<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Black Hat 2008: FasTrak toll system completely broken</title>
	<atom:link href="http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sun, 12 Feb 2012 02:22:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Jefferson Manas</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-116378</link>
		<dc:creator><![CDATA[Jefferson Manas]]></dc:creator>
		<pubDate>Sat, 09 Jan 2010 20:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-116378</guid>
		<description><![CDATA[I just wanted to drop you a line and let you know that I really have enjoyed your well-written articles.  I have bookmarked this site and will definitely be checking back for new posts.]]></description>
		<content:encoded><![CDATA[<p>I just wanted to drop you a line and let you know that I really have enjoyed your well-written articles.  I have bookmarked this site and will definitely be checking back for new posts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RAJEEV DHANDA</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-51643</link>
		<dc:creator><![CDATA[RAJEEV DHANDA]]></dc:creator>
		<pubDate>Thu, 20 Nov 2008 09:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-51643</guid>
		<description><![CDATA[PLZ SEND ME THE COMPLETE BLOCK ,CIRCUT DIAGRAM ALONG WITH DATA SHEET AND COMLETE WORKING MANUAL AS SOON AS POSSIBLE 



   THANKS WITH REGARD 
RAJEEV DHANDA
09971336366]]></description>
		<content:encoded><![CDATA[<p>PLZ SEND ME THE COMPLETE BLOCK ,CIRCUT DIAGRAM ALONG WITH DATA SHEET AND COMLETE WORKING MANUAL AS SOON AS POSSIBLE </p>
<p>   THANKS WITH REGARD<br />
RAJEEV DHANDA<br />
09971336366</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naturalorange</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-47842</link>
		<dc:creator><![CDATA[naturalorange]]></dc:creator>
		<pubDate>Mon, 27 Oct 2008 15:02:08 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-47842</guid>
		<description><![CDATA[The ez-pass system in the northeast run by NJ, actually allows you to use it any vehicle that you want to, as long as the tag isn&#039;t put into a vehicle of a different class (i.e. you cant put a tag registered to a small car in a Commercial Truck).

I doubt ez-pass does random checks or sends fines since they explicitly say that you can move it to other vehicles.]]></description>
		<content:encoded><![CDATA[<p>The ez-pass system in the northeast run by NJ, actually allows you to use it any vehicle that you want to, as long as the tag isn&#8217;t put into a vehicle of a different class (i.e. you cant put a tag registered to a small car in a Commercial Truck).</p>
<p>I doubt ez-pass does random checks or sends fines since they explicitly say that you can move it to other vehicles.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shgb</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40208</link>
		<dc:creator><![CDATA[shgb]]></dc:creator>
		<pubDate>Fri, 15 Aug 2008 01:55:31 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40208</guid>
		<description><![CDATA[It is going to take someone with a serious set of balls to over the air program all the fastrak tags to the free account of the CEO of Fastrack before people will take security seriously. At that point we will have their attention....]]></description>
		<content:encoded><![CDATA[<p>It is going to take someone with a serious set of balls to over the air program all the fastrak tags to the free account of the CEO of Fastrack before people will take security seriously. At that point we will have their attention&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terry</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40207</link>
		<dc:creator><![CDATA[Terry]]></dc:creator>
		<pubDate>Mon, 11 Aug 2008 06:17:54 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40207</guid>
		<description><![CDATA[I use this system daily for my commute from my house in Oakland to my job in San Francisco.  About a year ago I missplaced the transponder someplace in my house and went for a week without it.  I figured they would assume my transponder was malfunctioning or something and manually match my plate to my account.  &lt;br&gt;&lt;br&gt;After a week of doing this I decided to never put the transponder back in the car and let the FasTrak agency decide how to deal with it.  I&#039;ve been commuting this way ever since.  They match up my plate to my account with 100% accuracy and I don&#039;t need to worry about the security problems.  &lt;br&gt;&lt;br&gt;I did this because I am not sure who/where my car is queried electronically.  It&#039;s too easy to start gathering information at non-toll locations.]]></description>
		<content:encoded><![CDATA[<p>I use this system daily for my commute from my house in Oakland to my job in San Francisco.  About a year ago I missplaced the transponder someplace in my house and went for a week without it.  I figured they would assume my transponder was malfunctioning or something and manually match my plate to my account.  </p>
<p>After a week of doing this I decided to never put the transponder back in the car and let the FasTrak agency decide how to deal with it.  I&#8217;ve been commuting this way ever since.  They match up my plate to my account with 100% accuracy and I don&#8217;t need to worry about the security problems.  </p>
<p>I did this because I am not sure who/where my car is queried electronically.  It&#8217;s too easy to start gathering information at non-toll locations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Skazz</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40206</link>
		<dc:creator><![CDATA[Skazz]]></dc:creator>
		<pubDate>Sun, 10 Aug 2008 12:45:35 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40206</guid>
		<description><![CDATA[The idea of checking plates against IDs is already in effect.  If you borrow a transponder without adding your car to that account, you (not the account holder) will get hit with a fine (I think the first one is $25).]]></description>
		<content:encoded><![CDATA[<p>The idea of checking plates against IDs is already in effect.  If you borrow a transponder without adding your car to that account, you (not the account holder) will get hit with a fine (I think the first one is $25).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: starfight</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40205</link>
		<dc:creator><![CDATA[starfight]]></dc:creator>
		<pubDate>Sun, 10 Aug 2008 10:06:06 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40205</guid>
		<description><![CDATA[yeah ok but in belgium there is a seperate company for the speedcameras. but before the police can give you a fine they have to get your license plate and name and such. but if the speedcamera-company gives the pictures or license plates to the police isn&#039;t this like a violation on privacy?]]></description>
		<content:encoded><![CDATA[<p>yeah ok but in belgium there is a seperate company for the speedcameras. but before the police can give you a fine they have to get your license plate and name and such. but if the speedcamera-company gives the pictures or license plates to the police isn&#8217;t this like a violation on privacy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40204</link>
		<dc:creator><![CDATA[Greg]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 18:35:14 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40204</guid>
		<description><![CDATA[Holy Crap, my family just recently bought the new Sunpass Mini Transponder (its the equivalent of the FastTrak here in Florida). And once I saw that it was only an RFID chip built inside I knew that the only thing a person would need to do is read the id data, and overwrite it onto another one.&lt;br&gt;Its great to see I was great.]]></description>
		<content:encoded><![CDATA[<p>Holy Crap, my family just recently bought the new Sunpass Mini Transponder (its the equivalent of the FastTrak here in Florida). And once I saw that it was only an RFID chip built inside I knew that the only thing a person would need to do is read the id data, and overwrite it onto another one.<br />Its great to see I was great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yoshi</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40203</link>
		<dc:creator><![CDATA[Yoshi]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 18:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40203</guid>
		<description><![CDATA[It&#039;s insane they make a mistake like this, The developers should have looked to how automotive rf key locks work. The problem is there is insufficient time to do a fancy &quot;key&quot; exchange between radios. The (secure) mobile systems work with a deviated rolling code system. For example when you purchase your RFID tag the tag action_counter will be zero. The exact value of the &quot;action counter&quot; is known by both radios, however the incrementing is done via a complex math formula burned in the ROM, if they didn&#039;t make the mistake of not blowing security fuse, or use OTP non-readable devices. The radios will allow a deviance of +/- 10 counts to make sure a remote can handle some false triggering. The number length is about 32-128 bit depending on model. Microchip makes a IC that handles this. Not impossible to crack, but a heck of a lot better then plaintext flash based serial numbers.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s insane they make a mistake like this, The developers should have looked to how automotive rf key locks work. The problem is there is insufficient time to do a fancy &#8220;key&#8221; exchange between radios. The (secure) mobile systems work with a deviated rolling code system. For example when you purchase your RFID tag the tag action_counter will be zero. The exact value of the &#8220;action counter&#8221; is known by both radios, however the incrementing is done via a complex math formula burned in the ROM, if they didn&#8217;t make the mistake of not blowing security fuse, or use OTP non-readable devices. The radios will allow a deviance of +/- 10 counts to make sure a remote can handle some false triggering. The number length is about 32-128 bit depending on model. Microchip makes a IC that handles this. Not impossible to crack, but a heck of a lot better then plaintext flash based serial numbers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: webmaren</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40202</link>
		<dc:creator><![CDATA[webmaren]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 14:23:15 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40202</guid>
		<description><![CDATA[Still could be used to damage the system by RFID-cloning the tags and switching them around a bit.&lt;br&gt;&lt;br&gt;Would put any RFID-based tracking system down the tubes.]]></description>
		<content:encoded><![CDATA[<p>Still could be used to damage the system by RFID-cloning the tags and switching them around a bit.</p>
<p>Would put any RFID-based tracking system down the tubes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CarlosMC</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40201</link>
		<dc:creator><![CDATA[CarlosMC]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 06:26:41 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40201</guid>
		<description><![CDATA[Here in Portugal we have Via Verde (Green Lane), since 1991 (which was bought from the norwegians, although this is not publicised...), and it has since then expanded into parking lots and pump stations. According to them it follows CEN/TC278 standards, still, I wonder if it&#039;s any safer...&lt;br&gt;&lt;br&gt;Electronic license plates are going to become law - they&#039;ll read insurance and safety inspections data  and allow toll payments as well, but won&#039;t allow geo location or speed logging.]]></description>
		<content:encoded><![CDATA[<p>Here in Portugal we have Via Verde (Green Lane), since 1991 (which was bought from the norwegians, although this is not publicised&#8230;), and it has since then expanded into parking lots and pump stations. According to them it follows CEN/TC278 standards, still, I wonder if it&#8217;s any safer&#8230;</p>
<p>Electronic license plates are going to become law &#8211; they&#8217;ll read insurance and safety inspections data  and allow toll payments as well, but won&#8217;t allow geo location or speed logging.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Vangerov</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40200</link>
		<dc:creator><![CDATA[David Vangerov]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 03:00:41 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40200</guid>
		<description><![CDATA[#22: We already get a monthly statement that shows which transponder was used, when it was used, and the toll lane that it went through. In addition, there&#039;s a website that you can login to to get up to date info on transponder use. &lt;br&gt;&lt;br&gt;And a slight correction to the article: You do not purchase the transponder for ~$26. The FasTrak folks give it to you when you sign up and pre-pay your tolls. If you need more than a certain number of transponders (like for a fleet for a delivery company), they do require a deposit in addition to pre-paying the tolls. When your pre-paid FasTrak account dips below a certain threshold, that is when your credit/debit card is accessed to replenish the account.]]></description>
		<content:encoded><![CDATA[<p>#22: We already get a monthly statement that shows which transponder was used, when it was used, and the toll lane that it went through. In addition, there&#8217;s a website that you can login to to get up to date info on transponder use. </p>
<p>And a slight correction to the article: You do not purchase the transponder for ~$26. The FasTrak folks give it to you when you sign up and pre-pay your tolls. If you need more than a certain number of transponders (like for a fleet for a delivery company), they do require a deposit in addition to pre-paying the tolls. When your pre-paid FasTrak account dips below a certain threshold, that is when your credit/debit card is accessed to replenish the account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Malinowski</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40199</link>
		<dc:creator><![CDATA[Stephen Malinowski]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 02:00:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40199</guid>
		<description><![CDATA[@8, a power switch or &#039;tap to tag&#039; button both have the problem that if you forget, (unlike @11 in ma) you get fined :-(&lt;br&gt;&lt;br&gt;What I&#039;d like is the option of having fastrak send me an email whenever my tag gets charged a toll.  I could then report a spurious use.  The ultimate would be: I get the email when I&#039;m at home, report the violation immediately, they get the picture of the perp&#039;s car, and pick him up when gets off the bridge.  Would fastrak need legislative action to add something like this?]]></description>
		<content:encoded><![CDATA[<p>@8, a power switch or &#8216;tap to tag&#8217; button both have the problem that if you forget, (unlike @11 in ma) you get fined :-(</p>
<p>What I&#8217;d like is the option of having fastrak send me an email whenever my tag gets charged a toll.  I could then report a spurious use.  The ultimate would be: I get the email when I&#8217;m at home, report the violation immediately, they get the picture of the perp&#8217;s car, and pick him up when gets off the bridge.  Would fastrak need legislative action to add something like this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dj caliban</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40198</link>
		<dc:creator><![CDATA[dj caliban]]></dc:creator>
		<pubDate>Fri, 08 Aug 2008 01:57:18 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40198</guid>
		<description><![CDATA[&lt;br&gt;i don&#039;t even keep my transponders in the car.  the system photographs my plates each time i roll through - the BACK plate - and bills my account.]]></description>
		<content:encoded><![CDATA[<p>i don&#8217;t even keep my transponders in the car.  the system photographs my plates each time i roll through &#8211; the BACK plate &#8211; and bills my account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Bennett</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/comment-page-1/#comment-40197</link>
		<dc:creator><![CDATA[Matt Bennett]]></dc:creator>
		<pubDate>Thu, 07 Aug 2008 23:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-fastrak-toll-system-completely-broken/#comment-40197</guid>
		<description><![CDATA[#7, Don&#039;t count on an anti-static bag to shield your tag from being read- they&#039;re just meant to dissipate static, not block RF.&lt;br&gt;&lt;br&gt;Here in Austin, TX, they take a picture of your front and rear plate for every vehicle that passes through the tag lanes and the pay with change lanes, no matter if you have a tag or not.  They use a high speed flash which I assume helps prevent a blurry picture of a car going 70+ mph (the speed limit on the toll roads here is 70).&lt;br&gt;&lt;br&gt;I guess we&#039;ve gotten to the point where digital storage of the images is cheap enough that they should keep everything.  Heck, I think police cars should be fully monitored, in addition to the cameras that make such good fodder for TV clip shows.]]></description>
		<content:encoded><![CDATA[<p>#7, Don&#8217;t count on an anti-static bag to shield your tag from being read- they&#8217;re just meant to dissipate static, not block RF.</p>
<p>Here in Austin, TX, they take a picture of your front and rear plate for every vehicle that passes through the tag lanes and the pay with change lanes, no matter if you have a tag or not.  They use a high speed flash which I assume helps prevent a blurry picture of a car going 70+ mph (the speed limit on the toll roads here is 70).</p>
<p>I guess we&#8217;ve gotten to the point where digital storage of the images is cheap enough that they should keep everything.  Heck, I think police cars should be fully monitored, in addition to the cameras that make such good fodder for TV clip shows.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

