How teens hacked Boston Subway

Поделиться
HTML-код
  • Опубликовано: 22 окт 2024

Комментарии • 331

  • @OS.CUCCOS
    @OS.CUCCOS 6 месяцев назад +2141

    Honestly for developers it is just the best advice to never trust the users of your products and don't be dumb and store an id in card instead of all the details

    • @hockdudu
      @hockdudu 6 месяцев назад +86

      And sign it, otherwise they could try and spoof another ID.

    • @reyariass
      @reyariass 6 месяцев назад +9

      @@hockduduCould you explain what you mean by sign it?

    • @valkyr7431
      @valkyr7431 6 месяцев назад

      ​@@reyariassLook up "Code Signing" on Wikipedia, in short it's a way to tell if code is authentic or modified

    • @BenjaminVestergaard
      @BenjaminVestergaard 6 месяцев назад

      ​@@reyariass make a signature using a private key, everyone knowing the public key can verify it.

    • @BenjaminVestergaard
      @BenjaminVestergaard 6 месяцев назад +65

      The reason to store ID and value on a card would be so that it'd still work if the network behind it would be offline.
      Anyway, if you use 2-3 private/public key pairs and a hard coded salt, it wouldn't be difficult to catch compromised/reprogrammed cards. While still being useful while the network is down.

  • @neoxyte
    @neoxyte 6 месяцев назад +1317

    The fact that the money loaded is not done on the backend(like nyc MetroCards) is just straight up incompetence.

    • @smalls5001
      @smalls5001 6 месяцев назад +7

      frr

    • @hatter1290
      @hatter1290 6 месяцев назад +27

      I agree. But what else can you expect from a government agency?

    • @ZanHecht
      @ZanHecht 6 месяцев назад +47

      The current system was introduced in 2006, when having a reliable low-latency internet connection on every bus and trolly just wasn't feasible.
      The new system will be identical to NYC's, the company behind it just put off working on Boston's system until they were done in New York.

    • @SIETETIZ
      @SIETETIZ 6 месяцев назад

      That's because there a little bit of decency around here

    • @anotherguy9402
      @anotherguy9402 6 месяцев назад +7

      ​@@SIETETIZ is the decency before or after they stab their victims 😂

  • @GlassFamFishing
    @GlassFamFishing 6 месяцев назад +406

    These kids presented this at defcon in 2023, it was a pretty good presentation.

  • @WOMFT
    @WOMFT 7 месяцев назад +1057

    Just a simple RFID replication 😂, I used to do that to get access to a workshop at my job

    • @2v2
      @2v2 7 месяцев назад

      That is not at all what it is, go watch their blackhat talk it was a cryptography algorithm that was for some reason proprietary and they managed to reverse engineer it. It was very complex...

    • @anondimwit
      @anondimwit 7 месяцев назад +4

      Ik right

    • @thearchitect9757
      @thearchitect9757 7 месяцев назад +114

      They didn't just clone it, the reversed the data on the cards and see what bits need to be changed and stuff to get a certain "role", amount of credits,... Check their defcon presentation

    • @anondimwit
      @anondimwit 7 месяцев назад

      @@thearchitect9757easy

    • @aarovaris
      @aarovaris 6 месяцев назад +35

      In the presentation they actually revealed there were cloning counter-measures in the system. Highly recommend the presentation, it was a fun watch.

  • @SuperPupperDoggo
    @SuperPupperDoggo 6 месяцев назад +284

    wait until the mbta devs find out about just having a database and only storing an id on the card

    • @HoloScope
      @HoloScope 6 месяцев назад +16

      Hard to do that when you’re ripping the government off 100x and only spending 5k for software development

    • @RKingis
      @RKingis 6 месяцев назад +5

      Pretty sure they're storing the cash value on the cards. And without any kind of checksum.

    • @king_james_official
      @king_james_official 6 месяцев назад +2

      @@HoloScopepeople ripping off the government has got to be my favorite type of hacking stories lol

  • @Scrappp_
    @Scrappp_ 5 месяцев назад +16

    MIT students did the original hack and I'm pretty sure they were sued. Even after they gave up all their information to the MBTA

  • @morg4899
    @morg4899 5 месяцев назад +28

    what grand mind thought storing the balance locally on the card was a good idea in the first place?

    • @romangeneral23
      @romangeneral23 5 месяцев назад +15

      The lowest bidder company that was hired.

  • @andreasarnoalthofsobottka2928
    @andreasarnoalthofsobottka2928 5 месяцев назад +5

    To solve this "problem" Spain made local public transport free of charge.

  • @jasonxhx7854
    @jasonxhx7854 6 месяцев назад +28

    "How did they do it? They figured it out."

  • @Daniel-o7s1f
    @Daniel-o7s1f 6 месяцев назад +10

    Works the same in The Netherlands, lots of people go in public transport for free, just dont put to much on it.

    • @Jooeepp
      @Jooeepp 5 месяцев назад +1

      No, it doesn't anymore. Only the old generation of cards had that issue. Lots of free rides either way tho

  • @ObservationofLimits
    @ObservationofLimits 6 месяцев назад +12

    "Leaked presentation"
    Bruh the presentation wasn't leaked, it was posted publicly

  • @WoutervanderMeulen
    @WoutervanderMeulen 5 месяцев назад +3

    This is probably the same RFID issue we had in the Netherlands 10+ years ago. People were also just copying the transit card and putting money on it.

  • @BINX-RR
    @BINX-RR 5 месяцев назад +2

    I saw the defcon breakdown of this hack, it’s well worth the watch, even if you know nothing about this topic they explain it very eloquently in a way anyone can comprehend.

  • @UKsystems
    @UKsystems 7 месяцев назад +90

    you can also duplicate a staff card when it changes

    • @popupdestroyer
      @popupdestroyer 6 месяцев назад +11

      It's hard to get a staff card to duplicate it. Also there's the danger the staff member could be identified and get fired.
      This students reverse engeneerd the card data and modified it. That's the safe way to responsible disclosure.

    • @Poggershditne-ff4sr
      @Poggershditne-ff4sr 6 месяцев назад

      @@popupdestroyerthere are crackers the size of the very microchip inside of them that can find them out…

    • @UKsystems
      @UKsystems 6 месяцев назад

      i was just pointing out how insecure some smart cards are @@popupdestroyer

    • @UKsystems
      @UKsystems 6 месяцев назад

      also they can be read from around a meter away when walking past@@popupdestroyer

    • @campandcook3118
      @campandcook3118 6 месяцев назад +7

      ​@@popupdestroyer its an RFID card, with a good directional antenna and an LNA, you only need to stand close to anyone with a card in its pocket.

  • @makesomedrinks
    @makesomedrinks 6 месяцев назад +37

    "By the way, they haven't fixed it yet. "
    The end

  • @eskewroberts7663
    @eskewroberts7663 6 месяцев назад +2

    I swear, every few months I hear something else about the flaws of the Boston subway

  • @johndododoe1411
    @johndododoe1411 6 месяцев назад +17

    This is the bad NXP MiFare card system, mass peoduced and sold to travel systems worldwide, years after being proven insecure . Ticket system operators can't afford upgrading everything to better chips, forcing them to keep using and buying these bad chips .

    • @user-28qhfk65
      @user-28qhfk65 6 месяцев назад +1

      In my country, we went from a commuter card to just using paper tickets with QR code. I dont know if it is related to this hack but its weird that they went backward. So.. maybe?
      Scanning the qr code will get you an encrypted code (idk I'm not a programmer), the commuter code name, the location its departing, the location its going, date, date.

    • @danielmorton9956
      @danielmorton9956 6 месяцев назад +1

      ​@user-28qhfk65 No, it's not. The QR code is created on an external server and the code just has rider info if valid, which corresponds to the external list. Here they were loading the info onto the card.

    • @dglcomputers1498
      @dglcomputers1498 6 месяцев назад

      Though that's what was done on London Transport, the old Mifare system was replaced with a newer system and the old cards no longer work.

    • @ethanlarge3572
      @ethanlarge3572 5 месяцев назад

      @@danielmorton9956Did you actually read what he said? His country switched to using paper tickets with QR codes and he was wondering if the fact they switched had something to do with the fact the non-paper cards could be hacked.

  • @sukmaadhiw9033
    @sukmaadhiw9033 7 месяцев назад +48

    It is so easy to replicate or inject all sorts of data into an RFID Card, i'm surprised that the identification/verification information is contained within the card itself.
    They should have just take its UID to do verification process on their backend service.
    Would be cool to try out this hack and definitely not exploit it 😂

    • @casparjaeqx8328
      @casparjaeqx8328 6 месяцев назад +5

      That is how they do it where I live

  • @rocketappliantist4969
    @rocketappliantist4969 6 месяцев назад +1

    They still use the paper cards, they're just disposable single use/2 way/one day cards that can't be reloaded. They've had the reloadable charlie cards for years.

  • @Ironbattlemace
    @Ironbattlemace 4 месяца назад

    Here in Finland we have a mobile ticket app that is a carbon copy of the original ticket app, you can buy what ticket you ever want and ride on trams and busses, but if ticket checker comes, you are screwed.

  • @WaivexJCI
    @WaivexJCI 6 месяцев назад +6

    How to ride the Boston metro for free: _shows the London tube_

    • @JesseFuches
      @JesseFuches 5 месяцев назад +1

      It’s also called the T in Boston

  • @foxgh0st-yt
    @foxgh0st-yt 5 месяцев назад +2

    These kids are based, and maybe if they made public transit more accessible and affordable, people wouldn't need to hack them for free rides.

  • @root3291
    @root3291 4 месяца назад

    I was visiting my school robotics shop when these kids got the invitation to DEFCON lol. They were excited but almost nonchalant about it, they’re definitely gonna go places

  • @S1NERT
    @S1NERT 6 месяцев назад +1

    The super funny thing about this is they use the default encryption key for mifare ultra cards

  • @123321mario
    @123321mario 3 месяца назад

    Did exactly the same in my city, still works 5 years later

  • @7dayzzz
    @7dayzzz 5 месяцев назад +1

    Not me with my student Charlie card from the school 😂

  • @Mouthwashh
    @Mouthwashh 4 месяца назад

    A high school code academy kid could have told you that. If you store the value on the card itself with no handshake from the server upon authorizing, obviously someone can just edit the data. It would be like banks storing your account balance on your debit card.

  • @Kas_Styles
    @Kas_Styles 6 месяцев назад +1

    They also did a talk on this too.

  • @bf3949
    @bf3949 6 месяцев назад +13

    These kids defeated our best tech blocks. Put them in school, not jail.

    • @RKingis
      @RKingis 6 месяцев назад

      Fr. Sneakers even had a character that was caught as a hacker.

    • @moamber1
      @moamber1 6 месяцев назад +4

      If these were your "best tech blokes", you are doomed.

    • @justcosmi
      @justcosmi 6 месяцев назад +2

      I go to school with these guys, they didn’t face any charges for this, they just turned over their findings to the MBTA in exchange for not getting sued

    • @manicsurfing
      @manicsurfing 5 месяцев назад

      What’s the difference?

  • @i110gical3
    @i110gical3 5 месяцев назад +3

    I'm guessing the manuals were posted online in pdf format with the default admin user name and password in them... The machines in production never had their default creds updated and the machines ended up getting exploited...

    • @AeroAUS
      @AeroAUS 5 месяцев назад

      more than likely just cloned the rfid data off the card and found which strings did what, allowing them to edit at will

  • @StolenPw
    @StolenPw 6 месяцев назад +1

    I hacked the shit out of the Vancouver skytrain and did a prestation at defcon about it.

  • @villandoom
    @villandoom 7 месяцев назад +12

    I also ride for free on public transport with the same method. Won't mention the company obviously

  • @gman83090
    @gman83090 6 месяцев назад +3

    Because what they do they do not cross reference the booking system with the QR code that they use to get into the airport lounge so the airport lounges access system is totally separate from the Airlines reservation system it's broken

    • @SuperPhexx
      @SuperPhexx 6 месяцев назад +5

      Here, you forgot some of these
      ....,,,,,

  • @TRIPPLEJAY00
    @TRIPPLEJAY00 5 месяцев назад +1

    You should watch their presentation on this.

  • @andrew_the_railfanner123
    @andrew_the_railfanner123 6 месяцев назад

    As a person who lives in MA and near Boston, I can confirm that this seems something that I should learn to do LMAO

  • @bharaninathkomandur6330
    @bharaninathkomandur6330 5 месяцев назад

    Usually, the currency is added in the Backend. The Card merely bears a Unique ID. But if you can duplicate an Employee's ID, then you can get lifetime free rides.

  • @Miyamoto-Rain
    @Miyamoto-Rain 5 месяцев назад +1

    Bruh just walk in behind somebody

  • @SteveySanchez
    @SteveySanchez 6 месяцев назад

    Uh well in my country they use customized version of debit cards. It is actually connected to bank and you can even manage it through online banking or atms. It is rather pretty cool feature.
    It employs same security measures as normal cards so good luck with that.

  • @animationenusw
    @animationenusw 6 месяцев назад

    If they don't have competition, make them one. The best way for modernization is to have competition.

  • @Recroomsniperpro
    @Recroomsniperpro 6 месяцев назад +1

    Better than hopping the turnstile ⬆️

  • @65cbtengr
    @65cbtengr 5 месяцев назад

    Boston native here, the MBTA is nothing more than a cash cow for the hacks.

  • @dieseldragon6756
    @dieseldragon6756 6 месяцев назад

    As a British viewer, I can definitely tell you that being found in possession of a _Charlie Card_ on this side of the Atlantic might result in some *very* uncomfortable interactions with the Police... 🇬🇧💥😉

  • @jcode1919
    @jcode1919 4 месяца назад

    For real though, the MBTA is like almost bankrupt. Pay for your ticket lol.

  • @ashenmoonclash
    @ashenmoonclash 5 месяцев назад

    In the late 1990s we just scanned movie tickets and printed them out on the same card stock. Photoshop skills were good enough we could match the font plenty well for whatever show and time. Even used a utility knife for the preferation for the stub😂

  • @jakeferreira1211
    @jakeferreira1211 4 месяца назад

    The T has issues? Who possibly could have seen that one coming? Is the red line still actively falling apart?

  • @jamesseeker1538
    @jamesseeker1538 6 месяцев назад

    Not so smart if they WILLINGLY admit to a crime they already got away with....

  • @shinosukesantana3628
    @shinosukesantana3628 5 месяцев назад

    This was done by mexican students for years. In the National pollitechnic Institute, it became so big that the Mexico city govt had to create a law against this.
    I learned about it in 2014, but I don't know since when this started.

  • @CZghost
    @CZghost 6 месяцев назад +25

    So they in fact didn't hack the subway themselves, they just used an older write up and pretty much rode the wave somebody else created before them. To be honest, that could be done by anybody with some little coding skills and good searching skills.

    • @Itsashnicole
      @Itsashnicole 6 месяцев назад +5

      😆 crazy when you're butt hurt because some teenagers are getting attention instead of you

    • @entropic_may
      @entropic_may 6 месяцев назад

      ​@@Itsashnicoletbf the short says "leaked hacker's presentation" when it was intentionally made freely available. the whole short is sensationalised.

    • @F-oxi-e
      @F-oxi-e 6 месяцев назад +4

      Actually, it says in the video they couldn't use the old hack, as paper tickets were scrapped. So they've hacked the new implied card instead.

    • @Karavusk
      @Karavusk 6 месяцев назад +1

      I guess nobody ever told him that most hacking is just as simple...

  • @nathanielcowan3971
    @nathanielcowan3971 5 месяцев назад

    They'll lose more money patching it than just letting the few people hacking the system slip through. It's like walmart and retail theft vs auto-checkout. That's their justification, at least. Really, they're just lazy and/or incompetent.

  • @randykitchleburger2780
    @randykitchleburger2780 4 месяца назад

    Lmao Los Angeles does the money value on the back end. That would never work here.

  • @WeeHee
    @WeeHee 5 месяцев назад

    I know a group of students that did the same in Denmark as their exam project

  • @cb49999
    @cb49999 5 месяцев назад

    It's insane the developers thought storing the balance on the card itself was a good idea. Storing secrets on the client side is literally one of the cardinal sins of cybersecurity lol. smh

  • @GeoMo52
    @GeoMo52 6 месяцев назад +1

    “Charlie Cards” who else gets it. Oh no he’ll never return

  • @sigi9669
    @sigi9669 6 месяцев назад

    Having a system like this function independent of the internet working flawlessly on each terminal has it's merits.
    But I don't see why there can't be occasional backend checks available.

    • @dglcomputers1498
      @dglcomputers1498 6 месяцев назад

      There are backend checks on the TFL Oyster system, of a card gets flagged more than a few times then it'll stop working, it also allows you to view your journey history online and for revenue protection to notice any suspicious activity. Noting that if there is any discrepancy between what value is on a card and what the system knows has been added there must be something amiss.
      Also any "high value" card (such as an employee card, senior card or child's card) brings up a different light on the ticket gate which can make things like wrongly using an age restr8cted free pass easily noticeable.

  • @kenney5454
    @kenney5454 5 месяцев назад

    I heard MIT students published how the Charlie Card machines loaded dates, time and amount were programmed onto it with its 256 Mg Htz CPUs, 20 year old Tech on day one, so easy to hack

  • @JRush374
    @JRush374 6 месяцев назад

    Should've just used the cards for identification of the person, which then checks the system for the amount on that person's account. Putting the amount on the cards is so stupid.

  • @kyberite
    @kyberite 5 месяцев назад

    Public transport should be free either way

  • @RaisedLetter
    @RaisedLetter 6 месяцев назад +5

    These are the people who should be designing a new system. If they know how to defy it then they should know how to protect it.

    • @moamber1
      @moamber1 6 месяцев назад +2

      Not necessarily. This was a simple hack. But it tells a lot about the level of people who were trusted to create the previous system.

  • @ronin_user
    @ronin_user 6 месяцев назад

    Theft is theft kids. Especially if you didn’t come up with the exploit.

  • @antongunther3977
    @antongunther3977 5 месяцев назад

    The MBTA is a joke. Honestly Boston has one of the worst public transport systems in the north east.

  • @DronisFilms
    @DronisFilms 5 месяцев назад

    Love the black hoodie AI-generated kid holding gibberish tickets standing in a NYC subway station 5sec into the video

  • @julianfairbanks1264
    @julianfairbanks1264 4 месяца назад

    Boston subway is in its own league tbh

  • @joemccay9978
    @joemccay9978 4 месяца назад

    Technically, this is theft of service. It's a crime.

  • @XIIchiron78
    @XIIchiron78 6 месяцев назад

    It's almost certainly cheaper to let a few people ride for free than to hire someone competent to fix an outdated system that's already being replaced. Enjoy it while it lasts. Modern RFID tags can solve this by using rolling key systems, like car key fobs do.

  • @sammygomes7381
    @sammygomes7381 6 месяцев назад

    FREE. You would have to pay me to ride the Boston subway.

  • @Joaquin__
    @Joaquin__ 6 месяцев назад +5

    They used cheat engine irl to edit their money

    • @RKingis
      @RKingis 6 месяцев назад +1

      Script kiddies

  • @pascalthedog8451
    @pascalthedog8451 5 месяцев назад

    Public transportation should be free

  • @jimmychoi5219
    @jimmychoi5219 5 месяцев назад

    You need to pay to ride the subway in US? That’s not what I see in NYC 🤣🤣🤣

  • @MrEditor6000
    @MrEditor6000 6 месяцев назад

    What the hell?
    The actual balance is written to the card?
    Those cards are at most supposed to store an account ID, and that's it.
    Everything else would be behind an (hopefully) strong authentication layer and looked up on a database.
    Make them go live faster by giving out hundreds of thousands of dollars of free rides.

  • @WrvrUgoThrUR
    @WrvrUgoThrUR 6 месяцев назад

    I redeemed all mine to attend a Foghat concert.

  • @bldrtom
    @bldrtom 6 месяцев назад

    I guess they get some kind of an award for that don’t they?

  • @drsuessl
    @drsuessl 5 месяцев назад

    I don’t appreciate these thieves

  • @clipsthatsforyou
    @clipsthatsforyou 6 месяцев назад +1

    Opal cards are an easy solution 😮😮😮😮

    • @luminism
      @luminism 6 месяцев назад

      NSW gang

  • @kidnamedfinger.productions
    @kidnamedfinger.productions 4 месяца назад

    They could at least use digital signatures to verify that the amount.

  • @DegenCode
    @DegenCode 4 месяца назад +1

    MEDFORD HS young sheldon?

  • @justinransburg5560
    @justinransburg5560 6 месяцев назад

    I dont live in Boston and i have no need for this card...but now i want one 😂

  • @snipez2600
    @snipez2600 5 месяцев назад

    I need this for my laundry card its expensive paying 3-4 dollar per one machine

  • @erebusaeon6945
    @erebusaeon6945 6 месяцев назад +1

    This isn't very impressive, you can buy RFID replication tech fairly easily and cheaply. This tech has been around for as long as RFID emitters have been around.
    I prefer the old-school hack by hopping the gate.

  • @HighRailmaxx
    @HighRailmaxx 6 месяцев назад

    Other people are paying for their so called "Free Ride".

  • @DrBovdin
    @DrBovdin 4 месяца назад

    So, showing vulnerabilities in a system: good.
    However, after showing a proof of concept, _using_ the concept will drop into somewhere between fare evasion and fraud territory. Of course these kids would never use this hack for personal gain…Right??
    Did the transport company threaten to, or worse, actually sue them? That would be extremely petty and fully expected, especially if they proudly displayed their results.

  • @bestbuny0078
    @bestbuny0078 6 месяцев назад +1

    I find it funny that thy use a raspberry pi but under power it so there is a symbol on the top right

  • @John-li1df
    @John-li1df 5 месяцев назад

    At least they did not rip the subway and make money out of this.

  • @titus9895
    @titus9895 6 месяцев назад

    That is the definition of not reinventing the wheel

  • @chris44gy
    @chris44gy 5 месяцев назад

    Okay so not that I don't appreciate your efforts but did you just watch defcon and polish it with graphics

  • @CaLiDaRi
    @CaLiDaRi 6 месяцев назад

    old school hacking... using hex editor. The good old days editing the saved games.

  • @couchpotatoes5158
    @couchpotatoes5158 6 месяцев назад

    It’s crazy how they don’t have a more secure system. I feel like this would be a pretty easy fix

  • @JackRyanRobtics
    @JackRyanRobtics 4 месяца назад

    paper tickets were still in use in 2018

  • @yahoolane
    @yahoolane 5 месяцев назад

    Who thought it was a good idea to have the balance on the card? Your card should only be giving a serial number, and the computer system. Tell them the balance. Something's not right.

  • @Bwong55
    @Bwong55 6 месяцев назад

    not a hacker, just exploited an extremely obvious weakpoint. Cant even call it a backdoor.

  • @thebdsyt
    @thebdsyt 6 месяцев назад

    ELLIOT HARDMAN IN THE WILD

  • @Edin155
    @Edin155 4 месяца назад

    Why bother fixing it when You can make bank off of it?😂😂

  • @Thebestbacon1t
    @Thebestbacon1t 6 месяцев назад

    Boston subway
    Casually shows the nyc subway

  • @KillianTwew
    @KillianTwew 5 месяцев назад

    They probably just bought a flipper zero lol

  • @matthewrease2376
    @matthewrease2376 5 месяцев назад

    Why did you randomly show Hatchi????

  • @kaito2674
    @kaito2674 6 месяцев назад +5

    The only thing that comes to my mind is young Sheldon because of Medford

    • @AbrahimSabir
      @AbrahimSabir 6 месяцев назад

      was expecting Sheldon's name in the first three comments.. but glad tht it eventually popped up

  • @BerzerkaDurk
    @BerzerkaDurk 5 месяцев назад

    Flipper Zero to the rescue!

  • @teobellverwhite3562
    @teobellverwhite3562 6 месяцев назад

    it seems it could be monetized by selling 200 credits for smaller amounts of money

  • @kreativeforce532
    @kreativeforce532 6 месяцев назад +2

    hack the card top up kiosk as well. Reverse the process so it takes money off the card and refunds it onto your bank card. effectively creating money out of thin air.

  • @tadyoshi3610
    @tadyoshi3610 5 месяцев назад

    They been loading up cards and selling them on marketplace?. For some extra stolen cash.

  • @ericjamesable
    @ericjamesable 5 месяцев назад

    Stop telling on yourself when you got it going good 😢😢