Latest news
A security flaw in most Mifare NFC contactless cards can easily be misused by hackers to modify the contents of the cards and get free rides on at least two U.S. transit systems, two researchers from Intrepidus Group have revealed to the crowd gathered at this years' EUSecWest.Researchers Corey Benninger and Max Sobell discovered the flaw on the Ultralight cards used by San Francisco' Muni rail and bus system and New York City's Path rail system, and have since then found out that there are other U.S. NFC transit systems that use the same type of card and are possibly susceptible to this type of exploit.
The flaw can currently be exploited only on the disposable paper tickets that are set to be used for a predetermined number of rides.
By using a NFC-enabled phone and a specially developed Android app that allows them to copy the data from new tickets, then copy that data back on "expired" tickets thus making them "new" again, the researchers have developed a simple way for hackers to get as many free rides as they want.
Fortunately for the transit systems mentioned by the researchers, the app is not available for download. Intrepidus Group has only released an app that can scan the data from this type of tickets and tell users if the transit system issuing them is vulnerable to the exploit.
In the meantime, they have also informed the operators of the two aforementioned vulnerable transit systems about the flaw and instructed them on how to fix it.
"We know a number of cities are looking to roll out contactless technology and hope we can bring light to this issue so that it is implemented correctly in the future," the researchers say.
"One of the items we also raised in our talk is that full card emulation on smartphones is likely to happen soon. When this does, it could cause a number of NFC based access control systems to be re-evaluated."



Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





