Myki gets upgrade as vulnerability emerges

The Victorian Transport Ticketing Authority (TTA) is transitioning to newer myki smart cards following the discontinuation of the current version and the revelation that the cards are vulnerable to modification.

(Timetable TripUp image by MrPbps, CC2.0)

This week, a group of German researchers released a paper describing how the Mifare DESFire MF3ICD40 cards that are used in the myki ticketing system could be cloned, and the information stored on them accessed and/or modified, potentially allowing for account balances to be faked.

The cards are susceptible to a form of differential power analysis (DPA), where attackers observe the power consumption or electromagnetic radiation emitted by the cards and by analysing variances during cryptographic processes, which can extract stored information, such as its secret keys. As the attack itself is non-invasive and won't damage the cards, it is very difficult to determine whether an attack has taken place.

NXP, a subsidiary of Panasonic that makes the cards, said in a statement that it was aware of the vulnerability. The company stated that the card would be discontinued at the end of this year, and customers should upgrade to its DESFire EV1 series, which aren't vulnerable to the attack.

Stephen Wilson, managing director of digital identity research company Lockstep, said the vulnerability would have been an easy fix during the design phase.

"This type of side channel attack has been known for over a decade. It is easily circumvented in the silicon, although at a cost of several tens of cents. For a transit smart card, operators are keen to save cents per card, so until an attack like this is proven, DPA protection and other advanced security measures are often left out on economic grounds," he said.

Although this could have been a cost-cutting method, the TTA appears to have avoided cutting corners with respect to card security. There are four security measures that can be installed for the cards relating to key diversification, fraud detection, card blocking and card information binding. The TTA elected to include all four, pointing the issue further up the chain to the manufacturer.

Despite the cards being theoretically vulnerable, however, there isn't a need to replace the cards as a matter of urgency. NXP stated that even if the lab equipment required to pull off the vulnerability is obtained, it could still take hours to days for the analysis of a card to be completed.

"End consumers will hardly be affected: the theft of a wallet can pose a greater threat to personal belongings than the attack on a public transport card, which also needs to be stolen in order to be successfully attacked," the company said.

Wilson agreed.

"For a transit smart card, even a yearly pass worth hundreds of dollars, you would question the criminal return on investment of spending $3000 on equipment to clone one card," he said.

TTA CEO Bernie Carolan was also quick to point out the limited extent to what could be gleaned from the cards.

"No personal information is stored on a myki card. Only the card balance and the past 10 transactions are held on the card. If one of the 10 previous transactions was a top up, no banking details are recorded on the myki card, just the amount added."

Additionally, those that had access to the right equipment and sought to artificially inflate their card balance would see limited returns. NXP stated that the ability for operators such as TTA to blacklist cards will make it hard to pull off cloning or modifying cards for commercial purposes.

The TTA said it did not have any plans to recall any of its 1.1 million cards that are currently in the wild and believed that myki customers needn't worry about the security of their cards.

Nevertheless, it is taking action to change them.

"The TTA, through its contractor Kamco, has already begun developing a migration strategy to a newer version of [card], the Mifare DESFire EV1," Carolan said.

Talkback

Seriously, they are continuing with Myki after all the horrendous failures to date AND now a new one that requires all the cards to be replaced?

IF this system ever completes roll out, every TTA manager on the project should be fired and KAMCO banned from any future government projects.

There is nothing wrong with the existing MetCard system. It's proven, operational, and far less complex than this Myki debacle.

Scott WScott W October 14th, 2011
Report offensive content Reply (0) (-2)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

"take up of the highest plan was again higher in April, making up 50 per cent of all services activated in April"

33 minutes ago by Abel Adamski on NBN users opt for 100Mbps

What has not been considered which may well be the case, is the key attribute of the FTTP. Upload capability. 82% chose an upload capacit...

38 minutes ago by Abel Adamski on NBN users opt for 100Mbps

"@ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/PiR0zeF1 #infosec #hack #cybersecurity"

Cool: NZ will host part of Square Km Array http://t.co/a2mz3DC5. Sad: @smh couldn't bring themselves to acknowledge it http://t.co/l90oLuYp

Build your own smartphone stand http://t.co/I0avWsRO

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/vA11Otks

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/FqSe1Uju

SKA bid ends in three-way tie AU/NZ/ZA http://t.co/aGw6dndH < interesting outcome

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

Is #PR dying at the hands of #SocialMedia? Check out how #UnitedAirlines suffered a Social PR hiccup in 2008 http://t.co/OVpYX8Uv

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

2 hours ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

3 hours ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

4 hours ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

4 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

4 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

4 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

5 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

5 hours ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

5 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

6 hours ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

6 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

6 hours ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

6 hours ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

6 hours ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

6 hours ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

6 hours ago by mathew42 on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

The rural Silicon Valley http://t.co/vqV6bl5i

Build your own smartphone stand http://t.co/IY6VxA7n

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar