5 ms·
This isn't just a problem with just universities. I have a card reader as well, and any site that issues swipe-able ID cards is more than likely susceptible.
by omgitstom 12y ago
This isn't just a problem with just universities. I have a card reader as well, and any site that issues swipe-able ID cards is more than likely susceptible. You would be surprised how many use an incrementing ID that you can easily impersonate another user.
The equipment needed to create fake cards (not just blanks) that look good is trivial to purchase.
I would be curious if OSU built or bought this system to issue cards. If they built it, shame of them. If they bought it, shame on them as well. Any security audit would have caught this clearly. Cards like any interface require good design for use and security.
- samsnelling 12y agoI think you hit the nail on the head here - this isn't a super sophisticated reverse engineer. Total equipment cost is $300 (for one that prints a full color front!) and you could theoretically impersonate anyone on a wide array of systems.