4 ms·
Smartcard security is notoriously bad in the vast majority of deployed systems. The people designing these high human traffic systems are usually much more con
by pius 18y ago
Smartcard security is notoriously bad in the vast majority of deployed systems.
The people designing these high human traffic systems are usually much more concerned about other factors (low latency at the turnstile, minimal number of network connections to wire, card reliability, etc.) than they are about security.
- jrockway 18y agoSometimes I wonder why they even bother collecting fares. Fares rarely cover the cost, so paying money to develop an expensive fare collection system that's easily hackable doesn't make much sense. Oh well, at least the politicians can give their contractor buddies my money!
- stcredzero 18y agoThere needs to be good standards program for security audits. There is a serious problem, because security is not well understood. It's very easy to sell the government and private organizations a shoddy set of goods. What about institutionalizing white hat hacking, somehow? I could imagine a system where two competing tiger teams ensure good results. Basically, pay bonuses for actually breaking the security measures. If only one team succeeds in breaking in, then they get both team's bonus.
- krschultz 18y agoWell not sure about what part of the world you are in, but here in Manhattan the MTA subway system pays for itself. Only about 4-5% of their operating budget comes from taxes, with the remainder coming from fares. A serious vulnerability would crush their budget. I can just imagine going into some back room to buy a $1,000 metro card for $5. However I can't imagine many people really bothering, an unlimited card is only $81 a month. When rent is $2500 a one bedroom apartment in brooklyn, and lunch is $15 every day, $81 for all of your transportation really isn't a big deal. Excellent hack though.
- andr 18y agoMBTA, the system they hacked, is notoriously inefficient. Apart from fares, they get 20% of state sales tax, or 1 cent of every dollar you spend in the state, even if you don't live in a place that has a train station. The new (electronic) fare system was introduced about 18 months ago and was accompanied by a fare raise from 1.25 to 2.00/1.75, and one of the major reasons quoted was the cost of the new system.
- thomasmallen 18y agoYou guys are so lucky. Here in DC, we have the second-highest ridership in the country, and somehow these nincompoops can't get the system to pay for itself. Never mind that we don't have month passes like in most normal cities, and that somebody who regularly rides the Metro will easily spend in excess of $200, even $300 per month. Thanks for hiking fares again, guys! And the number of cars, stations, and miles of track almost certainly pale in comparison to those in New York. Hell, I pay $140/month to take the Orange line two stops west and a flat-fee bus to its second stop on the route. And people wonder why we have such awful traffic: Driving is often cheaper!
- GavinB 18y ago". . . lunch is $15 every day . . ." Get some bread and make a sandwich, already!
- gaius 18y agoHaha, half the apartments in Manhattan barely even have kitchens!
- angstrom 18y agoAgreed. The cost of implementing such an open system is negligible compared to the cost of securing it. You can harden a system as much as you want, but the business case for doing so is nil until it becomes a problem. At 0.000000003 of rides are being stolen it doesn't make sense. While the security tzars are focused on the electronic hackers just having fun the majority of losses are probably coming from kids who jump the turn styles or go through 2 at a time.
- stcredzero 18y agoDoesn't this apply more to the vendor and less to the customer? The vendor can sell a system and skimp on the added cost of security. If they are good at managing the account and spinning the situation, when security issues do come up, they have a chance to sell the customer an entirely new system. The customer is probably better off with a spec for proper security in the first place, so they can avoid the cost of refitting or replacing the entire system.