Options

Web Trends and Digital Lifestyle
This item is part of the public WebDB named Web Trends and Digital Lifestyle - Add Feedback
Oyster card hack to be published   22/07/2008 - 10:48:09


Oyster cards, PA
The research will be unveiled at a security conference in October

Details of how to copy the Oyster cards used on London's transport network can be published, a Dutch judge has ruled.

The ruling overturns an injunction to suppress the information won by NXP - makers of the travel smartcards used in London and many other cities.

The injunction was sought in June 2008 after Dutch researchers demonstrated how to copy cards and travel free on the London Underground.

The researchers plan to publish their research in October.

Cracked cards

The security weaknesses in the Oyster card were discovered by Prof Bart Jacobs and colleagues from Radboud University, Nijmegen in March 2008.

The weaknesses centre around the chip, called the Mifare Classic, that sits at the heart of the contactless card system.

As well as being used on 17 million Oyster cards, the Mifare chip is used about 1bn smartcards worldwide, and is the basis of the Dutch Rijkspas card.

Many organisations, including governments, use Mifare technology as a secure entry system for buildings.

Given the many millions of cards in use Prof Jacobs held off publishing details about how the information on the chips can be copied and used. It told the Dutch government and NXP about its work to give them time to harden systems against the attack.

Assume organised crime knows about this, assume they will be selling it anyway
Bruce Schneier

Despite this, NXP sought an injunction to ensure the details of the attack would never be aired.

The case went to court in Holland and now the court in Arnhem has overturned the injunction citing local freedom of expression laws.

In its ruling, the court said: "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."

In a statement, Radboud University hailed the ruling and said: "...in a democratic society it is of great importance that the results of scientific research can be published".

Christophe Duverne, a spokesman for NXP, told Reuters that it would take months or years for some users of the chip to adapt their systems to defend against the attack.

"We don't mind them publishing the effects of what they have discovered to inform society, I think this is absolutely fine," he said. "But disclosing things in detail including the algorithm ... is not going to benefit society, it will create damage to society."

A spokesman for Transport For London said: "Transport for London remains confident in the security of the Oyster card system. We take fraud and the security of personal data extremely seriously and constantly review our security procedures."

He added: "Any fraudulent card would be identified within 24 hours of being used and blocked. Using a fraudulent card for free travel is subject to prosecution and we would seek to enforce this wherever possible."

Security expert Bruce Schneier said: "As bad as the damage is from publishing - and there probably will be some - the damage is much, much worse by not disclosing."

Mr Schneier said it was a "dangerous assumption" to think that only the researchers know about weaknesses with Mifare.

"Assume organised crime knows about this, assume they will be selling it anyway," he said.

Information about the research will be published in a journal and shown at a security conference held in Malaga. The Dutch group is one of three known to have cracked the Mifare Classic technology.

Original Location: http://news.bbc.co.uk/2/hi/technology/7516869.stm

Drill Down Search: hacker Keywords: hacker

Related public Items that share at least one of the item’s keywords.
49 related items were found. (1 to 49 shown) SlideShow 
36981 US credit card hacker sentenced usa hacker 27/03/2010 - 09:32:05
36103 Microsoft bounty for worm creator microsoft hacker worm 13/02/2009 - 22:58:13
35441 How To Become A Hacker hacker cracker 13/12/2008 - 17:32:50
33618 NZ teenage hacker charges dropped hacker botnet 16/07/2008 - 17:14:44
33213 Jail sentence for botnet creator botnet spam hacker 13/06/2008 - 07:33:07
32898 Spain arrests 'prolific' hackers spain hacker 18/05/2008 - 09:12:19
31709 'Hacker' launches iTunes copying hacker itunes 20/02/2008 - 17:11:36
31131 Quarter of US iPhones 'unlocked' apple iphone hacker 29/01/2008 - 15:17:36
24925 Internet crime 'is big business' crime hacker virus 17/09/2007 - 07:44:34
23850 How 'Hackers Are Us' worked hacker 28/06/2007 - 09:02:50
23849 Private-eye hackers are convicted privacy hacker 28/06/2007 - 08:59:00
23640 Anatomy of a spam e-mail spam hacker 14/06/2007 - 22:36:52
23639 Spinning a web to catch a hacker hacker honeypot 14/06/2007 - 22:33:52
23636 Caught in the net hacker botnet ddos sabotage 14/06/2007 - 22:21:12
22358 UK hacker loses extradition fight hacker 03/04/2007 - 21:43:58
21957 'Surge' in hijacked PC networks hacker 19/03/2007 - 16:34:53
21896 US tackles Indian share-hack scam hacker 14/03/2007 - 13:59:46
21752 Three hacker teams unlock the PSP sony psp hacker 28/02/2007 - 21:52:11
19665 Hi Tech Crime crime spam phishing hacker botnet 13/10/2006 - 15:43:07
19352 Security breach hits online world hacker game 11/09/2006 - 13:36:58
18032 Woman targeted by web hackers hacker 03/06/2006 - 18:04:52
17213 Tougher hacking laws get support hacker 07/03/2006 - 19:16:08
16236 Profile: Gary McKinnon hacker 16/02/2006 - 07:48:45
9176 Microsoft warns of latest flaws microsoft hacker 09/11/2005 - 20:20:08
7837 TLC :: Hackers: Biggest Hack Poll hacker 07/10/2005 - 13:42:33
7284 Hackers target net call systems hacker voip 19/09/2005 - 17:00:08
7189 Paris Hilton hacker sent to jail hacker mobile phone 16/09/2005 - 07:52:13
3324 Top 20 computer threats unveiled virus hacker loophole 11/04/2005 - 19:55:31
3323 Digital self-defence hacker virus 11/04/2005 - 19:50:24

Telecommunity wide Keyword Search
You can also search for the following keywords in all public Telecommunity WebDB Items: hacker ·