August 6, 2008 4:37 PM PDT

Hacking electronic-toll systems

LAS VEGAS--Electronic toll systems like FasTrak and E-ZPass may be convenient for drivers, but they are rife with privacy risks, a security expert said Wednesday at the Black Hat 2008 security conference.

Strangers with the right transponder reader walking through a parking lot can steal the ID number off the transponders that are visible through the windshield, put the data on their devices and pass through bridge and other tolls for free, with the victim paying the bill, according to Nate Lawson, principal of security consultancy Root Labs.

The transponder ID, which lacks encryption, could be wiped and switched with that of a device from a different car used in a crime, such as for alibi purposes, he said.

The e-toll systems also pose a risk in that a driver's movements could be tracked in real time, and e-toll operators have already been served with subpoenas seeking customer information, Lawson said.

Although the ID is not personally identifiable, it can be linked in the back-end database to customer information like name, driver's license, and credit card number, he said.

The FasTrak system, used in the San Francisco Bay Area, has said it will improve the security, but it is difficult to make a system secure after the fact, Lawson said. So, he is designing a FasTrak Privacy Kit that people can use to make their transponders more secure.

Basically, the kit will allow someone to put a "kill switch" on their transponder so the ID can't be read unless the device is turned on with a special button. The system is only vulnerable while it is on.

Or, you could just do what I do, and keep the device in the mylar pouch it comes in when you buy it and that will protect the data.

Click here for full coverage of Black Hat 2008.

In this video Lawson explains why consumers should be wary of using electronic-toll systems:

Recent posts from News - Security
Facebook botnet risk revealed
Security firm spots Chrome 'SaveAs' flaw
Microsoft: Expect four bulletins on Patch Tuesday
Protesters decry NASA hacker's extradition
Chrome suffers first security flaw
Add a Comment (Log in or register) 9 comments
by Methuss August 7, 2008 8:27 AM PDT
DUH! And not only that but they can send you speeding tickets in the mail. All they need is the distance between two toll booths, the time leaving the first and the time arriving at the second and they have all they need to determine how fast you were going. Any 3rd grader can do the math for that. Since they also have the transponder number, they have positive identification of the registered driver too.
Reply to this comment View reply
by myosh_tino August 7, 2008 10:16 AM PDT
To prevent hackers from doing as the article suggests, someone should develop software that will compare the license plate to the one linked to the FasTrak account. If they don't match, notify the account holder and send the driver using the cloned transponder a hefty toll violation notice.
Reply to this comment
by TV James August 7, 2008 10:41 AM PDT
Yeah, that's great... an on/off switch. How much money will they make from people who forget to turn it on? Or how money will they lose from people who "forget" to turn it on?
Reply to this comment
by ZaphodQB August 7, 2008 10:45 AM PDT
So I am guessing Methuss thinks that getting a ticket for breaking the law is bad, but breaking the law is not?
Reply to this comment
by ZaphodQB August 7, 2008 10:47 AM PDT
So I am guessing Methuss thinks that getting a ticket for breaking the law is bad, but breaking the law is not?
Reply to this comment
by jsjonesnet August 7, 2008 11:10 AM PDT
Having one of the SF Bay transponders I can tell you that the photo they take when you pass the toll gate shows them the license plate which they match to the Fastrack account.
My low battery transponder works only 1/2 the time.
They do not fine the Fastrack users when passing the toll gate without the transponders, as long as their plates are registered with them.
This is so as you could have many cars and only one transponder possibly forgetting to take the transponder.
BTW our bridges here have only one toll gate in one direction only.
Reply to this comment
by morlamweb August 7, 2008 1:34 PM PDT
What about the Fast Lane system in Massachusetts? Was that system mentioned in the conference? And how exactly would one track a car with an e-toll tag, anyway? I thought that the tags were read only at the toll gates. To say that someone could be tracked real-time makes me think of something out of the Bourne movies.
Reply to this comment
by benjaminstraight August 7, 2008 2:48 PM PDT
I didn't know this.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

About News - Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

News - Security topics

Featured blogs

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Intel ships low-power chips for servers

    New server chips from processor giant draw as little as 12.5 watts per core.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Ad trade group opposes Yahoo-Google search deal

    Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    TI does energy efficiency on a chip

    Its line of Piccolo microcontrollers can reduce power consumption significantly of home appliances, hybrid cars, LED lighting, and even solar panels.