Advertisement
Promo

Security threats Toolkit

Fears for Oyster security as researchers claim crack

Tom Espiner ZDNet.co.uk

Published: 23 Jun 2008 13:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Questions have been raised about the security of chips in Oyster cards after Dutch researchers claimed to have successfully cracked and cloned cards, and travelled on London Underground for free.

According to Dutch publication Webwereld, researchers from Radboud University cracked the Mifare RFID chip, from NXP, used in the Oyster card, travelled on the Tube and then restored the balance on the card. The researchers also claimed to have launched a successful denial-of-service attack against Tube entry gates, causing them to jam closed.

Radboud researcher Wouter Teepe presented evidence to the Dutch parliament on Wednesday, in which he outlined the research. Teepe declined to comment to ZDNet.co.uk on Wednesday, directing us to a Radboud University spokesperson. The spokesperson also declined to comment, saying only that Transport for London (TfL) had been informed and that the university was preparing a scientific paper on the subject, due in October.

TfL said it runs daily tests for cloned cards and that anyone caught using such a card could be prosecuted.

"We run daily tests for cloned or fraudulent cards and any found would be stopped within 24 hours of being discovered," wrote a TfL spokesperson in an email to ZDNet.co.uk. "Therefore, the most anyone could gain from a rogue card is one day's travel. Security is the key aspect of the Oyster system and Londoners can have confidence in the security of their Oyster cards. Using a fraudulent card for free travel is subject to prosecution."

TfL insisted that Oyster cards have "robust security" that operates "at different points in the system", and claimed that personal information could not be compromised through a Mifare card hack.

Read this

Feature
Keep mobile data from going walkabout

Mobile email is no longer the preserve of upper management but providing access to company information on the go has its risks...

Read more +

"Should one security measure be breached, another will protect Oyster cards and the system as a whole," wrote the spokesperson. "No personal information is stored on an Oyster card and specific information relating to the individual card holder (name, address, telephone, etc) is stored on a central database and kept separate from journey data."

Security experts called for TfL to upgrade the Mifare chips in April, after a series of Mifare cracks were publicised. "My understanding is there are now three [Mifare] cracks at least," Adam Laurie, an RFID and communications protocol security researcher and consultant, said in a keynote speech on RFID flaws at the Infosec 2008 conference. Speaking to ZDNet.co.uk after his speech, Laurie said he thought TfL, the body that runs the Oyster-card scheme, "ought to think about upgrading as soon as possible".

Laurie said the Dutch government had been right to announce it was replacing the Mifare-based cards. "I applaud the Dutch government for jumping straight on it," he said. "It would be better if TfL just got on with it. It's a bit of an arms race; once you know it can be done, that's enough of an impetus to say: 'We will get on and do it.'"

TfL said on Monday that it was not considering reviewing its use of Mifare technology in Oyster cards.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
20 out of 20 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters