Actually Adam did a hasty follow-up to this when the video came out to say something to the effect of 'Hmmm, I may have embellished the story - and um that didn't happen' (BTW, thats me doing some heavy me para-phrasing, not a quote) Here's the link: http://news.cnet.com/8301-13772_3-10031601-52.html September 3, 2008 10:59 AM PDT 'MythBusters' co-host backpedals on RFID kerfuffle
Wonderful. Which account do we believe now?
Why the Mythbusters won't do RFID (2008)
51–60 of 66 posts
Re: Why the Mythbusters won't do RFID (2008)
#52Re: Why the Mythbusters won't do RFID (2008)
#53Earlier quoted context omitted.
> d) The only thing that should (ideally) be stored on any RFID chip is a unique number I disagree. This is basically where RFID has its benefits. Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card. This allows the system to work without the huge point of failure that is a central database and the connections to it. They have millions of peopl…
Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card. I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall: 1. Someone comes up with an "infinite balance"-hack. 2. Infinite balance cards are sold on a growing scale. 3. Transport company is forced to apply expensive bandaids to contain the problem. Mor…
The writing isn't at all obvious, otherwise they wouldn't have come up with it. I guess they've come to the conclusion that forging Oyster cash is similar to forging paper ticket or real cash. I don't know exactly how the Oyster card is implemented, but if it has some level of transaction log trail (however asynchronous), it's possible to detect forgeries (if you've only ever deposited £20, but since spend £100, you're cheating).
> Moreover I don't understand why they don't simply leverage the device that everyone already has in their pocket - the cellphone.
Scanning a barcode on a cellphone screen has three problems:
1: There are still loads and loads of cellphones not reliably capable of displaying a scannable barcode.
2: Barcodes are 100% copyable and include 0 cryptography - they have the same security as a barcode printed on a piece of paper, which, incidentally, is what they replace in airports.
3: A barcodes is read-only and requires online access to verify and record the transaction which is not feasible on the scale required for TfL.
Bluetooth has similar problems:
1: While most phones might be BT equipped, developing and supporting software for enough different phonemodels is very complex.
2: BT is designed for communication between specific devices, not a "class" of trusted devices. You can't trust all TfL checkpoints under one, so you'd have to navigate some sort of interaction every time you check in and out of a station/bus. Also, this interaction is different for each phone type = support hell.
3: BT is long range, compared to an RFID card. Sure, an RFID card might be skimmed from a difference, but it's easy for a reader to tell the card directly on the reader from every other card in the room. No so much for BT.
The solution including cellphones we need is NFC, which is basically RFID that can leverage the processing power of the cellphone. It just doesn't exist on very many phones yet.
Re: Why the Mythbusters won't do RFID (2008)
#54Earlier quoted context omitted.
Transport for London has the Oyster card, which I'm pretty sure is "electronic cash", i.e. your balance is stored on the card. I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall: 1. Someone comes up with an "infinite balance"-hack. 2. Infinite balance cards are sold on a growing scale. 3. Transport company is forced to apply expensive bandaids to contain the problem. Mor…
> I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall: The writing isn't at all obvious, otherwise they wouldn't have come up with it. I guess they've come to the conclusion that forging Oyster cash is similar to forging paper ticket or real cash. I don't know exactly how the Oyster card is implemented, but if it has some level of transaction log trail (however asynchrono…
That doesn't have to be case, which imho invalidates the rest of your points.
It's perfectly doable to issue tamper-proof tickets in the form of cryptographic signatures. So you could, for example, on a website order a barcode that encodes "This ticket valid between 10:00-18:00, on route section X, and belongs to Mr. John Doe". Obviously someone could copy and re-use that very barcode but you have the same problem with RFID tokens, unless there's some sort of centralized validation going on. Which is, btw, actually much easier to implement than you make it out to be, considering you'll have a hard time finding a train-station without GSM coverage nowadays.
I do agree with your concerns that not everyone has a phone capable of displaying these codes, yet, but it's a matter of years until that will be the case. During then you'll need the old paper tickets as a fallback - but that's the case with any new technology, it's not like you could flip the switch with RFID over night either.
Likewise Bluetooth may indeed be the wrong tool for the job, personally I'd favor the barcodes that seem to work out well enough on airports.
And finally, the development effort for making the software work all phone platforms is negligible. Again, the Airlines have demonstrated it can be done, and when you compare it to the effort required to rollout an RFID solution including the hardware then I'd bet the barcode approach is actually easier to do.
So. This, for once, is a problem that would be fairly straightforward to solve with technology. I can't help but assume this massive gravity towards more expensive and inferior solutions is mostly a result of lobbying. Obviously there's much more money to be made by handing out physical tokens and then enjoying the benefits of a ridiculously expensive support contract as you pile bandaid over bandaid...
Re: Why the Mythbusters won't do RFID (2008)
#55Earlier quoted context omitted.
> I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall: The writing isn't at all obvious, otherwise they wouldn't have come up with it. I guess they've come to the conclusion that forging Oyster cash is similar to forging paper ticket or real cash. I don't know exactly how the Oyster card is implemented, but if it has some level of transaction log trail (however asynchrono…
Barcodes are 100% copyable and include 0 cryptography That doesn't have to be case, which imho invalidates the rest of your points. It's perfectly doable to issue tamper-proof tickets in the form of cryptographic signatures. So you could, for example, on a website order a barcode that encodes "This ticket valid between 10:00-18:00, on route section X, and belongs to Mr. John Doe". Obviously someone could copy and re-…
I do, however, not agree that it's a superior solution to Oyster cards. First, the Oyster card was introduced in 2003 when even fewer cellphones would have been capable of displaying these barcodes - even then, the Oyster card was immediately available to everybody. That is a major feature - and it's not a small thing that even today all cellphones can't effortlessly do this. Fast mass adoption is a feature.
Also, no matter how easy the implementation, buying a barcode-ticket on your phone and then scanning it is more complicated than simply touching a card. If you have to run to catch a train, you don't want to have to stop and fiddle with your phone, for however short time, to get it to show the relevant barcode.
But that's dwelling over tiny details. My post was a counter-point to your claim that the Oyster card has grave and obvious flaws and was deployed in favour of an obviously better solution. I argue that, even considering that the Oyster card system have problems, those have not been exploited, while enabling the benefits of a pay-as-you-go system.
And just to be clear: I fully expect the Oyster system to be replaced by a system based on NFC once that is viable. That just wasn't in 2003, and it isn't today.
Re: Why the Mythbusters won't do RFID (2008)
#56Re: Why the Mythbusters won't do RFID (2008)
#57Earlier quoted context omitted.
Barcodes are 100% copyable and include 0 cryptography That doesn't have to be case, which imho invalidates the rest of your points. It's perfectly doable to issue tamper-proof tickets in the form of cryptographic signatures. So you could, for example, on a website order a barcode that encodes "This ticket valid between 10:00-18:00, on route section X, and belongs to Mr. John Doe". Obviously someone could copy and re-…
Fair enough, I misunderstood how you imagined barcodes to be implemented, and yes, that invalidates my specific arguments. I do, however, not agree that it's a superior solution to Oyster cards. First, the Oyster card was introduced in 2003 when even fewer cellphones would have been capable of displaying these barcodes - even then, the Oyster card was immediately available to everybody. That is a major feature - and…
I admit I got a bit carried away on the barcode idea, mostly because I have used it at the airport and liked it. But I have to agree it might not scale as well to public transport use - the whole running after train thing.
Well, I guess we can meet in the middle and agree that NFC would be the near-optimal solution, when and if implemented securely (however unlikely that is.. ;-) ).
Re: Why the Mythbusters won't do RFID (2008)
#58Re: Why the Mythbusters won't do RFID (2008)
#59Earlier quoted context omitted.
> I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall: The writing isn't at all obvious, otherwise they wouldn't have come up with it. I guess they've come to the conclusion that forging Oyster cash is similar to forging paper ticket or real cash. I don't know exactly how the Oyster card is implemented, but if it has some level of transaction log trail (however asynchrono…
Barcodes are 100% copyable and include 0 cryptography That doesn't have to be case, which imho invalidates the rest of your points. It's perfectly doable to issue tamper-proof tickets in the form of cryptographic signatures. So you could, for example, on a website order a barcode that encodes "This ticket valid between 10:00-18:00, on route section X, and belongs to Mr. John Doe". Obviously someone could copy and re-…
"All transactions are settled between the card and reader alone. Readers transmit the transactions to the back office in batches but there is no need for this to be done in real time." - http://en.wikipedia.org/wiki/Oyster_card
People here are saying "I think/guess/assume that oyster cards work like... ". Without even checking with Wikipedia. I'd like to hear about the Oyster card system's strengths and weaknesses from someone who really knows the system.
Re: Why the Mythbusters won't do RFID (2008)
#60Earlier quoted context omitted.
Fair enough, I misunderstood how you imagined barcodes to be implemented, and yes, that invalidates my specific arguments. I do, however, not agree that it's a superior solution to Oyster cards. First, the Oyster card was introduced in 2003 when even fewer cellphones would have been capable of displaying these barcodes - even then, the Oyster card was immediately available to everybody. That is a major feature - and…
Hmm yea, you do have a point. I admit I got a bit carried away on the barcode idea, mostly because I have used it at the airport and liked it. But I have to agree it might not scale as well to public transport use - the whole running after train thing. Well, I guess we can meet in the middle and agree that NFC would be the near-optimal solution, when and if implemented securely (however unlikely that is.. ;-) ).