A group of scientists from Radbound University in the Netherlands has discovered that Oyster cards can be cloned by connecting a Mifare card reader to a computer.
After successfully cloning the card, they travelled around the London uynderground using the cloned card in order to demonstrate their points.
Oyster uses a basic version of the Mifare system, 'Mifare Classic'. Secure versions of Mifare are available, but TfL chose an unsecured version in order to reduce costs. ATOC have refused to embrase Oyster due to the lack of ITSO compliance which includes the lack of security. ITSO is the standard for smartcards specified by the DfT which TfL chose to ignore.
The unsecure nature of the system has been known by industry insiders since it's inception, but only recently has it been publicly announced.
Oyster cards hold the data themselves, rather than reading from a central database. This means that it is possible to clone cards. Some IT experts even claim they could easily 'top up' legitimate cards.
TfL responded by announcing that they can detect fraudulent use and that the most anyone could get is a single day's travel, however many in the industry are sceptical about this claim. A TfL spokesman warned "Using a fraudulent card for free travel is subject to prosecution." Whether TfL bosses will face any disciplinary action for not complying with Government standards remains to be seen.
Some links for information about the flaw:-
http://www.itpro.co.uk/603912/oyster-cards-at-risk-from-cloning
http://www.theregister.co.uk/2008/06/23/dutch_clone_oyster_card/
http://www.ru.nl/english/general/radboud_university/vm/security_flaw_in/ (Video)
After successfully cloning the card, they travelled around the London uynderground using the cloned card in order to demonstrate their points.
Oyster uses a basic version of the Mifare system, 'Mifare Classic'. Secure versions of Mifare are available, but TfL chose an unsecured version in order to reduce costs. ATOC have refused to embrase Oyster due to the lack of ITSO compliance which includes the lack of security. ITSO is the standard for smartcards specified by the DfT which TfL chose to ignore.
The unsecure nature of the system has been known by industry insiders since it's inception, but only recently has it been publicly announced.
Oyster cards hold the data themselves, rather than reading from a central database. This means that it is possible to clone cards. Some IT experts even claim they could easily 'top up' legitimate cards.
TfL responded by announcing that they can detect fraudulent use and that the most anyone could get is a single day's travel, however many in the industry are sceptical about this claim. A TfL spokesman warned "Using a fraudulent card for free travel is subject to prosecution." Whether TfL bosses will face any disciplinary action for not complying with Government standards remains to be seen.
Some links for information about the flaw:-
http://www.itpro.co.uk/603912/oyster-cards-at-risk-from-cloning
http://www.theregister.co.uk/2008/06/23/dutch_clone_oyster_card/
http://www.ru.nl/english/general/radboud_university/vm/security_flaw_in/ (Video)