<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; chris tarnovsky</title>
	<atom:link href="http://hackaday.com/tag/chris-tarnovsky/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:27:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; chris tarnovsky</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Black Hat 2009: Parking meter hacking</title>
		<link>http://hackaday.com/2009/07/30/black-hat-2009-parking-meter-hacking/</link>
		<comments>http://hackaday.com/2009/07/30/black-hat-2009-parking-meter-hacking/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 22:53:12 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[transportation hacks]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[black hat 2009]]></category>
		<category><![CDATA[chris tarnovsky]]></category>
		<category><![CDATA[jacob appelbaum]]></category>
		<category><![CDATA[joe grand]]></category>
		<category><![CDATA[parking]]></category>
		<category><![CDATA[parking meters]]></category>
		<category><![CDATA[sf]]></category>
		<category><![CDATA[sfmta]]></category>
		<category><![CDATA[silver card]]></category>
		<category><![CDATA[smart card]]></category>
		<category><![CDATA[transportation]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=13070</guid>
		<description><![CDATA[For day two of Black Hat, we sat in on on [Joe Grand], [Jacob Appelbaum], and [Chris Tarnovsky]&#8216;s study of the electronic parking meter industry. They decided to study parking meters because they are available everywhere, but rarely considered from a security perspective. They focused on the San Francisco&#8217;s MTA implementation of electronic smart card [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=13070&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-13072" title="meter" src="http://hackadaycom.files.wordpress.com/2009/07/meter.png" alt="meter" width="450" height="244" /></p>
<p>For day two of Black Hat, we sat in on on [Joe Grand], [Jacob Appelbaum], and [Chris Tarnovsky]&#8216;s study of the electronic parking meter industry. They decided to study parking meters because they are available everywhere, but rarely considered from a security perspective.</p>
<p><span id="more-13070"></span></p>
<p>They focused on the San Francisco&#8217;s MTA implementation of electronic smart card meters. To start they purchased several meters on eBay just to see the different styles. SF MTA lets you purchase disposable payment cards with values of $20 or $50. They decided to sniff the interaction between the meter and the smartcard using a shim. With that first capture they were able to easily replay the transaction. This didn&#8217;t require a smartcard reader, just an oscilloscope. They then took the attack a little further.</p>
<p>[Joe] built a smartcard emulator using a PIC16F648A. They used it to capture multiple transactions and then decoded the interactions by hand. Luckily, the card was using the <a title="ISO/IEC 7816 - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/ISO/IEC_7816">IEC 7816</a> standard so they had some insight into the protocol. They found that the card has a stored maximum value and only writes how many times the value has been decremented. As a proof of concept, they change the maximum value, which you can see on the meter above. They could also have just changed the acknowledgement so that the card never writes any deductions.</p>
<p>The PIC16F648A was a good choice because it&#8217;s available in a smart card format called a &#8216;<a title="Interesting Devices Ltd - July 30, 2009" href="http://tinyurl.com/mqphcj">silver card</a>&#8216;. You can find the emulator code and slides from the talk <a title="Grand Idea Studio  » Archive   » Smart Parking Meters" href="http://www.grandideastudio.com/portfolio/smart-parking-meters/">on [Joe]&#8216;s site about the project</a>.</p>
<br />Posted in cons, security hacks, transportation hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/13070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/13070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/13070/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=13070&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/07/30/black-hat-2009-parking-meter-hacking/feed/</wfw:commentRss>
		<slash:comments>45</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/07/meter.png" medium="image">
			<media:title type="html">meter</media:title>
		</media:content>
	</item>
		<item>
		<title>PSP 3000 hacked</title>
		<link>http://hackaday.com/2008/11/19/psp-3000-hacked/</link>
		<comments>http://hackaday.com/2008/11/19/psp-3000-hacked/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 03:30:54 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[playstation hacks]]></category>
		<category><![CDATA[psp hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[chris tarnovsky]]></category>
		<category><![CDATA[christarnovsky]]></category>
		<category><![CDATA[datel]]></category>
		<category><![CDATA[homebrew]]></category>
		<category><![CDATA[lite blue tool]]></category>
		<category><![CDATA[maxconsole]]></category>
		<category><![CDATA[psp]]></category>
		<category><![CDATA[psp 3000]]></category>
		<category><![CDATA[psp brite]]></category>
		<category><![CDATA[psp hacking]]></category>
		<category><![CDATA[psp3000]]></category>
		<category><![CDATA[silicon]]></category>
		<category><![CDATA[silicon hacking]]></category>
		<category><![CDATA[sony]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=6083</guid>
		<description><![CDATA[Peripheral manufacturer Datel has been hard at work attempting to crack the PSP 3000 since its release. They&#8217;ve developed the Lite Blue Tool battery to force the PSP into service mode so hackers can run any arbitrary code they want. According to MaxConsole, Datel performed a silicon level investigation of the PSP&#8217;s chips to determine [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=6083&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="psp firmware" src="http://hackadaycom.files.wordpress.com/2008/07/sony_psp_firmwareupdate.jpg?w=450&#038;h=303&#038;h=303" alt="" width="450" height="303" /></p>
<p>Peripheral manufacturer Datel has been hard at work attempting to crack the <a href="http://www.mahalo.com/PSP_Hacks">PSP 3000</a> since its release. They&#8217;ve developed the Lite Blue Tool battery to <a title="PSP 3000 hacked - Datel gives the green light to PSP 3000 service mode  - MaxConsole Forums" href="http://forums.maxconsole.net/showthread.php?t=132171">force the PSP into service mode</a> so hackers can run any arbitrary code they want. According to MaxConsole, Datel performed a silicon level investigation of the PSP&#8217;s chips to determine how to break into service mode. This means they decapsulated the the chips and reverse engineered any cryptographic protections. We&#8217;d love to hear exactly what chips were being used since some are <a title="mifare  - Hack a Day" href="http://hackaday.com/tag/mifare/">fundamentally flawed</a>.</p>
<p><a href="http://hackaday.com/tag/silicon/">Silicon hacking</a> has always been a favorite topic of ours and we suggest you check out [Chris Tarnovsky]&#8216;s decapsulation technique to <a title="Silicon hacking  - Hack a Day" href="http://hackaday.com/2008/05/31/silicon-hacking/">learn more about it</a>.</p>
<br />Posted in news, playstation hacks, psp hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/6083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/6083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/6083/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=6083&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/11/19/psp-3000-hacked/feed/</wfw:commentRss>
		<slash:comments>63</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/07/sony_psp_firmwareupdate.jpg?w=450&#38;h=303" medium="image">
			<media:title type="html">psp firmware</media:title>
		</media:content>
	</item>
	</channel>
</rss>
