Make us your homepage



  Top100  


  Classifieds  


  News  


  Help  


  Contacts  

Search: 

 



News

News category


Security flaw in smart cards poses risk for transit, building access

10.10.2008 06:02 Shopping - Source: cbc.ca

Transit systems across Canada stand to lose tens of thousands of dollars to fare fraud, and access to office buildings could be compromised, after a security flaw in some of their smart-card technology was widely publicized this week.

Computer-security researchers at the Radboud University Nijmegen in the Netherlands revealed how the smart-card technology, called Mifare, can be hacked to let anyone with a computer and $100 worth of parts create counterfeit transit and building-access passes.

Mifare uses a radio-frequency-emitting computer chip embedded in a plastic card. Transit riders wave the card over a reader to pay fares, while employees and students flash it at secured doorways to gain admittance in many offices and schools.

The management summary would be something like, 'Mifare Classic is broken.'—Dutch security researchers

The technology has been implemented in transit systems in St. John's, Gatineau, Que., the Greater Toronto Area and the Ontario cities of Kingston and Brantford, and is under consideration for use in Saskatoon.

Mifare chips, according to Dutch-based vendor NXP Semiconductors, are used in more than a billion radio-frequency identification (RFID) cards around the world — including security passes used to access buildings — and represent 70 per cent of the market for so-called contactless smart cards.

"The proprietary cryptography used on the Mifare Classic RFID chip is severely flawed," Wouter Teepe, one of the Dutch researchers, writes in a paper published Monday. "The management summary would be something like, 'Mifare Classic is broken.' "

Teepe and his colleagues cracked the encryption code on Mifare chips. They reported the security flaw in March, in the wake of earlier work by University of Virginia grad student Karsten Nohl, but only published the full details this week.

Once they'd cracked the encryption, the Dutch researchers were able to use hand-held antennas to remotely read the contents of someone's building-access pass, then forge a fake duplicate pass that gave them access to the same building.

The researchers also successfully hacked the Dutch national transit system and London's transit, showing how someone could get a day of free rides with little effort.

NXP working on solutions

Transit systems that use Mifare Classic smart cards are vulnerable in two ways. Because the cards communicate through the air using radio waves, a hacker could wirelessly read a transit rider's pass from a distance — several inches, or, as some hackers have demonstrated, up to 10 feet — and then "clone" the confidential information onto a blank impostor card that would seem like the original to a bus farebox. In transit systems where riders put money onto their smart cards that gets deducted with each trip, a hacker could also tinker with the card to increase its balance.

NXP Semiconductors has acknowledged the security problems and says it is working on solutions.

"It is NXP's objective to transparently update all system integrators and operators of infrastructures which use Mifare Classic in a timely manner," the company says in a statement on its website.

There are also ways to mitigate the security gaps, according to Juan Liverant, CEO of BEA Transit Solutions, which implemented smart-card payment systems for the transit networks in St. John's, Kingston and Brantford, as well as cities in Mexico.

"One is for the software on the back end to keep track of the balance on all the cards, and if one doesn't match what I have on my system, then the next time it's tried to be used it can be invalidated," Liverant told CBC News. "So far, to our knowledge, we haven't had a card cloned of all the systems we have in Canada or anywhere in the world."

But that fix has its shortcomings, Liverant acknowledged. Payment information has to be downloaded from every bus in the transit system onto a central database, which typically can only happen once the buses are parked for the night, so high-tech fare cheats would enjoy 24 hours of potentially free rides.

Also, riders with legit transit cards that were copied by a hacker would see their cards invalidated, in the same way that credit cards can be automatically blocked in the event of suspected fraud.

'It's unlikely we'd use that'

Cities around the world have been shaken by the Mifare flaw. In addition to London and the Netherlands, Mifare Classic is used in Minneapolis-St. Paul, Boston and Brisbane, Australia.

Edmonton is using Mifare technology in a small, pilot smart-card program to test the feasibility of deploying contactless payments across its transit system. But Graydon Woods, the program's manager, said the security flaw won't affect the city's transit in the long term.

"We're aware of the vulnerabilities with Mifare, so it's unlikely we'd use that," Woods said Thursday. "It's not applicable to us."

Elsewhere in Canada, the Gatineau transit authority implemented its payment system based on Mifare Classic in 1998. Burlington, Ont., a Toronto suburb, used a Mifare Classic system until last summer.

Vince Mauceri, a former manager with Burlington Transit and now the general manager of transportation operations for the Greater Toronto Area's Metrolinx transit agency, played down the Mifare problem.

"We're talking micropayments. We're not talking about buying a couch at Leon's," Mauceri said. "I think the crooks want to go after the big-dollar items, not micropayments."

Metrolinx is part of a project to implement a smart card called the Presto card for all Toronto-area transit systems over the next four years, and it will use a newer, more secure Mifare platform called DESFire — the same version Edmonton is considering.

Vancouver is also aiming to bring in smart-card payment systems, but transit authority TransLink is still in the early stages of planning and hasn't settled on what technology it will use, spokesperson Ken Hardy said.

Manufacturer blamed

The Dutch researchers who successfully hacked Mifare said NXP is entirely to blame for the security issues because the manufacturer decided to use a confidential, proprietary encryption method that was untested.

"All this demonstrates, once again, the dangers of relying on 'security by obscurity,' keeping the design of a system secret and relying on this to keep the system secure," the researchers said in a statement issued Monday.

"As all experts in the field agree, a better approach is … making the design of a system public so that it can be openly evaluated and scrutinized by experts."

  •  

Related

Internal Links

IN DEPTH: RFIDOttawa transit smart-card project gets $7M from OntarioSmart transit cards come to Montreal, QuebecOnt. minister says multi-system transit card a first for Canada

External Links

VIDEO: Dutch researchers demonstrate smart-card hack

(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)

Consumer Headlines

Most recent listeria finding 'very, very low,' says Maple Leaf CEO Maple Leaf's CEO says the most recent findings of listeria at the company's Toronto plant are a sign its testing system is working.Undergrad tuition rises to average of $4,724 a year: StatsCanFull-time Canadian undergraduate students paid an average of $4,724 in tuition for the 2008/2009 academic year, an increase of 3.6 per cent over the previous year, Statistics Canada said Thursday.Drug makers to change codeine labels to prevent overdose in babiesNursing mothers who take codeine medication should be aware that, depending on how quickly they metabolize the drug, their breastfed babies may be at increased risk of morphine overdose, Health Canada warns.Security flaw in smart cards poses risk for transit, building accessTransit systems across Canada stand to lose tens of thousands of dollars to fare fraud, and access to office buildings could be compromised, after a security flaw in some of their smart-card technology was widely publicized this week.4 more products test positive for listeria at Maple Leaf's Toronto plantFour product tests at a Maple Leaf plant in Toronto have come up positive for listeria, the deli meat producer at the heart of a deadly nationwide listeriosis outbreak said Wednesday.  

Consumer Life Features

YOUR MONEYFinancial adviceFINANCEInterest ratesMortgages, car loans hit by credit crunchSAFETYRecalls and Advisories
  • Electrical wire splices
  • Vacuum attachment
ENTERTAINMENTVideo gamesRequiem for the hardcore gamer?BLOGFood BytesWhen kids ask 'Can I help?', let themCOMM-ODDITIESMoneyWhat stock market crash?

People who read this also read …

  Add comment

Name: 
E-Mail: 
Comment: 
Enter code: 



« November 2008
MonTueWedThuFriSatSun
     12
3456789
10111213141516
17181920212223
24252627282930

Last added news

Auto dealers call for government help 21.11.2008 19:48 The industry group representing Canada's automobile dealers said Canadian politicians must take immediate steps to increase liquidity in the car markets.

Worried consumers turn to comfort spending on cosmetics, electronics 21.11.2008 19:46 Canadian consumers, worried about the wobbly economy, are shelving big-ticket purchases in favour of little luxuries, some retailers are reporting.

Michigan's governor hopes auto execs fly commercial on next trip to Washington 21.11.2008 17:45 LANSING, Mich. — Michigan Gov. Jennifer Granholm is confident the Detroit Three automakers will successfully persuade Congress to give relief to the battered industry next month.

GM to extend holiday shutdown, will cut production 21.11.2008 17:29 DETROIT — General Motors Corp. will extend its holiday shutdown or make other production cuts at five factories at as it deals with a continued U.S. auto sales slump and fights to stay solvent.

Dana stock stuck under $1 a share 21.11.2008 17:20 Skiers may have developed an affinity for Dana Holding Corp.'

Fostoria plant lays off 110 through month’s end 21.11.2008 17:18 FOSTORIA — ThyssenKrupp Crankshaft Co. has laid off 110 machine operators through the end of the month.

Rocket Ventures pledges $467,000 to local firm 21.11.2008 17:18 Rocket Ventures, the venture-capital fund operated by the Regional Growth Partnership, will make a $467,000 investment in AquaBlok Ltd.

Fannie, Freddie to halt foreclosures for holidays 21.11.2008 17:18 WASHINGTON — Mortgage finance companies Fannie Mae and Freddie Mac will halt foreclosure sales for about 16,000 households during the holiday season — Nov. 26 to Jan.

Belt-drive bikes go mass-market 21.11.2008 17:18 RICHMOND, Va. - For bicyclists whose pants cuffs have been shredded by the chain, a revolution may be at hand.

Top court backs free seat ruling for some disabled, obese travellers 20.11.2008 22:50 The Supreme Court of Canada has upheld a regulatory ruling requiring airlines to offer a free extra seat to certain disabled and obese people.

All news | News archive | RSS feed

Home    |    Add your site    |    Member login    |    Lost id    |    Contact Us    |    Help   |    Advertise    |    Privacy Policy

© Top100biz Inc., 2004-2005. This site is powered by AlphaStoreDesign.com