Alarming Suburban Ticketing System Hack

Alarming Suburban Ticketing System Hack

Techtree News Staff, Aug 14, 2008 1630 hrs IST

In an alarming development, a bunch of young researchers at Radboud University Nijmegen, Netherlands have managed to crack the ticketing system used by major suburban transportation systems around the world.

In this age of terrorism and cyber crime, here is one more news that could send security analysts and researchers in a tizzy.

A bunch of young researchers at Radboud University Nijmegen, Netherlands have managed to crack the ticketing system used by major suburban transportation systems around the world. The chip in question is called the "MiFare" and is manufactured by NXP Semiconductors. Generally considered very safe, the system is being used by transit solutions in cities around the world - including Delhi, where it is used in the Metro Railway. Apart from suburban rail networks, MiFare cards are also to control access to buildings.



The hackers and their weapons



The researchers claim that the proprietary CRYPTO1 encryption system used by these cards can be easily retrieved, especially when a common key is used for all RFID (Radio-Frequency Identification) readers and cards. Common keys are used on a large scale in large buildings and organizations. The hack itself is a simple affair, at least theoretically. What the hack does is to retrieve the secret key from the MiFare reader, which takes a while. Once the key is retrieved, the data is taken offline and then decrypted. Once this is done, the cracked key can be used to predict other random keys as well. The retrieved cryptographic key can provide various possibilities for abuse depending on the situation. For example, if all the cards share the same key, the card of a genuine employee/personnel can be cloned just by close contact and the affected person might not be even aware that his identity has been stolen. In case different keys are used, things become a lot safer - but it still remains vulnerable.

Earlier, two German researchers Karsten Nohl and Henryk Plotz had also reported security flaws in the technology. These two had actually managed to reconstruct CRYPT01 and had announced the same at a hackers' conference back in 2007. The Dutch team however did not replicate the encryption system - they simply exploited the weaknesses in the armor. This had happened in March 2008, and the news was immediately not revealed owing to security concerns. They wanted to ensure basic steps are taken to counter the vulnerability before the flaws were discussed. The Dutch Government was involved and kept in the loop. Later, the Dutch General Intelligence and Security Service confirmed that the hack was as effective as an attack. Post this, the companies involved - NXP and Trans Link Systems - were briefed and technical representatives from the company are working with the researchers to analyze the impact of the security breach and develop countermeasures to patch the weaknesses.

The researches cited security concerns for the delay in reporting this security flaw.

Read more here.

A video by the team:



Write a comment

       (All fields are mandatory.)

Text Limit = 255 Characters

Type the characters you see in the picture below.

#

Characters are not case sensitive.

USER COMMENTS

cheers .....great !!!!

by Fifanomore, Pune, on Aug 14, 2008 06:56 PM, Report abuse   Reply

by Nil, Mumbai, on Aug 15, 2008 03:48 PM, Report abuse

what is CRYPTO1 encryption system?

by Parag Joshi, Mumbai, on Aug 15, 2008 03:47 PM, Report abuse   Reply

And they even made a video of it? Haha!!

by Gdn | TD, Chennai, on Aug 14, 2008 07:23 PM, Report abuse   Reply

VIEW ALL LATEST

RBI Delibrates On E-Wallets And Cash Card Norms

News > Internet , November 22, 2008 0830 hrs IST

Approach paper readied ...

LiveJournal Gets India Focused Communities

News > Internet , November 22, 2008 0938 hrs IST

For all you movie and sports buff ...

Indians Big in Online Spending

News > Internet , November 21, 2008 1857 hrs IST

Surprisingly 76% spend on digital downloads ...

Flash Drives Surpasses Blu-ray Capacity

News > Gadgets , November 21, 2008 1831 hrs IST

Kingston new offing the -- DT150 USB drives ...

Search Gets Personal With Google SearchWiki

News > Internet , November 21, 2008 1748 hrs IST

A service giving search power to the user ...

 

USER REVIEWS

Security NEWS

Hide
Microsoft: Security Suite To Be Free

Microsoft: Security Suite To Be Free

News | Security | 19 Nov 2008

Comprehensive protection against viruses, spyware, rootkits, and Trojans

Microsoft Patches Bug After 7 Years

Microsoft Patches Bug After 7 Years

News | Security | 13 Nov 2008

Releases a security patch

Obama, McCain Cyber-attacks have Chinese Origins?

Obama, McCain Cyber-attacks have Chinese Origins?

News | Security | 11 Nov 2008

Hackers got away with a large amount of sensitive data

Security REVIEWS

Hide

Security USER REVIEWS

Hide

MOST POPULAR NEWS

Hide
News

Could A DVR Save Your Marriage?

News | Consumer Electronics | 04 Sep 2008

...Or should you stick to your shrink?

News

Firefox Counters Chrome's Speed Test

News | Internet | 04 Sep 2008

According to Mozilla's SunSpider test, Firefox 3.1 is 28% faster than Chrome on ...

News

Nokia N96 for Rs. 40,000?

News | Telecom | 04 Sep 2008

False alarm everyone... We have learnt from Nokia that the N96 will be priced be...

MOST POPULAR REVIEWS

Hide

MOST POPULAR GAMES

Hide

MOST POPULAR DOWNLOADS

Hide
Downloads

Forbidden.exe

Downloads | Games | 02 Sep 2008

Downloads

md5deep

Downloads | System Tools | 04 Sep 2008

Downloads

RivaTuner

Downloads | System Tools | 03 Sep 2008

Close