[00:08.460 --> 00:11.780] This is MagStripe Technology in the New York City MetroCard. [00:11.980 --> 00:21.760] Just a reminder, all of these sessions are being recorded and DVDs finalized after the session and then duplicated in some kind of whismaging machine. [00:22.580 --> 00:26.200] So you will be able to purchase them moments after the session. [00:26.440 --> 00:30.340] So if there's something that you like, they kept them at the low, low price of ten bucks. [00:30.760 --> 00:34.000] So you can grab one and give it to your friends. [00:36.200 --> 00:40.520] All right, let's move on to the New York City MetroCard with Joseph Battaglia. [00:43.640 --> 00:44.080] Hello. [00:44.520 --> 00:49.000] Okay, so this discussion is going to be on Magnetic Stripe Technology and the New York City MetroCard. [00:49.100 --> 01:06.080] I'm going to discuss a little bit about what Magnetic Stripe Technology is, what sort of information you can find on Magnetic Stripes, what cards use Magnetic Stripes, how you can build your own reader, and a little bit about reverse engineering proprietary formats based on what I did for the MetroCard. [01:08.020 --> 01:11.260] So I'll talk a little bit about how I first got started in this. [01:11.480 --> 01:13.280] How many of you guys are from this area, New York City? [01:13.700 --> 01:14.500] So a lot of you. [01:14.500 --> 01:24.480] So a year and a half ago or so, you probably saw a bunch of stuff on the news about these guys in the subway who were selling fares, right? [01:25.000 --> 01:27.540] So there were a lot of news reports about that. [01:27.980 --> 01:39.800] And what they were saying was, don't buy fares from these guys because what they're doing is taking cards off the ground, doing something to them, bending them, and some magical way getting free fares from cards that they found on the ground. [01:39.800 --> 01:51.320] And it became a problem that made the news because what they started doing was plugging up the vending machines, sticking gum in the coin slots and on the bill slots so that you couldn't actually buy a card if you needed one. [01:52.120 --> 01:58.520] And so this obviously caught my interest in how could you possibly bend a card and get a free ride from it? [01:58.600 --> 01:59.600] How does that work? [02:00.360 --> 02:03.760] And it actually came up as a topic at one of the 2600 meetings. [02:04.240 --> 02:08.740] And I had a discussion with a couple of people about it and nobody really knew exactly what was happening. [02:09.400 --> 02:11.400] And so I tried to find out more information about it. [02:11.480 --> 02:13.100] I talked to some of the guys who were doing it. [02:13.320 --> 02:16.380] And some of them were like, oh, not, you know, don't want to talk about it. [02:16.420 --> 02:18.220] And some of them were just like, yeah, man, it works. [02:18.300 --> 02:19.280] You know, you just got to do this. [02:19.380 --> 02:21.200] And then when they would attempt to demonstrate it, it wouldn't work. [02:23.140 --> 02:26.960] And so, you know, I didn't really believe that it could actually happen. [02:26.960 --> 02:29.040] But, you know, there was a lot of press about it a while ago. [02:29.160 --> 02:31.020] And so I wanted to look into it. [02:31.020 --> 02:42.540] And so I had been trying to read MetroCards and see if I could find out exactly what's on them, see if maybe there's some clue there about how it worked and just about how the system worked in general. [02:42.940 --> 02:48.900] And you'll find if you try to read them in standard readers, you don't get any valuable data. [02:49.020 --> 02:55.440] You get either a string of zeros or you'll get a read error for those readers that check sums, which is most readers. [02:56.300 --> 02:57.860] And you just can't do anything with it. [02:58.200 --> 03:13.000] So my next route was to look and see how could I possibly build a reader and maybe, you know, obviously learn more about magnetic stripe technology, but also possibly be able to read the MetroCards and see what I can find out about it. [03:13.240 --> 03:17.080] And ultimately, how exactly these people were bending cards to get free fares. [03:18.880 --> 03:36.980] So fiddling around and learning more about how they worked, I realized that most of the magnetic stripe readers, all they had was a simple read head and some TTL logic circuitry that read the peaks that they got when, and I'll explain more about exactly how it works in a second, [03:37.660 --> 03:40.500] that they got from swiping the card across a magnetic head. [03:40.500 --> 03:44.200] So I figured, well, there's nothing really unique about the magnetic head. [03:44.300 --> 03:53.020] And looking up the specifications for magnetic stripe cards, you'll find that the track width is actually very similar to what you find on a cassette tape. [03:53.420 --> 04:00.600] So you can take a cassette tape head out of a standard Walkman or other cassette tape player and play around with it. [04:00.720 --> 04:01.800] And so that's what I was doing. [04:02.720 --> 04:09.880] And the first thing I did was look at the waveform on an oscilloscope and found that it looks very similar to an audio waveform. [04:10.160 --> 04:13.700] So then I hooked it up to a mic amplifier and listened to what I heard. [04:13.700 --> 04:21.680] And it sounded very similar to what you hear, you know, when you pick up the phone when a modem is online or something, but for a short period of time. [04:21.880 --> 04:24.800] And I'll play, if the audio is working, I'll play what it sounds like. [04:24.800 --> 04:25.800] This is going to be unpleasant. [04:27.320 --> 04:31.220] So, okay, so it's not so loud, but that's what it sounds like. [04:31.620 --> 04:35.720] So you get this very short burst of audio information. [04:36.480 --> 04:43.940] And that was perfect because I have this very nice analog to digital converter in my laptop, also known as a sound card. [04:44.340 --> 04:51.100] And so I was able to write just some very simple DSP code to decode that stuff. [04:51.900 --> 04:53.820] And that's where the idea came from. [04:54.300 --> 04:57.800] So I'm going to start talking a little bit about magnetism. [04:58.180 --> 05:03.820] Try to make it quick just for those of you who aren't exactly sure what's going on when you're actually swiping the card. [05:04.740 --> 05:07.380] And so some magnetism basics. [05:07.780 --> 05:09.040] Every magnet has two poles. [05:09.300 --> 05:10.780] I'm sure all of you have played with them. [05:11.920 --> 05:18.000] Opposing similar poles repel each other and this, you know, opposite poles attract to each other. [05:19.580 --> 05:33.940] So using this principle, ferromagnetic materials, which are materials that will retain magnetism when presented with a magnetic field, when presented with an external magnetic field. [05:34.080 --> 05:42.380] So you can basically take ferromagnetic materials, expose them to a field and set them up as a magnet for whatever orientation you want. [05:43.900 --> 05:46.680] One very common example of this is iron. [05:47.100 --> 05:54.980] A term that I'm going to be using later, coarsivity, is just a measure of how strong that magnetic field has to be to magnetize the material. [05:55.180 --> 05:56.700] And that's measured in units of Orsted. [05:56.700 --> 05:57.520] Solenoids. [05:58.540 --> 06:01.440] Solenoids are very simply coils of wires. [06:01.900 --> 06:06.100] When current is passed through these coils, they essentially become a magnet. [06:06.320 --> 06:10.940] Depending on which way current is flowing in the coil, you can change the polarization of that magnet. [06:12.320 --> 06:12.780] Okay. [06:13.080 --> 06:17.320] So magnetic field lines look exactly like what you see there for the bar magnet. [06:17.880 --> 06:25.080] Very close to the surface of a bar magnet, you'll find that all of the magnetic field lines are pretty much entirely horizontal. [06:25.960 --> 06:35.420] One of the things about solenoids is the same concept, which when you introduce current to it, produces a magnet, works in reverse. [06:35.420 --> 06:40.580] So if you were to insert a magnet into a solenoid, you would be able to get current out of it. [06:40.680 --> 06:45.400] And it only happens when these magnetic field lines are perpendicular to that coil. [06:45.740 --> 06:54.200] So you'll notice that with the standard bar magnet, all of the magnetic field lines are very close to the surface and all run horizontal. [06:55.260 --> 06:59.980] At the end of the magnet, you notice that they become very vertical. [07:00.380 --> 07:05.540] And so if you were to put a bar magnet into a solenoid, you would find that you'll get two peaks. [07:05.820 --> 07:11.800] One is when you insert it and one is when you remove it because it works on the concept of a changing magnetic field. [07:12.500 --> 07:12.980] Okay. [07:13.260 --> 07:18.720] So an unencoded magnetic stripe looks almost exactly like a very unpowerful bar magnet. [07:19.680 --> 07:20.120] Okay. [07:20.480 --> 07:22.840] So this is what you get when you bring two magnets together. [07:23.020 --> 07:24.460] These are the flux lines that occur. [07:24.620 --> 07:34.460] And when you have opposing poles next to each other, you'll notice that the flux lines look very similar to a standard bar magnet anywhere across its surface. [07:34.680 --> 07:41.740] And so you can't really tell the difference if you've got two magnets stuck together and move them through a solenoid. [07:42.300 --> 07:43.740] You won't notice the difference. [07:43.900 --> 07:46.060] It'll look as if it's one big bar magnet. [07:46.260 --> 07:53.060] But when you have poles that repel each other, the flux lines are perpendicular to the coil. [07:53.260 --> 07:56.240] And so you'll get another peak of current when you pass it through. [07:57.220 --> 07:57.500] Okay. [07:58.440 --> 08:15.520] So magnetic stripes are made by taking a whole bunch of little tiny ferromagnetic particles, combining them with a glue, which holds them all together, sort of painting them on the surface of the card, holding them in place so that their poles are all aligned with an external magnetic field, [08:15.660 --> 08:22.380] and then allowing that binder to dry and putting a layer of protective coating over it. [08:22.380 --> 08:24.780] So that's how magnetic stripes are actually made. [08:25.800 --> 08:26.240] Okay. [08:26.500 --> 08:40.160] So they're encoded by taking the concept of a solenoid, where you can create your own magnet, running it over this magnetic stripe, whatever track you want to encode, and flipping the polarization. [08:40.380 --> 08:47.620] And as you flip the polarization of the solenoid, you're actually flipping the polarization of the ferromagnetic materials, and you're encoding them with some sort of data. [08:48.840 --> 08:55.920] So one of the difficult things about making your own rider, or using riders, is that very careful timing has to be observed. [08:56.120 --> 08:57.820] If you try to buy a rider, they're very expensive. [08:58.360 --> 09:00.900] I mean, generally speaking, they're expensive. [09:01.820 --> 09:16.760] So you can use different techniques, and one of the most common ones are just inserting it into a machine that has rollers, and it'll make sure everything's at a constant velocity, it'll know the correct timing to get everything, so that you don't either overrun the magnetic stripe, [09:16.960 --> 09:18.100] or run too short of it. [09:19.220 --> 09:19.660] Okay. [09:20.000 --> 09:23.860] So, the next thing is, how is this stuff encoded? [09:24.120 --> 09:26.460] How do you actually encode data this way? [09:27.080 --> 09:38.220] So, what's used to encode magnetic stripes is a form of frequency shift keying, called ache and buy phase, which basically uses two frequencies to denote binary one and zero. [09:38.460 --> 09:42.800] So, one frequency would be zero, and half of that frequency would be a one. [09:42.960 --> 09:44.880] And you'll get a better idea for this when I show you the demo. [09:45.520 --> 09:56.220] So, output frequencies for a hand swipe reader, which is just me running a card across a magnetic stripe, is well within the audio range. [09:56.300 --> 10:00.460] You have no problem interfacing that with a sound card and getting away from that, you can look at it. [10:00.680 --> 10:03.140] And so, this is the reader design that you see right there. [10:03.260 --> 10:13.980] It's not much of a schematic, but you have the read head directly interfaces... directly interfaced with a 3.5mm jack, and that just goes right into your sound card. [10:13.980 --> 10:15.060] So, it's very simple. [10:15.220 --> 10:19.180] The first reader that I actually made was this thing. [10:20.060 --> 10:20.860] And that's... [10:20.860 --> 10:22.240] I mean, it's exactly what you're seeing. [10:23.000 --> 10:25.640] It's that tape head that I took out of that old Walkman. [10:26.080 --> 10:32.460] And it's taped around, like I said, just a 3.5mm jack with some standard headphone wire. [10:33.440 --> 10:36.800] And that worked actually pretty well if I wanted to get the wave. [10:36.860 --> 10:40.780] I'm not going to use it in this demo because it's a pain, but what I use now... [10:40.780 --> 10:45.820] What I'm using for this demo is a surplus magnetic stripe reader, which you can pick up for like five bucks. [10:47.720 --> 10:53.800] And usually when you buy them, you'll find that inside there's a bunch of TTL circuitry and logic stuff for reading standard cards. [10:54.600 --> 10:57.960] But I bypass all of that and interface directly with the read head. [10:58.100 --> 11:03.680] So, all that's coming out of here right now is two conductors, and it's all audio directly coming from the read head. [11:04.500 --> 11:07.320] So, let me show you guys what it looks like. [11:11.180 --> 11:12.380] So, I'm going to actually... [11:12.380 --> 11:14.920] I'm going to use a standard card example here. [11:17.520 --> 11:18.720] So, I've got... [11:18.720 --> 11:20.040] All I've got is a Starbucks card. [11:20.100 --> 11:21.180] I don't think there's any value on it. [11:24.460 --> 11:25.160] That's not so good. [11:26.400 --> 11:26.720] Okay. [11:26.840 --> 11:27.480] That's a little bit better. [11:28.520 --> 11:29.620] So, this is what you get. [11:29.720 --> 11:30.860] This is the waveform that you get. [11:32.680 --> 11:37.560] And it looks a lot like what you saw before with the RFID. [11:40.440 --> 11:48.400] So, at the beginning of the swipe, you'll notice that all of the peaks are relatively equidistant from each other. [11:48.840 --> 11:50.720] And these are actually called clocking bits. [11:50.940 --> 11:56.560] And this is what the standard reader circuitry uses to time what you see. [11:57.600 --> 11:58.920] To time the 0 bit. [11:59.200 --> 12:06.380] Because what I mentioned before is that one frequency will denote a 0 and half of that frequency will denote a 1. [12:06.560 --> 12:08.780] So, from here to here is a 0 bit. [12:09.240 --> 12:11.300] From here to here is a 0 bit, and so on. [12:12.160 --> 12:15.900] So, if you go a little bit further, you'll start to see when data is actually present. [12:16.180 --> 12:19.060] So, here is a 0 bit. [12:20.060 --> 12:21.620] This is double that frequency, right? [12:21.740 --> 12:22.540] So, that's a 1 bit. [12:23.140 --> 12:25.100] Again, another 1 bit and a 0 bit. [12:25.100 --> 12:29.940] And so you can go along like this and actually decode the entire magnetic stripe by hand if you wanted to. [12:30.140 --> 12:33.140] And what you would end up with is a string of zeros and ones. [12:37.500 --> 12:38.460] So it's pretty cool. [12:39.420 --> 12:44.180] And very simple hardware and it's really easy to build and really easy to play with. [12:45.400 --> 12:58.340] So obviously the benefits of these things are that it's not dependent on any sort of availability of, you know, serial port, PS2 port, game port, or anything else that laptops usually don't have anymore. [12:59.200 --> 13:03.380] All the decoding is done in software, so you're not dependent on any hardware specific design. [13:03.660 --> 13:10.340] If you want to play with a new proprietary format, you're welcome to play with the source code and modify it and see if you can get it to read. [13:10.560 --> 13:15.460] You can also look at the waveform very easily and try to pick up clues about how things are encoded. [13:15.900 --> 13:20.300] I know there's probably a couple of other magnetic stripes that don't use standard encodings. [13:21.160 --> 13:22.800] So it's very easy to play with. [13:23.960 --> 13:25.420] And it's really, really cheap. [13:26.160 --> 13:36.920] So this is a standard encoding for regular cards that you're likely to come across every day, like credit cards, ATM cards, gift cards, and all that sort of stuff. [13:37.460 --> 13:44.760] So you could find all this information actually in those ISO specifications and they're not so exciting to read. [13:46.060 --> 13:51.740] The magnetic stripe has three tracks, a standard magnetic stripe this is, I'm not talking about the metric card until later. [13:53.690 --> 13:57.320] Track number one is in IATA format. [13:57.720 --> 14:00.920] And that's actually an alphanumeric track. [14:01.100 --> 14:06.300] So you can actually store uppercase and numeric data on there. [14:06.720 --> 14:17.560] And most of the common stuff that you'll find on here is your count number, your name, a couple of other things, expiration date, service codes, and stuff like that. [14:17.900 --> 14:27.240] And so when you, you know, when you're at a kiosk or at a checkout or something and you put your credit card in and you see it knows your name immediately, it's because it's encoded on the magnetic stripe. [14:28.460 --> 14:35.500] The second track also contains the same information, generally speaking, except it's not alphanumeric, so the name is omitted. [14:35.660 --> 14:38.880] But most of the other fields are usually identical to what you'll find in track one. [14:39.720 --> 14:41.880] Track three is very rarely used anymore. [14:42.380 --> 14:46.060] I think the original use for track three was back when ATM machines were offline. [14:47.800 --> 14:53.260] And some sort of encoded pin was stored on track three and a couple of other things. [14:53.380 --> 14:55.080] And so that didn't work out so well for them. [14:55.200 --> 14:57.080] And most systems now are online. [14:57.580 --> 14:58.960] Actually all systems now are online. [14:59.060 --> 15:00.300] You're not going to find an offline ATM. [15:00.300 --> 15:14.000] And it turns out actually that the bits per inch aren't really all that important and often violated, but it doesn't really matter because when you swipe it, you're never swiping at the same velocity. [15:14.780 --> 15:18.460] And so the decoding software actually has to take account for that. [15:18.540 --> 15:20.220] So the bits per inch really aren't that important. [15:21.520 --> 15:27.960] And then the last field that you'll see there is approximately how many characters you can actually store on them. [15:27.960 --> 15:30.020] And I've seen more and I've seen a lot less. [15:30.220 --> 15:34.200] So it's dependent upon bits per inch and it's not really that important. [15:35.600 --> 15:40.500] Like I said, the alphanumeric track is encoded using seven bits per character. [15:41.200 --> 15:45.820] And six of those define the actual character. [15:46.060 --> 15:49.100] And it's actually equivalent to ASCII with an offset. [15:49.320 --> 15:50.540] So you can very easily decode it. [15:50.540 --> 15:54.380] You just have to add whatever offset it is. [15:54.480 --> 15:55.660] I don't remember off the top of my head. [15:55.840 --> 15:59.420] And then the seventh bit is just a CRC checksum. [15:59.880 --> 16:03.820] So you can actually verify independently that each character is read correctly. [16:05.600 --> 16:13.700] Typical financial card data, which is what I mentioned before, your credit cards, your ATM cards, gift cards, and stuff like that, all look exactly like this. [16:13.700 --> 16:16.340] Anyways, the first character is always a start sentinel. [16:16.960 --> 16:21.100] And depending on the track you're using, you know, the character is different. [16:21.300 --> 16:25.820] So you can very easily see that you've read either track one or track two or track three. [16:26.760 --> 16:29.580] After that, you'll find the format code. [16:29.580 --> 16:36.320] And that basically says, okay, this is a bank card or this is, you know, a debit card or this is, you know, a certain type of card. [16:37.320 --> 16:42.120] After that, your primary account number, you know, your credit card number, your ATM number, whatever it is. [16:42.780 --> 16:46.900] Another field separator, which basically says, okay, this is the end of the field. [16:47.000 --> 16:48.500] We're going to be going into something new now. [16:48.760 --> 16:52.960] Your name on the alphanumeric track, but not on the numeric track. [16:53.340 --> 16:55.580] And additional data and discretionary data. [16:55.860 --> 16:57.960] Additional data usually is the same. [16:57.960 --> 17:00.360] It's usually the expiration date and then some service code. [17:00.540 --> 17:07.320] And the service code can usually be looked up in the manuals if you have access to that sort of stuff. [17:07.360 --> 17:10.960] Usually it's somewhat confidential and not easy to get a hold of. [17:11.160 --> 17:13.680] And then discretionary data is totally proprietary. [17:15.740 --> 17:20.880] And you'll... you know, you really have to be working at that company to probably be able to find out what it is. [17:20.960 --> 17:27.080] But there's actually documents online of people sort of reverse engineering this stuff and looking to see what exactly the service codes mean. [17:27.100 --> 17:30.240] And some documents are even floating out there from the companies which they came from. [17:30.420 --> 17:33.560] So, you can very easily find out what they mean. [17:34.480 --> 17:34.840] Okay. [17:35.120 --> 17:41.840] So, now, sort of interesting is how do you... how do you go about reverse engineering a format? [17:41.980 --> 17:44.120] I mean, it's kind of cool to read these cards. [17:44.240 --> 17:47.640] And while I'm at it, I'll show you some of the stuff that you'll find on these cards. [17:47.860 --> 17:48.440] You know what? [17:48.700 --> 17:49.580] I have this open already. [17:52.790 --> 17:55.470] So, what I'm reading right now is a Starbucks card. [17:55.710 --> 18:00.050] And this is exactly what I showed you before when I showed you the waveform. [18:00.450 --> 18:02.150] And so, let me show you the output of DAB. [18:02.250 --> 18:12.290] DAB is an application I wrote to take the output from the microphone input and basically do some very simple DSP work on it. [18:12.390 --> 18:20.050] Detect the peaks and do some simple decoding of that data so that I don't have to go by hand and say this is 00110. [18:20.470 --> 18:22.190] So, let me show you what the output of that is. [18:22.870 --> 18:26.150] And it just takes the input from the sound card as I swipe it. [18:26.710 --> 18:27.010] Okay. [18:27.110 --> 18:31.170] So, you see that exactly what I said before, you get a whole series of zeros and ones. [18:32.250 --> 18:33.650] And that's not really very exciting. [18:35.430 --> 18:44.550] So, DMSB is an application that basically goes through the standard financial cards, tries to figure out what track it is, and then just decode it from there. [18:45.430 --> 18:48.030] So, I'll pipe it into that program, do it again. [18:48.570 --> 18:52.310] And what you see right here is the card information. [18:53.070 --> 18:56.470] And that's exactly what is stored on the card. [18:56.690 --> 19:01.610] And it's verified that that is what's stored on the card because there's checksums for every character and then there's a checksum at the end. [19:02.390 --> 19:03.950] And that's it. [19:04.010 --> 19:05.010] That's the number that's on the card. [19:05.370 --> 19:06.330] Here's another example. [19:06.450 --> 19:07.030] This is... [19:09.110 --> 19:12.770] This is a Sony Connect card, and it's another sort of stored value card. [19:12.950 --> 19:15.410] I would show you a credit card, but I don't want to. [19:18.050 --> 19:19.730] And you get the same sort of thing. [19:22.630 --> 19:28.010] And it's not very exciting, and it's looked up in Sony's database to see if you have enough value. [19:28.790 --> 19:31.710] But that's what standard cards look like. [19:33.590 --> 19:34.450] Proprietary formats. [19:35.170 --> 19:39.470] So, the New York City MetroCard obviously doesn't do this. [19:39.610 --> 19:42.150] If you tried to read it in that, it would give you an error. [19:42.250 --> 19:42.930] It wouldn't decode it. [19:43.230 --> 19:44.230] Checksums not valid. [19:44.410 --> 19:51.350] It doesn't really have any of the same sort of features that standard cards do. [19:53.210 --> 19:58.250] At the beginning of the first waveform I showed you guys, I mentioned how there are all those clocking bits, right? [20:00.630 --> 20:06.320] So, let me show you again with a MetroCard instead. [20:08.820 --> 20:11.380] So, I have a standard MetroCard. [20:11.620 --> 20:12.600] Everybody's seen these before. [20:12.960 --> 20:15.500] It's just a standard one-day unlimited MetroCard. [20:15.960 --> 20:17.300] And I'm going to swipe it. [20:17.300 --> 20:18.100] They're thinner, by the way. [20:18.260 --> 20:25.880] So, what I'm using is just a bunch of electrical tape inside the reader so that I can get it rubbing up much closer to the magnetic head. [20:27.480 --> 20:31.600] So, that's a MetroCard. [20:36.270 --> 20:37.870] And it looks very similar. [20:38.290 --> 20:41.390] And in fact, it actually does use the same encoding scheme. [20:41.710 --> 20:42.610] Frequency shift. [20:43.730 --> 20:46.190] And what's different? [20:46.410 --> 20:47.850] It doesn't have the clocking bits. [20:48.350 --> 20:58.870] So, most of the TTL decoding logic and other decoding logic circuits depend on the clocking bits to read the cards. [20:59.190 --> 21:01.650] And what they do is they look at a certain number. [21:01.850 --> 21:05.170] And there might be a standard, but I don't know what it is. [21:05.270 --> 21:08.570] Because you can't really find out how the chips are designed. [21:08.710 --> 21:13.170] They're usually just ICs that decode magnetic stripe data. [21:13.330 --> 21:15.810] And there's not really that much information about how they work. [21:16.150 --> 21:21.410] But what you see there is maybe a single clocking bit, maybe not. [21:22.590 --> 21:29.630] It's not really dependable from the standpoint of knowing for sure how long it is. [21:29.850 --> 21:36.150] You know, what if somebody didn't slide... you know, what if somebody didn't slide it with a constant velocity or something. [21:36.330 --> 21:38.770] So, you can't depend on the clocking bits. [21:39.270 --> 21:41.010] Also, I don't know if I'm going to be able to find it. [21:41.970 --> 21:45.570] Somewhere in the middle of the card, there's a funky looking bit. [21:50.570 --> 21:53.070] You can take my word for it and I can show you guys later if you're curious. [21:54.510 --> 21:55.030] Did I? [21:57.990 --> 22:00.710] Yeah, it's... I'm blind, but if... [22:04.250 --> 22:09.890] Okay, anyway, it's... all it is is a bit that looks like half of a one bit. [22:10.050 --> 22:15.950] And so, it's not really... it's not really dependable from the standpoint of knowing what binary number that is. [22:16.070 --> 22:19.790] And I'll... I'll explain... I'll actually explain what that's used for in a second. [22:20.410 --> 22:22.150] So, it's not... it's not standard. [22:22.310 --> 22:25.730] You're not going to be able to get any standard credit card readers to... to read this. [22:26.950 --> 22:31.050] However, if you're writing your own software, you can tweak it and you can modify it. [22:31.110 --> 22:34.510] And you can say, hey, don't depend on 10 clocking bits or 15 clocking bits. [22:34.710 --> 22:37.190] We know that the first one is going to be a zero. [22:37.830 --> 22:43.370] So, it's a little bit more finicky when you try to read a metric card with this. [22:43.790 --> 22:45.150] But it usually works pretty well. [22:45.550 --> 22:54.130] And so, what... all I do is depend... I think I dropped the first peak and depend on the second peak and say that that's definitely a zero bit for decoding metric cards. [22:54.270 --> 22:58.430] And it actually works fine with regular cards too, to use that assumption. [23:00.230 --> 23:10.280] So, if I try to swipe a metric card... I should have brought an old version to show you what it looks like when... when you don't make that assumption. [23:10.480 --> 23:14.100] But... So, you'll notice that it goes right away. [23:14.300 --> 23:15.620] 0, 1, 1, 0, right? [23:15.840 --> 23:18.380] So, there's no series of clocking bits when you decode it. [23:18.440 --> 23:20.960] And you have to make the assumption that the first one is going to be a zero. [23:24.130 --> 23:26.870] So, now... let's see. [23:27.190 --> 23:34.950] I have a slide that shows you... I'm sorry... all of the fields on the metric card that, so far, I've decoded. [23:36.730 --> 23:40.170] Track three... okay, first let me explain the format of the MetroCard. [23:41.410 --> 23:45.830] The MetroCard has one of the wide magnetic stripes, which means that it's actually a three track card. [23:47.750 --> 23:51.730] Track number three, which is at the top of the card, is all static data. [23:51.850 --> 23:57.210] So, all of this stuff does never... I'm sorry... all of this stuff that you see here never changes. [23:57.470 --> 24:02.110] This is all the same from when you buy the card to when you last used the card. [24:02.210 --> 24:03.050] Nothing ever changes here. [24:03.170 --> 24:08.270] And you'll find stuff like the card type, Subtype, the expiration date, serial number, stuff like that. [24:08.530 --> 24:11.790] There's a lot of stuff that I don't exactly know what is for. [24:13.350 --> 24:16.970] Unfortunately, it's not easy to find that out because it never changes. [24:18.030 --> 24:21.730] And I'll explain how I found out what's on track one and two later. [24:23.550 --> 24:25.330] Start Sentinel, time. [24:25.690 --> 24:27.310] The time field is kind of weird. [24:27.490 --> 24:32.910] There's two time fields and they sort of have to be concatenated together to get an actual time reading. [24:33.470 --> 24:40.570] The card subtype, which is different from the card type, which is number two on here. [24:41.250 --> 24:45.490] And card type basically says, okay, this is a standard metric card that you can buy from a vending machine. [24:45.750 --> 24:51.250] Other card types would be employee cards or student cards, stuff of that nature. [24:52.030 --> 24:59.990] The card subtype basically says, okay, this is a one-day unlimited or this is a full fare card or it's a 30-day unlimited card. [25:00.050 --> 25:01.690] It basically tells you what type of card it is. [25:03.030 --> 25:05.710] Time is the last time you used it. [25:06.470 --> 25:08.090] The date is the same thing. [25:08.910 --> 25:10.030] The last date you used it. [25:10.930 --> 25:12.910] Number six is the number of times you used the card. [25:13.070 --> 25:15.190] So every time you go through again, that number gets incremented. [25:16.290 --> 25:17.510] Seven is the expiration date. [25:18.850 --> 25:23.190] Eight is the transfer bit, which means, did you use the last swipe as a transfer? [25:24.110 --> 25:28.070] And this is what allows the turnstiles to know that you're not transferring twice. [25:29.270 --> 25:36.410] Nine is the last used ID, which basically is unique to each turnstile or bus. [25:37.510 --> 25:40.430] A is the card value, which is an interesting field. [25:41.350 --> 25:46.530] B is the purchase ID, which is unique to each vending machine or booth that you buy it from. [25:47.850 --> 25:48.710] Actually, you know what? [25:48.770 --> 25:49.230] I take that back. [25:49.310 --> 25:53.410] I don't know if the booths are unique or if that's a separate identifier. [25:53.630 --> 25:55.170] But each vending machine is definitely unique. [25:55.990 --> 25:57.430] And C, I don't really know what it is. [25:58.510 --> 26:01.090] A couple of the unknown fields could be checksums. [26:01.370 --> 26:02.250] I don't know. [26:02.430 --> 26:06.310] It would help if I knew because then I could verify that the swipe data is actually valid. [26:07.690 --> 26:11.690] But I don't know what C is here, and I don't know a whole bunch of what's on Track 3. [26:12.710 --> 26:25.830] So, the way that I went about reverse engineering the MetroCard is basically buying a whole lot of MetroCards, taking each card and comparing it to each other based on what I knew about the card. [26:26.290 --> 26:28.970] So, for Track 3, for example, I knew the card type. [26:29.290 --> 26:32.490] And every single card that I would get was pretty much of the same type. [26:32.630 --> 26:40.650] So, I didn't really know what that was until people started sending me different cards, like student cards and employee cards and stuff like that. [26:43.050 --> 26:47.950] The expiration date is related to when the card expires. [26:49.790 --> 27:04.850] There's some algorithm that I was playing around with, and I have a bunch of conditionals and a bunch of stuff that sort of works, and I could sort of get the expiration date, but it's pretty closely related to the expiration date, month and year. [27:05.370 --> 27:07.950] And they always expire on the last day of the month. [27:09.110 --> 27:14.430] I can talk about the source code maybe a little bit later or answer questions about it if I have time. [27:14.570 --> 27:15.350] I don't know if I'll have time. [27:17.530 --> 27:18.430] Five is unknown. [27:18.770 --> 27:19.810] I don't know what that's for. [27:20.090 --> 27:21.090] Six is always constant. [27:21.510 --> 27:22.530] Seven is also unknown. [27:23.410 --> 27:29.270] Eight is a serial number, which is just a binary representation of the decimal serial number that's on the back of the card. [27:29.630 --> 27:34.250] And then a couple of other unknown fields and the end sentinel. [27:34.350 --> 27:35.450] And the end sentinel is always the same. [27:37.310 --> 27:43.230] For track one and two, what I did was buy a whole bunch of metric cards. [27:43.310 --> 27:45.250] For example, for the serial number, I didn't explain that. [27:45.450 --> 27:48.690] I would buy a whole bunch of cards from the same machine or from the same clerk. [27:49.430 --> 27:53.410] And the serial numbers would be adjacent to each other. [27:53.590 --> 27:55.590] So for example, here it ends in 303. [27:55.690 --> 27:57.370] The next one would be 304 and 305. [27:57.490 --> 28:08.450] And so I was very easily able to compare the data on track number three and see, okay, where in this whole string of binary numbers am I incrementing by one every time? [28:09.370 --> 28:13.630] And it was very easy to see, okay, so this field is a serial number from there. [28:13.710 --> 28:14.770] So okay, that one's done. [28:14.930 --> 28:25.750] For the expiration date, you know, that took a little bit longer because you had to get cards that expired at different times and notice that that's the piece of information that was changing. [28:25.750 --> 28:29.030] So as you eliminate more and more fields, it gets easier to narrow it down. [28:29.690 --> 28:39.830] Since I knew that track three was static and it never changed, you know, it was very easy to guess that it's probably the expiration date, it's probably the serial number, it's probably other stuff that never changes. [28:40.690 --> 28:42.750] For track one and two, it was a little bit harder. [28:43.890 --> 28:51.990] I had to buy a lot more Metro cards and use them at, you know, for no reason really, I didn't really have to go anywhere. [28:53.210 --> 28:58.850] So I used the Metro cards and immediately after I used them, I read them. [28:59.710 --> 29:04.930] And I was able to... the first thing that was apparent was that the card value is actually stored on the card. [29:05.150 --> 29:06.970] It's pretty obvious where it is. [29:07.150 --> 29:17.690] So that was decreased by, you know, $2 or $1... it might have been $1.50 when I was working on every time that the card was swiped. [29:17.750 --> 29:20.350] So I knew that was the card value and I was pretty stunned at that. [29:21.950 --> 29:23.210] I found the purchase ID. [29:23.610 --> 29:28.410] I knew that everything that I bought from the same Metro card vending machine was the same. [29:29.110 --> 29:35.530] I was able to find the transfer bit, which is just one single binary digit, which basically says, have you used this card for a transfer? [29:36.610 --> 29:40.450] The expiration date, this is used for unlimited cards. [29:40.910 --> 29:44.170] It's not the expiration date that's on the back of the card, which is different. [29:44.670 --> 29:48.410] The number of times used, that was increased by one every time I used the card. [29:48.930 --> 29:51.390] And I explained what everything else was. [29:52.330 --> 29:54.990] Okay, so some of the interesting stuff about the Metro card. [29:56.190 --> 29:59.290] Like I said before, the value is actually stored on the card. [29:59.450 --> 30:07.470] There's no... this is not an online system in the sense that your card is authenticated with any server as soon as you use it because it's not. [30:08.330 --> 30:19.890] From what I've been told by MTA employees, and this isn't really verified, so I could be wrong and maybe there's MTA employees here who can correct me or maybe not. [30:20.910 --> 30:25.210] But the... also... I'm sorry. [30:25.330 --> 30:26.930] There's also patents online. [30:27.210 --> 30:33.310] The people who made this technology are... is a company called Cubic Transportation Systems. [30:33.550 --> 30:40.490] Cubic Transportation Systems have filed all their patents with pretty good representations of how the systems worked. [30:40.630 --> 30:46.450] So a lot of the other information that I got was from the patents, which is a pretty valuable resource if you're trying to reverse engineer things. [30:46.850 --> 30:56.530] They're not very technically in depth, but you can get a pretty... pretty good representation of how the system works and where you sort of want to focus. [30:57.250 --> 31:04.050] So from the patents and from what I've been told from MTA employees, the system is semi-online. [31:04.670 --> 31:13.130] The turnstiles synchronize with a station computer, and the station computer synchronizes with maybe a region computer. [31:13.370 --> 31:20.270] And then all of those computers are synchronized with a main server that's located on J Street in Brooklyn or something. [31:21.210 --> 31:26.230] Okay, so what that gives them the ability to do is disable certain serial numbers. [31:26.370 --> 31:28.490] So you see those advertisements all the time. [31:28.490 --> 31:32.930] If you've lost your card and you've paid with a credit card, you can very easily get refunded. [31:32.970 --> 31:36.610] And so they look it up with your credit card, also know exactly where you've been. [31:37.410 --> 31:39.610] And then they're able to disable the serial number. [31:40.190 --> 31:41.870] So that's one convenient thing. [31:44.170 --> 31:46.050] Unfortunately, that doesn't work so well for buses. [31:46.910 --> 31:52.490] So the buses are only synchronized when they dock again at the station, so I'm told. [31:53.410 --> 31:56.470] And that's when their databases are updated. [31:56.470 --> 32:06.330] So there's no sort of verification of how much money is actually on the card, which is interesting and is one of the clues as to how this card bending thing is working. [32:07.430 --> 32:14.110] So okay, so also what you'll find on the MetroCard is what I mentioned before about that strange bit. [32:14.750 --> 32:18.650] And that strange bit is almost exactly in the center of the card. [32:19.170 --> 32:22.550] And it's there because it's separating two different records. [32:22.770 --> 32:24.350] Track three is just one single record. [32:24.510 --> 32:32.270] But tracks one and two, which are identical, it's just basically one big wide track, actually stores two records. [32:32.710 --> 32:37.470] One of the records is the current transaction, and another one of the records is the last transaction. [32:37.850 --> 32:48.770] So for example, if I were to swipe my card, and I have a $10 prepaid card, both of those tracks... both of those records on track one and two would basically say, okay, you have $10. [32:48.770 --> 32:49.690] You bought it here. [32:49.830 --> 32:50.690] You didn't use it yet. [32:51.350 --> 32:56.110] You know, you haven't used it for transfer, and all this other stuff based on the data that's stored on the tracks. [32:56.750 --> 33:02.150] The first time I use it, the information from the current field is pushed back to the last field. [33:02.250 --> 33:03.650] So that's identical to what I just said. [33:03.810 --> 33:08.030] And then the current field has all this new information that says, okay, I just used it at this turnstile. [33:08.190 --> 33:10.910] I have this much money left, and all the other things. [33:12.090 --> 33:14.010] What happens next is I use it again. [33:14.250 --> 33:15.490] That data gets pushed back again. [33:15.670 --> 33:20.630] So record one says I have $8, and record two says I have $6. [33:20.950 --> 33:22.830] And it goes on, and it goes on, and it goes on. [33:24.230 --> 33:28.330] Recently... okay, so what I'm going to explain now is exactly how that exploit worked. [33:29.590 --> 33:31.630] I think most of you probably got it by now. [33:31.990 --> 33:43.630] When you get to a point where you don't have any value remaining on your card, legit value on your card, track... I mean, the second record still says you have $2 on it. [33:43.930 --> 33:52.750] So what people were doing... and I don't think anybody technically knew how it worked, but they probably had a kink in their card and say, wait a second, I didn't have any value on that card. [33:53.630 --> 33:59.350] So they got in for free and tried it again and probably kept doing it until they got it. [34:00.530 --> 34:03.590] So what happened was one of the records said it has $2. [34:03.690 --> 34:05.130] One of them says it has $0. [34:05.750 --> 34:12.070] If you remember back when they had the blue metric card system, before the gold cards, they had a blue card system. [34:12.690 --> 34:28.630] I haven't really done an analysis of that, but my guess is that they were having a lot of issues where... well, it was very apparent that people were having a lot of problems swiping into the turnstiles and people would stand there for a lot longer than they're standing there now to try to get into the turnstiles because they couldn't read the card. [34:28.850 --> 34:32.030] And so this is sort of their new revision of that. [34:32.350 --> 34:35.590] And my guess is that they wanted some sort of redundancy, but didn't do it very well. [34:37.490 --> 34:44.250] What happens is you put a kink in the card that only goes up to track three. [34:44.370 --> 34:45.510] You can't destroy track three. [34:46.130 --> 34:48.490] If you destroy track three, it doesn't work. [34:49.290 --> 35:01.570] You put a kink in the card on tracks one and two only, and you're under the assumption that where you put that kink prevents it from reading the previous record. [35:01.910 --> 35:07.450] So you do that, you swipe it, and the turnstile says, no, your card's not good because I couldn't read both tracks. [35:07.790 --> 35:11.210] You swipe it again and it says, okay, please swipe again at this turnstile. [35:12.110 --> 35:13.170] You swipe it again. [35:13.530 --> 35:19.650] After you swipe it again, you unkink it so that it can rewrite data back to the card and so that you don't get a write error. [35:19.750 --> 35:20.690] You don't want to get a write error. [35:21.950 --> 35:22.670] And that's it. [35:22.810 --> 35:24.110] And then the turnstile opens. [35:24.490 --> 35:34.330] And so what they obviously did was they put some sort of redundancy in there that looked at the previous record and sort of trusted it, hoping that maybe it was the current record. [35:34.990 --> 35:41.070] Because if you destroy the second record, you're not able to read how many times the card was used and things of that nature. [35:41.190 --> 35:43.810] That would allow you to say, okay, this is the current and not the last record. [35:44.570 --> 35:51.150] Different turn... not different turnstiles, but buses turnstiles and the path turnstiles treat it differently. [35:51.270 --> 35:58.650] I don't know exactly which do what, but some of them write the times you... write the current record to a different side of the card than the other one. [35:58.790 --> 36:02.210] So it's not necessarily always easy to know exactly where to fold it. [36:03.170 --> 36:09.890] But the MTA has recently done something about that particular exploit, which was to update all their firmware. [36:10.330 --> 36:22.610] And what happens is when you swipe your card now, probably most of you have had to do this, when you reach $2 and you're about to deplete your card, it asks you to swipe it again. [36:22.810 --> 36:26.290] And what it does is it copies that data over again. [36:26.390 --> 36:32.210] It basically runs the same routine that it did the first time you swiped it and copies the data to the last record. [36:32.330 --> 36:36.510] So the last record now, when you swipe it, says that there's no money remaining on the card. [36:38.730 --> 36:41.450] They only do that when you have $2 remaining on the card. [36:45.210 --> 36:45.650] Okay. [36:46.830 --> 36:50.630] So anyway, some places still don't do that. [36:52.210 --> 36:54.350] The path turnstiles don't do that yet. [36:54.670 --> 36:55.450] Maybe they will now. [36:57.430 --> 36:58.590] And a couple of other places. [36:59.450 --> 37:02.750] The only reason I ever used this was to play around because I wanted to learn how it worked. [37:03.370 --> 37:03.690] It's... [37:04.050 --> 37:05.190] Okay, so I'll tell you a story. [37:07.570 --> 37:15.430] The first time that I heard this was possible was when I was young and naive and playing in the Union Station station. [37:16.690 --> 37:19.930] I was actually with a friend of mine and we were like, oh, this can't possibly work. [37:20.030 --> 37:23.970] How could you get a free ride with, you know, bending by bending a card? [37:24.070 --> 37:30.790] And we were there for 10 minutes and didn't look up at the ceilings at the cameras that I didn't know were there. [37:31.250 --> 37:34.690] And we were just playing with the turnstile and not doing anything wrong. [37:34.870 --> 37:37.050] We weren't, you know, we weren't blocking traffic or anything. [37:37.230 --> 37:41.050] But this was actually before I even believed that it worked. [37:41.870 --> 37:43.730] And so I was playing and I was playing and I was playing. [37:43.790 --> 37:45.510] We were probably there for maybe 10, 15 minutes. [37:46.270 --> 37:47.950] And finally, the turnstile opened. [37:47.990 --> 37:48.510] I was like, whoa. [37:49.030 --> 37:51.150] So I was like, oh, this is really cool. [37:51.170 --> 37:53.570] So I go around the turnstile. [37:53.930 --> 37:59.490] Like, you know, those big turnstiles where you can go around if you really want to, but that's stupid because you lose your fare? [37:59.790 --> 38:02.170] Well, I did that and the cops probably thought that was kind of strange. [38:03.470 --> 38:06.930] So two officers came down and they were like, what are you doing? [38:07.070 --> 38:07.610] Yada, yada, yada. [38:07.750 --> 38:11.870] And I got a $75 ticket for turnstile manipulation. [38:13.330 --> 38:16.050] So they know about this stuff. [38:16.190 --> 38:16.670] Don't do it. [38:16.930 --> 38:25.110] I mean, you could still get away with it under certain circumstances, but it's one of those vulnerabilities that just don't do it. [38:26.330 --> 38:28.050] It's nice to learn how the system works. [38:29.650 --> 38:35.870] And by the way, they're looking to implement an RFID system as well. [38:38.610 --> 38:40.990] So I'm looking forward to seeing how that works. [38:41.250 --> 38:46.370] I think the first people that are actually going to do it, if you're curious about it, are the PATH people. [38:47.270 --> 38:48.930] And they... Who has it? [38:51.290 --> 38:51.690] Really? [38:51.870 --> 38:52.670] They have the... [38:56.830 --> 38:57.090] Yeah. [38:57.330 --> 38:57.450] Okay. [38:57.670 --> 38:59.670] So I know what you're talking about. [38:59.790 --> 39:02.890] They have... I think they have some RFID readers for the handicapped entries. [39:03.350 --> 39:03.610] Is that right? [39:06.330 --> 39:06.730] Okay. [39:07.050 --> 39:07.870] So... Right. [39:08.050 --> 39:11.850] So... Right. [39:12.290 --> 39:12.530] Okay. [39:12.630 --> 39:13.170] I know what you're saying. [39:13.290 --> 39:13.510] Right. [39:13.670 --> 39:13.950] Okay. [39:14.230 --> 39:15.570] So they're starting to do this. [39:15.650 --> 39:17.870] And I think they're playing with it in some experimental stage. [39:17.990 --> 39:25.090] But the first people where you're probably going to be able to buy a card soonest is with the PATH people. [39:25.290 --> 39:32.510] Let me just show you an example of what happens when you swipe a metro card because I didn't do a demo of that yet. [39:33.730 --> 39:34.930] So... Prepaid. [39:35.070 --> 39:35.290] Prepaid. [39:36.030 --> 39:36.390] Okay. [39:37.510 --> 39:41.570] So let me show you an example of... Unfortunately, I think I only brought exploitable cards here. [39:41.970 --> 39:42.770] But these are old. [39:42.950 --> 39:46.170] These are... These are... These are back when they didn't update the firmware yet. [39:46.270 --> 39:48.170] So this is just an example of what you used to be able to do. [39:50.210 --> 39:50.570] Okay. [39:50.670 --> 39:52.390] So this is... This is a seven-day unlimited. [39:52.850 --> 39:54.390] Seven-day express unlimited. [39:55.950 --> 39:59.990] Um... And you can see that here... Uh... You could see some of it. [40:02.530 --> 40:07.930] Here... This is just a Perl script that I wrote to take all that binary data and decode it and look... Look at it in a nice view. [40:08.030 --> 40:12.830] And the... The hex and the decimal views are really handy when you're trying to figure out what each field means. [40:14.070 --> 40:17.890] But, uh... But then I have a parsed field, which makes it sort of human readable. [40:18.590 --> 40:23.490] And you can see the times when this card was last used, and also how many times it was used. [40:23.650 --> 40:28.250] And it's really funny when you find, like, 30-day cards on the floor that have been used twice. [40:28.550 --> 40:29.350] And expired. [40:29.490 --> 40:30.490] Expired the day that you find. [40:30.590 --> 40:31.290] So, I don't know. [40:31.370 --> 40:32.430] Some people don't know what they're buying. [40:33.270 --> 40:34.970] But, uh... [40:37.170 --> 40:37.530] Well... [40:38.650 --> 40:39.010] Well... [40:39.010 --> 40:41.950] Well... Yeah, but... But only... Only being used twice, so... [40:45.390 --> 40:45.750] Well... [40:45.750 --> 40:46.410] Any... Okay. [40:46.610 --> 40:48.870] So anyway... Yeah, I'll get... I'll get to you later. [40:49.710 --> 40:53.610] Um... The... The... So you can... You can basically see everything about this card. [40:53.750 --> 40:57.450] And it would be... It's... It's kind of convenient because the only other way to... [40:57.450 --> 41:02.810] To know what's on your card is to go to a subway station where they have one of these things to... To learn about it. [41:03.430 --> 41:10.950] And, uh... It's so... So this... This is just a proof that all of the data that you're getting from those kiosks are actually all offline data. [41:11.510 --> 41:13.750] Um... Let me show you an example of what you get. [41:14.150 --> 41:14.470] Let's see. [41:14.710 --> 41:15.450] What's... All right. [41:15.450 --> 41:23.770] So this is... This is a full fare card that was used before they had the firmware update, which was done... Uh... Four or five months ago. [41:23.890 --> 41:24.730] Maybe a little bit longer. [41:25.710 --> 41:26.690] Something around that time. [41:27.910 --> 41:29.850] And... The last time you used a card... [41:30.790 --> 41:32.190] This is... This is what I'm talking about. [41:32.310 --> 41:34.830] Record two shows that you have $2 remaining. [41:35.170 --> 41:38.570] But record one shows that you have no... Value on the card. [41:38.810 --> 41:39.090] Sorry. [41:41.230 --> 41:44.370] So what happens is you take... You take the first record. [41:44.710 --> 41:45.710] And... And that's what was happening. [41:45.810 --> 41:46.950] They were destroying the first record. [41:47.190 --> 41:48.370] And that's how... And... And... And... [41:48.370 --> 41:49.410] They didn't really know what they were doing. [41:49.550 --> 41:50.410] But they were getting free rides. [41:51.410 --> 41:53.310] Um... Some... Some of the, uh... Let's see. [41:53.690 --> 41:55.610] I had a path... Path thing. [41:55.850 --> 41:56.690] So... So... [41:56.690 --> 41:57.850] The path people should fix this. [41:58.090 --> 41:58.230] Please. [41:59.690 --> 42:01.210] This is what happens on the path train. [42:01.470 --> 42:02.470] This is... I just use this. [42:04.510 --> 42:05.510] Um... $1.50. [42:05.770 --> 42:07.310] They... It's cheaper than the MTA. [42:07.530 --> 42:15.870] So you can't... So even though it's exploitable, you can't really do the bend thing anymore anyway because you feed them into the machine. [42:16.090 --> 42:18.290] So none of the stuff I'm showing you can actually still be used anymore. [42:19.590 --> 42:24.050] Uh... You... You... The... The... The path turnstiles actually suck your card in. [42:24.110 --> 42:25.350] I don't know how many of you have used them. [42:25.510 --> 42:30.210] But there's no... There's no way to really put a kink in it and manipulate it the way you would have to to use the old exploit. [42:30.470 --> 42:32.390] But they still... They still don't do this. [42:33.250 --> 42:39.310] They still don't take this value and write over it without, uh... You know, when on the... Upon the last use. [42:42.410 --> 42:43.330] Um... Let's see. [42:43.550 --> 42:43.750] Okay. [42:43.830 --> 42:44.750] I'm not going to show you any more cards. [42:44.930 --> 42:47.070] It's all... It's all very similar and it's all very boring. [42:48.110 --> 42:51.690] Um... But it's... It's basically all this offline data that you can find on the MetroCard. [42:51.950 --> 42:53.890] Um... I'll tell you some cool things you could do with the reader. [42:54.790 --> 43:06.710] Uh... When I was... When I was doing all this research into how you actually reverse engineer the MetroCard, uh... And... And finding all those fields and stuff, it wasn't very convenient to take my laptop out every time I wanted to swipe a card. [43:06.890 --> 43:12.370] So what... What's... What's sort of convenient about this interface is that it's just a standard 3.5 millimeter jack and all it is is audio. [43:12.590 --> 43:29.490] So if you have an MP3 player with... With recording capabilities, you can take... You can take this interface into your MP3 recorder and one of the last versions of this software can actually read... Any file that lib sound file supports. [43:29.770 --> 43:30.090] How much time? [43:30.210 --> 43:30.330] Okay. [43:30.450 --> 43:32.910] I have... I'm gonna leave it open to questions and answers now. [43:33.070 --> 43:35.350] But, uh... There's some cool things that you can do. [43:36.670 --> 43:39.850] Uh... And... And... And make really portable readers based on this design. [43:40.070 --> 43:40.790] And... And... [43:41.650 --> 43:57.290] You know, it's... It's... It's interesting because you realize when... When you're using something this small to record raw data off of a magnetic stripe, how... How easy it is when you give your credit card or uh... Or a debit card to a cashier or a restaurant waiter or waitress. [43:57.870 --> 44:02.190] That... You know, they can possibly have a device like this and just grab all the information off of it. [44:02.310 --> 44:02.650] So this is... [44:02.650 --> 44:04.570] This is just one of those cool things that you can do with it. [44:04.670 --> 44:05.490] There's a bunch of other stuff. [44:05.710 --> 44:07.410] But I'm running out of time and this always happens. [44:07.530 --> 44:10.610] So I'm gonna open it up to Q&A now because I see people are lining up. [44:21.070 --> 44:22.130] I have two questions. [44:22.310 --> 44:25.010] One is, uh... Since track one and two are rewritable... Right. [44:25.010 --> 44:27.390] What keeps replay attacks from occurring on this... Okay. [44:27.510 --> 44:30.590] So you can... You can... You can probably copy cards. [44:31.570 --> 44:33.390] Uh... I... The... Okay. [44:33.570 --> 44:37.850] So these are very high-co cards, which means that you need a very strong magnetic field to write to. [44:38.110 --> 44:42.710] And it's nothing that I can do with, um... With this sort of thing. [44:42.790 --> 44:48.930] I can't feed the output of a sound card into a writer and... And... And time it correctly and do all that other stuff and write to a high-co card. [44:49.110 --> 44:58.450] If you wanted to do something like put a reader and a writer adjacent to each other, sort of tape the cards together, and then you could probably use any... Any audio amplifier I see. [44:58.630 --> 45:03.210] You could use, like, probably a... Yeah, except high-co card writers are available commercially and they're not that expensive. [45:03.370 --> 45:03.450] Right. [45:03.530 --> 45:08.510] But they're... But they're commercial writers and they're depending on reading the data, parsing it, and then rewriting it with the... [45:08.510 --> 45:08.730] Okay. [45:08.730 --> 45:10.010] With the clocking bits and stuff like that. [45:10.050 --> 45:14.010] I recently received from Citibank a little device called a PayPass. [45:14.450 --> 45:14.690] Okay. [45:14.830 --> 45:14.910] Okay. [45:14.990 --> 45:16.970] Which is linked to my Citibank credit card. [45:17.150 --> 45:17.170] Right. [45:17.170 --> 45:27.050] And they sent me a promotion, a piece of paper in the mail recently that said that I could use it three times for free on the four, five, and six lines where they have RFID. [45:27.170 --> 45:27.390] Really? [45:27.570 --> 45:28.150] Tag readers. [45:28.870 --> 45:34.870] And if I pre-register and auto-refill my prepaid account, they'll give me six free rides. [45:35.430 --> 45:35.970] Very cool. [45:36.130 --> 45:36.450] Yeah, okay. [45:36.450 --> 45:38.150] Just so you know, Citibank and... [45:38.150 --> 45:41.990] There are a lot of chipped cards that people are starting to use right now for this kind of thing. [45:42.070 --> 45:44.770] Any corporate PayPass, a little chipped... You have to use the microphone. [45:45.290 --> 45:45.430] Yeah. [45:46.070 --> 45:47.810] People can't hear you if you don't use the microphone. [45:48.090 --> 45:48.850] You in particular. [45:48.850 --> 45:53.250] So, yeah, sorry about that. [45:53.510 --> 45:54.990] So that's very cool. [45:55.110 --> 45:57.330] I didn't actually look into the RFID system yet. [45:57.490 --> 45:59.330] I'm looking forward to getting some of the path cards. [45:59.470 --> 46:02.970] They're just 13.56 megahertz RFID, very standard stuff. [46:03.210 --> 46:09.390] So I don't know of any actual crypto stuff that's been developed for use with that. [46:09.470 --> 46:15.770] So it should be interesting to see how they manage that since most of the MTA system, as far as I know right now, is offline. [46:16.570 --> 46:17.190] Next question? [46:17.950 --> 46:19.390] Very basic question, maybe. [46:19.570 --> 46:21.370] But can you explain how you make your reader again? [46:21.570 --> 46:23.170] Oh, the reader is very, very simple. [46:23.370 --> 46:28.130] So the one that's the easiest to use is a surplus reader right here. [46:28.430 --> 46:31.230] You can get these for like two bucks, five bucks, something like that. [46:31.290 --> 46:35.070] They don't really do anything because there's no interface that's convenient to use. [46:35.170 --> 46:38.510] It's just TTL logic output, unless you want to make your own reader. [46:38.710 --> 46:42.470] Or actually, there's another open source project called... [46:43.590 --> 46:45.250] Stripe Snoop or something like that. [46:46.270 --> 46:47.170] Stripe Snoop, maybe. [46:47.450 --> 46:54.290] And they allow interfacing the TTL logic of these sort of things to the game port, but you still can't read the metric cards with them. [46:54.450 --> 47:04.690] So what you do is just basically take the surplus reader, throw out all the electronic components, because you don't need them, and solder on a 3.5 millimeter connector. [47:04.830 --> 47:05.970] That's all you have to do. [47:06.070 --> 47:08.750] It's just two conductors that you have to solder on. [47:10.110 --> 47:10.730] Next question? [47:10.730 --> 47:18.330] In your researching of the different cards, the 30-day Metro card, it actually has a value on it that goes down to $2? [47:18.370 --> 47:19.310] There's no value. [47:20.330 --> 47:21.810] There's just an expiration date. [47:22.150 --> 47:22.570] Okay. [47:22.570 --> 47:22.910] Thank you. [47:24.350 --> 47:36.230] When you swiped your PATH card before, did that actually take the $1.50 offers, or is there something special about the reader and MTA that moves the value, copies it from track one or one to two? [47:36.490 --> 47:36.490] No. [47:36.530 --> 47:47.130] Well, they use the same... they use the same... I want to say protocol, but they use the same system as the MTA now so that you can use Metro cards in the PATH turnstiles. [47:48.030 --> 47:51.790] It's not a fixed value so that they can increase the fares and whatnot. [47:51.950 --> 47:53.110] But all they do after... [47:54.130 --> 48:00.790] Yeah, my question actually is, is there something specific about the reader that takes the value off the Metro card? [48:00.910 --> 48:02.370] Or is it swiping the Metro card through anything? [48:02.510 --> 48:05.410] Like, when you just swiped your PATH card, did it take the $1.50 off? [48:05.410 --> 48:05.850] Oh, no, no, no, no, no. [48:05.890 --> 48:07.110] All I'm doing is reading to it. [48:07.170 --> 48:11.290] The actual MTA turnstiles have a whole bunch of read and write heads inside of them. [48:11.390 --> 48:15.970] So you can actually take a flashlight and look in there, and you'll notice all the read heads and write heads that are in there. [48:16.110 --> 48:20.690] So there's a bunch of them, and it's writing simultaneously while you swipe it through to read it. [48:20.870 --> 48:21.110] Okay. [48:21.290 --> 48:21.570] Thanks. [48:22.830 --> 48:28.130] This question is regarding some other possible data on the card. [48:28.270 --> 48:42.430] For example, if you ever were with a bunch of friends, and you were to buy like a $20 Metro card, and you were to keep, if you were to keep swiping it, eventually, like I think about five or six times, it would disallow you to continue. [48:42.810 --> 48:43.030] Right. [48:43.250 --> 48:48.130] Well, I mean, there's probably, there's probably checks on the servers for this sort of behavior. [48:48.330 --> 48:53.070] And like I said, they have the ability to disable, they have the ability to disable these serial numbers. [48:53.230 --> 48:56.150] So it's not, it's not something that's practical to do. [48:56.310 --> 48:58.150] I mean, I'd be interested if... [48:58.150 --> 49:06.610] Well, like for example, also, if you have, if you just have one friend and you swipe the Metro card twice, it will, and then you go to a different location, it will remember two transfers. [49:06.910 --> 49:07.270] Right. [49:07.330 --> 49:07.970] No, I know what you're saying. [49:08.090 --> 49:09.310] I think, right. [49:09.450 --> 49:15.130] I haven't, I haven't actually looked into that because that costs a lot money to, a lot more money to play with than just a single transfer. [49:15.130 --> 49:18.890] So I, I'm totally willing to play with it. [49:18.970 --> 49:21.150] If you guys, you have to use the microphone. [49:21.330 --> 49:21.510] I'm sorry. [49:22.230 --> 49:31.550] Um, there's, there's, there's a lot of stuff I could play with that if I wanted to spend a lot of money on playing with the reverse engineering stuff, I could find out, like I said, there's a lot of unknown tracks on here. [49:31.770 --> 49:33.770] So that data could be stored somewhere else. [49:33.890 --> 49:35.890] They could have been unused tracks. [49:35.970 --> 49:40.410] So when they implemented this feature, uh, you know, they, they started utilizing those tracks. [49:40.530 --> 49:42.390] So there's still a lot of work to be done on this. [49:42.470 --> 49:48.950] This, this is basically, basically a good outline of how the system works and, and, and where you can start, if you want to learn more about it. [49:49.150 --> 49:54.650] But I have a feeling in a couple of years, it's probably not going to be as widely used anymore if they really do implement the RFID stuff. [49:55.410 --> 49:56.270] Uh, yeah. [49:56.870 --> 50:04.410] I wasn't to the impression that the whole system was not stored value, but basically that the value was stored on the main system. [50:04.570 --> 50:06.050] This kind of looks like it's a little of both. [50:06.190 --> 50:07.850] I, I, I think it may be both. [50:07.970 --> 50:15.070] I think they're probably storing records of all this transaction data on the main server and then doing comparisons. [50:15.570 --> 50:15.670] Yeah. [50:15.750 --> 50:21.570] But the point is that meant, from what I understood, that copying your card, as the other person asked would basically be useless. [50:21.870 --> 50:23.990] You just end up with two cards at the same value. [50:24.110 --> 50:28.790] But when you took it off one, it would be off the other automatically because it was the server would, would go off on the server. [50:29.010 --> 50:29.990] So you wouldn't gain anything. [50:30.250 --> 50:30.410] Right. [50:30.510 --> 50:33.650] But they, but if they see this crazy stuff happening, they're going to disable the card. [50:33.770 --> 50:34.350] Well, I was assuming they didn't. [50:34.470 --> 50:37.030] Let's say you had a card and you copied that card. [50:37.030 --> 50:37.170] Right. [50:37.310 --> 50:41.390] You swipe one, the other one's going to go down by the same amount is what I understood. [50:41.690 --> 50:41.830] No. [50:42.290 --> 50:42.630] Not really? [50:43.090 --> 50:44.270] Because the question I got to that, it would. [50:45.390 --> 50:51.870] Their records would show that this serial number has this value on it, but you can't magically decrement some magnetic data in somebody's wallet. [50:52.130 --> 50:52.250] Yeah. [50:52.310 --> 50:56.590] But in other words, the system, when you swiped it again, it's not going to look at the records in the system and say, wait a minute. [50:56.710 --> 50:57.270] It's not online. [50:57.430 --> 50:59.390] It's not a real time system. [50:59.570 --> 51:00.750] Well, on the train it is. [51:00.810 --> 51:01.530] On the bus, it's not. [51:01.530 --> 51:03.430] No, it's not on the train either, no. [51:03.570 --> 51:03.630] Not either. [51:03.890 --> 51:04.150] Oh, okay. [51:06.890 --> 51:07.250] Right. [51:07.250 --> 51:07.610] Next. [51:07.890 --> 51:10.090] How do you tell the difference between the three tracks? [51:10.290 --> 51:11.470] You only have one head reading? [51:11.710 --> 51:13.850] I have, yes, I have one reader head. [51:14.130 --> 51:17.770] Everything that I showed you, this stuff right here is only tracks one and two. [51:17.950 --> 51:23.830] I have to unscrew it and move the read head if I want to read track three, but three isn't really exciting either because it's all static data. [51:24.010 --> 51:27.730] It's stuff that never changes from the time that you get the card to the time that you throw it out. [51:28.530 --> 51:31.830] So, yes, you can use the same script. [51:31.930 --> 51:32.730] I don't know if I have it online. [51:32.810 --> 51:33.530] I'll put it online though. [51:33.730 --> 51:37.110] Uh, you could use the same script to decode track three. [51:37.330 --> 51:37.950] It's not a problem. [51:38.130 --> 51:40.070] Well, let me put the website up. [51:43.750 --> 51:44.490] Uh, okay. [51:44.630 --> 51:47.350] So implications, you know, you could, you could read the stuff. [51:47.450 --> 51:48.230] I mentioned it already. [51:48.470 --> 51:55.130] This is where, this is where the articles are and this is where you can get the software and the articles which describe how to make this if you want. [51:55.210 --> 51:58.630] And there's a couple pictures of these readers in, uh, on the webpage. [51:59.450 --> 51:59.810] Question? [52:00.810 --> 52:01.530] Uh, yeah, hi. [52:01.930 --> 52:03.890] Um, first of all, will all the scripts be available? [52:04.130 --> 52:05.330] I can definitely make them available. [52:05.450 --> 52:06.510] All the software is available. [52:06.710 --> 52:10.930] The DAB decoder and, uh, the DMSB which decodes the binaries is all available online. [52:11.150 --> 52:15.250] Uh, when you soldered the read head to the, um, wire, is it polarity sensitive at all? [52:15.490 --> 52:15.890] Is it what? [52:16.110 --> 52:16.830] Polarity sensitive? [52:17.110 --> 52:17.710] No, not at all. [52:17.890 --> 52:18.270] Okay, great. [52:18.350 --> 52:18.530] Thank you. [52:18.630 --> 52:20.050] The peaks would just go in the other direction. [52:20.230 --> 52:20.690] It's not, it's not. [52:22.310 --> 52:23.150] Okay, question? [52:23.570 --> 52:24.150] Uh, thanks. [52:24.370 --> 52:28.330] What's the difference between swipe again and swipe again at this turnstile? [52:28.450 --> 52:29.950] At what point does it switch over? [52:30.490 --> 52:40.550] Okay, uh, swipe again at this turnstile means that it read your card and it might have done a partial write or it might have written on some of the card and then you screwed up or something. [52:40.710 --> 52:51.890] So, if you don't swipe it again at the same time, uh, at the same turnstile because that firmware is what has the accurate data for your card so that it can rewrite it again with the correct data, you're going to lose your fare or you're going to correct your card. [52:52.070 --> 52:56.610] So, swipe again at this turnstile means that it probably already did a partial write From what I can tell. [52:58.010 --> 52:58.410] Next. [52:59.150 --> 53:02.470] Have you done any experimentation with writing to MetroCards? [53:03.490 --> 53:07.970] I haven't done it with writing to MetroCards because, like I said, it's a very high-co card. [53:08.890 --> 53:15.050] I've played a little bit with the same sort of thing, using a sound card to create a waveform to write to another card. [53:15.150 --> 53:22.350] But my problem with that is it's hard to get the velocity correct, and it's hard to make sure that you're not writing off the end of the card. [53:22.350 --> 53:26.210] And it's hard to get it so that your data expands for the full card. [53:26.330 --> 53:34.530] If I was able to make something which I didn't have time to do that had a roller and did it, and I could time it to see how long it took, I could tweak the waveform to accurately write it. [53:34.590 --> 53:40.150] So it's definitely possible, and this could definitely be developed, but it's not as simple as, you know, this project would be. [53:40.190 --> 53:41.470] Just with a higher budget than... [53:41.470 --> 53:41.630] Right. [53:41.770 --> 53:43.750] Like $5 that needed to... [53:43.750 --> 53:43.770] Right. [53:44.130 --> 53:44.430] Right. [53:44.590 --> 53:45.410] But it's definitely possible. [53:45.790 --> 53:45.930] Yeah. [53:46.210 --> 53:54.550] I've been able to have some of those cards after it took, you know, like maybe a half hour, an hour of playing around with it to get it just right to be able to read again. [53:54.730 --> 53:59.610] So it's definitely possible if you use a local card, that doesn't require much power to write to. [53:59.930 --> 54:00.310] Thanks. [54:03.420 --> 54:15.180] Just thinking about TCP sequence numbers and how that could be a vulnerability and thinking perhaps with the serial numbers of these cards, and you have a high probability that a new card has a large value. [54:15.800 --> 54:17.060] Do you think that's a vulnerability? [54:17.460 --> 54:17.980] I don't think it's... [54:17.980 --> 54:19.880] I don't think it's a vulnerability because... [54:19.880 --> 54:27.140] Well, it could eventually become a vulnerability because I don't have a full spec for the MetroCard. [54:27.240 --> 54:28.820] I don't know what a lot of the unknown fields are. [54:28.960 --> 54:32.740] So it's not possible as far as I know right now to create your own MetroCard. [54:33.300 --> 54:40.720] I don't know if I want that to be possible because the only thing that people are going to be using it for is, you know, for fraudulent uses. [54:40.880 --> 54:52.820] But it's definitely observable that this could be a vulnerability if you were able to predict a serial number and you were able to guess that, okay, it's most likely one of the common values. [54:52.940 --> 54:55.320] Like it's most likely a $10 card or a $20 card. [54:55.440 --> 54:55.620] Right. [54:56.260 --> 54:58.160] And then that's certainly a possibility. [54:58.680 --> 54:59.340] Next question. [55:00.060 --> 55:00.680] No, go ahead. [55:01.640 --> 55:05.100] Are you familiar with cards used in other subway systems? [55:05.660 --> 55:07.720] I haven't done any work on them. [55:07.900 --> 55:10.480] I know Cubic also does the Chicago system. [55:10.860 --> 55:13.720] The Chicago cards look almost identical to the MetroCards. [55:13.940 --> 55:14.500] Right. [55:15.120 --> 55:16.580] Same exact physical format. [55:16.780 --> 55:18.120] I'm running out of time, sorry. [55:18.560 --> 55:21.720] Same exact physical format, but the data structure is slightly different. [55:22.220 --> 55:23.580] I have them. [55:23.820 --> 55:26.420] I just didn't do any work reverse engineering it. [55:27.740 --> 55:37.600] I know the Moscow subway system had an exploit for a very long time, where they also had redundant data, but it referred to the... it was completely redundant. [55:38.260 --> 55:39.040] Oh, completely redundant, right. [55:39.520 --> 55:41.620] So it was, I guess, to guard against damage to the card. [55:41.800 --> 55:42.240] Right, right. [55:42.860 --> 55:43.940] That would make sense. [55:43.960 --> 55:49.780] But then there's also exploits for that in which you can play with it when it's writing back to the card instead of when it's reading the card. [55:49.780 --> 55:52.180] The model would just tape over one side. [55:52.300 --> 55:52.460] Exactly, right. [55:52.560 --> 55:56.220] So now you can't write back to the card, but when you want to tape it, you're able to read that data. [55:56.460 --> 55:57.640] Also, one small question. [55:57.740 --> 55:58.460] I might have missed this. [55:58.560 --> 56:00.900] Have you looked into single rides and bus transfers? [56:01.180 --> 56:02.740] I've looked into single rides. [56:03.120 --> 56:08.280] They corrupt all their data or they make it unreadable to me after you use it the first time. [56:08.540 --> 56:12.120] So I don't know much about those cards. [56:12.860 --> 56:16.520] It's hard to do analysis of something that destroys itself after you use it. [56:16.520 --> 56:18.420] So I haven't really played with it that much. [56:20.400 --> 56:21.500] Sorry, we're out of time. [56:22.020 --> 56:22.340] Sorry. [56:22.920 --> 56:27.020] If anybody who has questions can meet Joe back out there. [56:27.180 --> 56:27.620] Thanks.