• Home
  • Videos
  • Contact
  • Subscribe to Newsletter
  • Subscribe to Re:ID Magazine
  • Twitter
  • RSS
SecureIDNews
  • Markets »
  • Corporate
  • Education
  • Financial
  • Government
  • Health
  • Transit
  • Technologies »
  • Biometrics
  • Contactless
  • Digital ID
  • NFC
  • RFID
  • Smart Cards

Time: 0 :0

You are here:

  • Home
  • UltraReset: the NFC-stumping app that lets you ride for free

UltraReset: the NFC-stumping app that lets you ride for free

25 September, 2012

By: Andrew Hudson

category: NFC, Transit

0

An NFC mobile app exploiting a transit system loophole has been created that enables users to ride trains for free.

Gizmodo reports that Corey Benninger and Max Sobell of the Intrepidus Group have developed the UltraReset app, which preys on vulnerabilities in a number of public transit systems including the New Jersey Path and San Francisco Muni trains where the app proved its effectiveness.

The app works on any NFC-enabled Android device operating 2.3 or later. By using a train card with zero rides, the app refills the account with rides repeatedly at no cost to the user.

The flaw doesn’t lie with NFC, rather it resides within the transit authority system, which did not enact security measures to effectively lock down the read/write permissions. The app has thus far only been tested in New Jersey and San Francisco, but if the loophole is consistent Boston, Seattle, Salt Lake City Chicago, and Philadelphia could be prone to exploitation as well.

Benninger and Sobell recently presented their creation at a security conference in Amsterdam. Despite being warned back in December of 2011, and the recent wave of recent attention and coverage, authorities are yet to close the loophole.

The app— for rather obvious reasons— is not available to the public, but for the time being those tech-savvy hackers will continue to enjoy the free ride.


Tags: NFC, Transit

recommend to friends

Related News

Future of NFC greater than just payments

20 May, 2013

OSPT Alliance releases CIPURSE open security standards for NFC phones

04 May, 2013

Spring 2013 Regarding ID Magazine available via interactive PDF viewer

29 April, 2013

Frost & Sullivan: The three-headed monster of the smart card industry

29 April, 2013

SecureIDNews
BACK TO TOP

re:ID Magazine



Read current issue online

CR80News Magazine



Read current issue online

Questions, Tips, & Comments

Name:

Email:

Message:

Twitter feed

Follow on Twitter
  • About
  • Advertise
  • Store
  • re:ID
  • Subscribe
  • Twitter
  • RSS

© 2013-2014 AVISIAN Publishing. All rights reserved. info@avisian.com

Close

Enter the site

Login

Password

Remember me

Forgot password?

Login
Skip to toolbar
    • WordPress.org
    • Documentation
    • Support Forums
    • Feedback
Log Out