UPDATED: Oyster card hack is published
By Nicole Kobie,
Details on how to hack the RFID chip have finally been fully published, after a legal battle to keep the information from being released into the public domain.
Professor Bart Jacobs at Radboud University in the Netherlands revealed the details of the hack at a security conference yesterday.
The Mifare Classic RFID chip is used by the Oyster travel card, which lets users swipe for access onto London public transport, as well as by many building entry systems. NXP, the maker of the Mifare chip, tried to delay publication of the hack with a court injunction, but it was revealed yesterday at the European Symposium on Research in Computer Security in Spain.
Steve Owen, vice president of identification sales and marketing at NXP Semiconductors, told the BBC that his firm’s legal move was designed to give its customers time to protect themselves.
"We sought the injunction to cause a delay, not to completely stop the publication," he said, adding that NXP does not recommend the Mifare Classic for new installations.
The Dutch researchers said the hack allowed cards containing the chip to be cloned, and used the knowledge to travel on London’s transport system for free last summer. At the time, Transport for London said it had noticed the cloned cards in its system and fixed the flaw.
NXP spokesman Alexander Tarzi told IT PRO his firm regrets that the researchers released the details, not least because its customers may need years to make the necessary upgrades. "NXP would like to point out that a broad publication of detailed information to carry-out attacks with limited means is, at this moment in time, contradictory to the scientific goal of prevention and the responsible disclosure of sensitive information."
advertisement
Latest Security Features
Lessons to learn from a year of data breaches
In the year since the HMRC data breach, many more have been made public – here’s a roundup of 11 lessons (we should have) learned.
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
- Chinese web control an Olympic challenge for tech firms
- SOS Bletchley Park
Latest Security Reviews
Boston 3000GP - AMD Shanghai Server
Rating: ![]()
- Fortinet FortiGate-3810A
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
advertisement
Latest News Videos in Security
Video: Q&A with Richard Archdeacon, Symantec
IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?