Live data from Hacker News

Copying a hotel keycard onto an NYC MetroCard

youtube.com

11–19 of 19 posts

Re: Copying a hotel keycard onto an NYC MetroCard

#12

Not exactly ground breaking. This is standard functionality of most card readers/encoders. You can do the same with your credit/debit card with the same results. The information on the mag stripe is not encrypted and just plain text.

You're certainly right that there's nothing groundbreaking here; tons of people have done similar things. I just thought it was interesting to clone it onto a random metrocard. However, the data is encrypted, you just don't need to care about the encryption when you're doing a bit-for-bit clone.

Re: Copying a hotel keycard onto an NYC MetroCard

#15

Major Malfunction had a great class at Black Hat: USA last year, and has been at DefCon/SchmooCon as well showing how insecure these systems are. Check out http://rfidiot.org/ for some of his research into RFID, mag strip cards and all that jazz. It is all very interesting.

Fact that you can copy magstripe keycard has no security implications. The whole idea behind hotel keycards is that each guest gets unique code on keycard and thus cannot use his copy after leaving hotel. In fact it is pretty secure design: you don't defend against copying, you simply expect that copying is possible.

Re: Copying a hotel keycard onto an NYC MetroCard

#16
There's a great article on similar situations at:

http://www.berghel.net/col-edit/digital_village/dec-07/dv_12...

He talks about being brought in to help the cops figure out why they kept arresting hookers, crooks, etc with pocket fulls of hotel room keys. It turned out they were encoding stolen credit & atm cards on them.

Re: Copying a hotel keycard onto an NYC MetroCard

#17
post #6

Did the hotel keycard have anything interesting encoded in the magnetic data? I've heard stories about credit card numbers and the likes being stored in the clear on them.

Daeken's a cool guy, but the more time you spend here, the more you'll learn that he'd do a press release for an exceptional ham sandwich.

Re: Copying a hotel keycard onto an NYC MetroCard

#18
post #6

Did the hotel keycard have anything interesting encoded in the magnetic data? I've heard stories about credit card numbers and the likes being stored in the clear on them.

Daeken's a cool guy, but the more time you spend here, the more you'll learn that he'd do a press release for an exceptional ham sandwich.

I'd be interested in a really good ham sandwich.

(It's my lunchtime!)

Re: Copying a hotel keycard onto an NYC MetroCard

#19
post #15

Major Malfunction had a great class at Black Hat: USA last year, and has been at DefCon/SchmooCon as well showing how insecure these systems are. Check out http://rfidiot.org/ for some of his research into RFID, mag strip cards and all that jazz. It is all very interesting.

Fact that you can copy magstripe keycard has no security implications. The whole idea behind hotel keycards is that each guest gets unique code on keycard and thus cannot use his copy after leaving hotel. In fact it is pretty secure design: you don't defend against copying, you simply expect that copying is possible.

Except it is easy to fake the key, there are videos of Major Malfunction changing the key to lock out all other keys, to lock out "older" keys and all kinds of other neat tricks.

Copying and modifying the data is too simple, there is no real security on those cards. The data is not encrypted on the card, it is just a proprietary format. Once you get a couple of cards it becomes easy to understand the various different data fields and what they mean.

Post reply on HN