UPDATED: Oyster card hack is published
By Nicole Kobie,
Details on how to hack the RFID chip have finally been fully published, after a legal battle to keep the information from being released into the public domain.
Professor Bart Jacobs at Radboud University in the Netherlands revealed the details of the hack at a security conference yesterday.
The Mifare Classic RFID chip is used by the Oyster travel card, which lets users swipe for access onto London public transport, as well as by many building entry systems. NXP, the maker of the Mifare chip, tried to delay publication of the hack with a court injunction, but it was revealed yesterday at the European Symposium on Research in Computer Security in Spain.
Steve Owen, vice president of identification sales and marketing at NXP Semiconductors, told the BBC that his firm’s legal move was designed to give its customers time to protect themselves.
"We sought the injunction to cause a delay, not to completely stop the publication," he said, adding that NXP does not recommend the Mifare Classic for new installations.
The Dutch researchers said the hack allowed cards containing the chip to be cloned, and used the knowledge to travel on London’s transport system for free last summer. At the time, Transport for London said it had noticed the cloned cards in its system and fixed the flaw.
NXP spokesman Alexander Tarzi told IT PRO his firm regrets that the researchers released the details, not least because its customers may need years to make the necessary upgrades. "NXP would like to point out that a broad publication of detailed information to carry-out attacks with limited means is, at this moment in time, contradictory to the scientific goal of prevention and the responsible disclosure of sensitive information."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





