California's FasTrak system completely insecure

Fri Aug 8, 2008 12:43AM EDT

See Comments (2)

Security researchers are finally getting around to telling us what we probably all should have guessed years ago: California's FasTrak system, the RFID tag technology used across the state to automatically pay tolls on bridges and toll roads, is hopelessly insecure.

How insecure? According to research published at Hackaday.com, there's no security at all in the devices. With little difficulty, anyone with RFID experience could "wander through a parking lot with an RFID reader and pick up the ID of every tag in the lot." But that's just the half of it: The FasTrak devices support "over the air upgrading," so that hacker could not only read your FasTrak ID, he could replace it with another ID on a whim.

The opportunity for annoying havoc is obvious: Clever hackers could set up a transponder at a busy intersection and replace or erase FasTrack ID tags en masse, causing huge headaches for billing systems and consumers alike. And of course, the Holy Grail is out there too: The hunt for "toll-free" IDs (such as those that might be used by highway management types), allowing anyone with the code to pass on any road or bridge, completely free of charge.

Proposed fixes include developing a mechanism for turning off the FasTrak circuitry when you aren't actively passing through a toll system, but I've got an even better one sitting on my dash: My FasTrak battery died years ago, but since the toll bridges scan your license plate whenever a car with a busted tag passes through, my account still gets billed normally, just as if my transponder was working. It's all the convenience without the insecurity, and California doesn't seem to care at all.

LINK: Black Hat 2008: FasTrak toll system completely broken

 

Comments on California's FasTrak system completely insecure

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 1 Posted by rogueist on Thu Sep 3, 2009 8:49PM EDT Report Abuse

    Wow, over the air upgradable? Who was the nebbish that thought of that blunder? Here in Florida they will bill you only if occasionally the sensors do not properly pick you up. Otherwise, if you let your battery die, they will issue you a ticket each time you go through.

  • 2 Posted by susieq324 on Thu Sep 3, 2009 9:50PM EDT Report Abuse

    Is this issue restricted to this pass system in California or is the East Coast "EZPass" system also a concern?

More Posts: 1

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.