resource Center

Featured Company


Most Recent Resources

Advertisement
Sponsored Links
Advertisement
NEBBOKBanner
NEWSLETTERS
NewsWatch
Business of Engineering Management Report
Fire, Security, Life-Safety Newsletter
Electrical Newsletter
HVAC Newsletter
Pure Power Newsletter
Product Showcase Newsletter
Greenscene
CSE Codes & Standards



Please read our Privacy Policy

About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Free Subscription   |   Affiliate Links   |   RSS
© 2009 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites