Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Saturday, September 3, 2011

Dutch journalist hacks transit card

In Netherlands, a reporter has been trying to stress out the outrageously insecure card software that the Dutch subway system uses for their transit cards. The transit card is designed as a kind of debit card where one can add money to the card and then travel with the subway system by paying with the card.



The card is delivered by the company Trans Link Systems that also oversees the transit card system. It functions by using a RFID chip that you wave in front of a proximity sensor that registers a travels start and stop, and then withdraws the amount of money according to the distance traveled. The main security issue exists in the encryption that the card is protected by, namely the Crypto-1 algorithm which was cracked in 2008, for more information see this.
   Now, armed with a cheap RFID reader/writer, which you can get for less than $40, you can easily access the information stored on the card and edit it as you wish. Moreover, the software that is used for monitoring the cards is not designed to detect unusual activity or even tampering with the card. That was exactly what the reporter/hacker Brenno de Winter proved by using a hacked card for 3 weeks without being detected even though he intentionally tried to get caught by inserting mutliple check-outs from the same airport with a 3-minute interval, which is practically impossible without some sort of teleportation. And that's not even the worst part. The technique not only allows you to insert checkouts but you could also add an unlimited amount of money to the card which means one could travel for free within the Dutch subway system with a hacked card. A potential exploiter could also use a portable RFID reader that would steal the information on other peoples cards just by walking past them and then print the information to his own card.
   You don't even have to be a hacker, let alone a techsavvy person,  to successfully hack your card since the tools needed only includes the cheap RFID reader/writer and software that easily can be downloaded from the internet.


Now the reporter Brenno de Winter, is being sued by the transportation companies for fraud, and his goal of getting the vulnerabilities fixed is being draned down the toilet. The company only stated that it is illegal to hack your card and that there will be taken legal actions against exploiters.


Even though the cards security flaws are well known, the same solution is being implemented into the bus and subway system in Denmark, which already is many years behind schedule and many millions of dollars over budget because of adjustments that needed to be made so it would adapt to the already established systems in Denmark.


At time of writing, there still hasn't been taken any action nor is there any information available that they intend to fix the vulnerabilities in the current card software.

Saturday, August 27, 2011

Danish ISPs mislead and cheat their customers

It has been known for quite some time that the majority of Danish ISPs (Internet Service Provider) promise more bandwidth than they deliver, and of course that irritates people a lot. Moreover the ISPs are acting like brutes against their customers when the poor people try to understand why they don't get the bandwidth as promised and why suddenly huge bills arrive in their mail which seemingly can be canceled in less than 2 minutes with a single phone call. Yes, this is a story of a close friend of mine who has been toyed with by the big bad phone company "3", their website is located here.


My friend moved into a new apartment almost half a year ago, and as many other people he needed to buy some internet access. He got a 3G modem from the company "3" and a subscription for 20 mbit/s for 250 DKK a month (roughly $50 USD).
   Then 2 months ago he receives a bill saying he has to pay 1200 DKK ($240) for downloading more than the 20GB his connection is limited to, except that when he looked through his logs he could see that he had only downloaded 6.5GB of data and when he called to ask about the bill, the woman who was just in customer service said: "Oh right, that must just be a mistake." and voided the invoice immediately. There was no need to talk to a "higher ranking" employee and when he asked how this mistake could have happened she said she didn't know and sadly there was no one around to tell him, he could just call again another time.

Let's take this one first. My questions are now:
  • How can there mistakenly be sent an invoice for overuse when their own software shows that there hasn't been downloaded more than allowed?
  • How is it that there isn't any confusion or surprise when a person calls about a bill he shouldn't have received? Are they used to such phone calls? Do they send unsolicited bills often?
  • Why can't she explain to him what has gone wrong?
  • If he hadn't reacted on the bill and just paid it (as some people just might have) would they have made any effort to cancel the payment or make sure he would be refunded?
This of course made him very angry, but I could just tell him that this wasn't unusual, there are many more such stories of people who have received huge bills they shouldn't have got in the first place. I asked him what connection he had, since I know for a fact that the 3G network in Copenhagen (Danish capital) can't deliver more than 2 mbit/s, and he told me he had this 20 mbit/s subscription. I went online and found 3's speed test and checked his download speed. No surprise: 2.12 mbit/s. He tested it a couple of times during the week but didn't get a higher result.

Feeling mislead and angry he went down to the store where he bought his modem and subscription and asked how come he is paying for a 20 mbit connection but only gets 2. The salesman answers that when buying a 20 mbit subscription one can expect speeds between 2 to 32 mbit/s, my friend politely says that he isn't paying for a connection which range is predominantly slower than what was promised when he bought it. So then he asks for the 2 mbit subscription that costs 50 DKK ($10) a month. The salesman tells him that then my friend won't have the possibility of the 20 mbit as his current subscription "theoretically" can achieve and my friend says he don't want to pay 5 times the price for something he don't think he'll ever get and insists that he wants his subscription changed immediately. After some discussing back and forth, the salesman finally gives up and tells him: "I'm sorry, but it is a breach of my contract if I downgrade your subscription."

I don't feel like I have to say anything, but I will just list what I get from all of this.
  1. They intentionally sell people connections that are much lower than what is promised.
  2. They are used to get complaints about the connection and there are many such stories if you do a simple google search (Danish).
  3. And a question: in what other business is it legal to promise a product or service for a fee and then not deliver what has been agreed? That is like going to the store paying for a 500-page-book and then receive the first two chapters? Isn't this called fraud?
As a last comment I just wan't to warn anyone who has considered buying any service with them since they obviously just try to take your money from you and they are being quite blunt about it.

That was all for now. See you later.