Eric Lundquist - Security - MIT Students Reveal All About Charlie Card!

MIT Students Reveal All About Charlie Card!

Written By
Eric Lundquist
Eric Lundquist
Aug 11, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Sensational headline, but the story should be dated December 10, 2004. That is the date on a paper entitled, “Privacy, SmartCards and the MBTA with a subtitle of A Policy Analysis of the MBTA’s New Automated Fare Collection System.” You can find a reference to the paper on Wikipedia.That paper did a great job at analyzing the entire automated toll concept including all the types of readers, middleware, RFID transmission sytems and databases. Let’s just say there are a lot of security and privacy issues to consider before you decide to automate your subway system. I am still a fan of tokens.

The issue of security of the Charlie Card came up again last March when University of Virginia researchers suggested that the Charlie Card could be hacked

And of course the issue came up again over this past weekend when a federal judge weighed in to prevent three MIT students from giving a presentation about Charlie Card weaknesses at the Defcon convention Las Vegas.InformationWeek has a good article with some pointers to the presentation. From the looks of it, both the students and the conference got too wrapped up in their own p.r. to think about a better way to present the information.

Now, of course all this begs the question of why anyone smart enough to hack the Boston MBTA subway system would really want to get lots of free rides on, say, the Green line out of Park Square at about 5 p.m. on a workday. The bigger issue as these type of induction-based cards (see, I read the paper and I know what the Charlie Card has in common with my electric toothbrush) are privacy issues, encryption issues and database issues. This has not been a great month for data security and it is worth remembering that all those really boring technical meetings about data security in your current projects are really worth attending. Data security and easy access are often in conflict, but you’d be wiser moving the meter to the security side of your projects these days. I wonder whatever happened to all those tokens?

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.