<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; mbta</title>
	<atom:link href="http://hackaday.com/tag/mbta/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:18:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; mbta</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>MBTA drops lawsuit against MIT subway hackers</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/</link>
		<comments>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 16:00:24 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[transportation hacks]]></category>
		<category><![CDATA[charliecard]]></category>
		<category><![CDATA[eff]]></category>
		<category><![CDATA[fpga]]></category>
		<category><![CDATA[gnu radio]]></category>
		<category><![CDATA[mbta]]></category>
		<category><![CDATA[mifare]]></category>
		<category><![CDATA[mifare classic]]></category>
		<category><![CDATA[mit]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[rfid]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[subway]]></category>
		<category><![CDATA[subway hackers]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7166</guid>
		<description><![CDATA[The Massachusetts Bay Transit Authority (MBTA) has dropped its federal case against three MIT researchers, &#8220;the subway hackers&#8221;. This happened in October and now the EFF brings news that the students will be working with the MBTA to improve their system. The overall goal is to raise security while keeping expenses minimal. This whole mess [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7166&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackadaycom.files.wordpress.com/2008/08/had_tid.jpg?w=450&#038;h=276" border="0" alt="" hspace="4" vspace="4" width="450" height="276" /></p>
<p>The Massachusetts Bay Transit Authority (MBTA) has dropped its federal case against three MIT researchers, &#8220;the subway hackers&#8221;. This happened in October and now the EFF brings news that the students will be <a title="MBTA, MIT Students Join to Discuss Improvements to Automated Fare Collection System | Electronic Frontier Foundation" href="http://www.eff.org/press/archives/2008/12/22">working with the MBTA to improve their system</a>. The overall goal is to raise security while keeping expenses minimal.</p>
<p>This whole mess started in August when a gag order was issued against the <a title="MIT Boston transit presentation gagged  - Hack a Day" href="http://hackaday.com/2008/08/09/defcon-16-mit-boston-transit-presentation-gagged/">students&#8217; presentation at Defcon</a>. It&#8217;s a shame no one ever saw it because it covers a lot of interesting ground. A <a href="http://www-tech.mit.edu/V128/N30/subway/Defcon_Presentation.pdf">PDF of the banned slides</a> is still online. They performed several attacks against both the subway&#8217;s fare system and physical security. Our favorites by far were using <a title="GNU Radio - GNU FSF Project" href="http://www.gnu.org/software/gnuradio/">GNU Radio</a> to sniff the RFID card&#8217;s transaction and bruteforcing <a title="24C3 Mifare crypto1 RFID completely broken  - Hack a Day" href="http://hackaday.com/2008/01/01/24c3-mifare-crypto1-rfid-completely-broken/">Mifare Classic</a> with an FPGA.</p>
<br />Posted in news, security hacks, transportation hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7166&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/had_tid.jpg" medium="image" />
	</item>
		<item>
		<title>Subway hacker speaks</title>
		<link>http://hackaday.com/2008/08/24/subway-hacker-speaks/</link>
		<comments>http://hackaday.com/2008/08/24/subway-hacker-speaks/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 04:30:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[checksum]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[defcon16]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[mbta]]></category>
		<category><![CDATA[mifare]]></category>
		<category><![CDATA[mifareclassic]]></category>
		<category><![CDATA[nxp]]></category>
		<category><![CDATA[popularmechanics]]></category>
		<category><![CDATA[rfid]]></category>
		<category><![CDATA[subway]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/24/subway-hacker-speaks/</guid>
		<description><![CDATA[Popular Mechanics has an interview with [Zach Anderson], one of the MIT hackers that was temporarily gagged by the MBTA. The interview is essentially a timeline of the events that led up to the Defcon talk cancellation. [Zach] pointed out a great article by The Tech that covers the vulnerabilities. The mag stripe cards can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2493&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img hspace="4" height="276" width="450" vspace="4" border="0" src="http://hackadaycom.files.wordpress.com/2008/08/had_tid.jpg?w=450&#038;h=276"  alt="" /><br />Popular Mechanics <a href="http://www.popularmechanics.com/technology/industry/4278892.html?page=1">has an interview with [Zach Anderson]</a>, one of the MIT hackers that was temporarily gagged by the MBTA. The interview is essentially a timeline of the events that led up to the <a href="http://www.hackaday.com/2008/08/09/defcon-16-mit-boston-transit-presentation-gagged/">Defcon talk cancellation</a>. [Zach] pointed out a great article by The Tech that <a href="http://www-tech.mit.edu/V128/N30/subwayvulnerabilities.html">covers the vulnerabilities</a>. The mag stripe cards can be easily cloned. The students we&#8217;re also able to increase the value of the card by brute forcing the checksum. There are only 64 possible checksum values, so they made a card for each one. It&#8217;s not graceful, but it works. The card values aren&#8217;t encrypted and there isn&#8217;t an auditing system to check what values should be on the card either. The RFID cards use Mifare classic, which <a href="http://www.hackaday.com/2008/01/01/24c3-mifare-crypto1-rfid-completely-broken/">we know is broken</a>. It was NXP, Mifare&#8217;s manufacturer, that tipped off the MBTA on the actual presentation.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2493/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2493/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2493/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2493/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2493/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2493&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/08/24/subway-hacker-speaks/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/had_tid.jpg" medium="image" />
	</item>
	</channel>
</rss>
