Free Rides in Denmark: Lessons from Improperly Generated Mobile Transport Tickets
نویسنده
چکیده
The term security ceremony describes a technical system extended with its human users. In this paper, we examine the inspection ceremony for the mobile transport ticket in Denmark. We find several security weaknesses that are ascribable to both human and computer components of the ceremony. The main vulnerabilities are due to the design choices of how the visual inspection ceremony is organised and the lack of information that is stored into the 2D barcode. These vulnerabilities allow a ticket holder to travel up to 8 zones with a 2-zone subscription and enable several people to travel with the same subscription. The attack is significant as it can be automated, and rather modest skills are necessary to break the inspection ceremony. We state four principles that aim at strengthening the security of inspection ceremonies and propose an alternative ceremony whose design is driven by the stated principles.
منابع مشابه
I-20: ART - Children How Are They Doing Lessons from Research
Worldwide there are over 4,000,000 ART conceived individuals. As fertility rates ‘fall’ in some countries use of ART is increasing with rates of 1.8% of live births in the UK, 4.4% in Denmark etc. Although still the single largest threat to future ART born children is being born twin, triplet or more, other research shows that there is good grounds for monitoring of the health of these children...
متن کاملusing the Railway Mobile Terminals in the Process of Validation and Vending Tickets
This article describes the functional and technical side of Railways Ltd. mobile terminals project. The advantage of mobile terminals lies in the greater efficiency of railway tickets vending, the control and real-time supervision of complete process of vending tickets in the country. Mobile terminals allow railway conductors to automatically vend and verify tickets. Also, information about eac...
متن کاملHow Big Hadoop Clusters Break in the Real World
Hadoop is among today’s most widely deployed “big data” systems. Cloudera is a company offering paid Hadoop services and support. This poster abstract describes lessons from examining a sample of 293 support tickets, from February through July of 2011. We manually labelled the tickets in our sample with the established root cause and the specific system component being worked on. Tickets cover ...
متن کاملScheduling and Load Sharing in Mobile Computing Using Tickets
Load sharing in mobile computing environments is challenged by frequent network disconnections, widely varying bandwidths among wired and wireless links, limited computing power of Mobile Hosts (MHs) and transient servers due to frequent hand-off. We consider a three-layered network architecture consisting of Mobile Hosts (MHs), Mobile Support Stations (MSSs) and Supervisory Hosts (SHs). We out...
متن کاملA Secure E-Ticketing Scheme for Mobile Devices with Near Field Communication (NFC) That Includes Exculpability and Reusability
An electronic ticket is a contract, in digital format, between the user and the service provider, and reduces both economic costs and time in many services such as air travel industries or public transport. However, the security of the electronic ticket has to be strongly guaranteed, as well as the privacy of their users. We present an electronic ticketing system that considers these security r...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2017