[17050] in cryptography@c2.net mail archive
DC metro smartcard failure/exploit?
daemon@ATHENA.MIT.EDU (Anne & Lynn Wheeler)
Sun Mar 13 14:40:17 2005
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 09 Mar 2005 11:52:51 -0700
From: Anne & Lynn Wheeler <lynn@garlic.com>
To: cryptography@metzdowd.com
In-Reply-To: <422DB1D0.1040507@garlic.com>
anybody hear of a DC metro (smartrip) smartcard failure/exploit?
you have a smartcard that supposedly has $10-something left ... and the
next time you go to the station ... the turnstyle says "not acceptable,
see stationmaster". the stationmaster puts the card in a reader and the
display comes up and says the card has negative $5 balance. in theory,
the transactions with the smartcard are encrypted (and possibly the
values stored in the chip are also encrypted). somehow the card has had
a failure/exploit that made it look like the card has a negative $5 balance?
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com