[Gllug] Oyster cards vulnerable?

Matt Blissett matt at blissett.me.uk
Fri Jan 25 00:17:39 UTC 2008


Richard Jones wrote:
> On Thu, Jan 24, 2008 at 12:18:18PM +0000, Ryan Cartwright wrote:
>> That was why I thought it didn't quite work as centralised as Bruce
>> suggests. I always assumed (dangerous I know) that the card contained
>> some kind of total itself and this updated the centralised system when
>> you next touched it to a connected swipe device (tube station.
>> newsagents etc.).
> 
> Store the cash on the card or in a central database?  The two are not
> mutually exclusive.  You can permit the card to make small (under some
> limit) purchases while disconnected from the network, and the card
> reader can transmit those back to the central point when it next gets
> network access.  The risk is very low, and it's easy to find out after
> the fact if someone cheated.

I read an article (of unknown origin...) on how it worked a while ago, and
as far as I remember it you are correct.  I think it said needing to
nominate a station to pick up an online top-up was a side-effect of this,
and also the reason buses didn't allow this or auto-topup, but things must
have been changed since then (auto-top-up works on buses now).

> What do you think the penalty would be for someone who was found to
> have made a fake Oyster card?  Consider this penalty versus
> insignificant loss (probably under a tenner) for TFL.

I think a card reported as lost or stolen is disabled, so assuming a
fake/tampered card is also disabled, and since there's a £3 deposit on that
card, you'd have to make a lot of journeys for it to be worth the effort.
(I assume the readers on buses etc are synchronised at least daily.)

If the tube/tram/rail readers aren't live it might make more sense to try.

If it counts as forging a ticket then it's definitely not worth it (IMO,
anyway!):
    http://www.tfl.gov.uk/corporate/media/newscentre/4390.aspx

-- 
Matt


-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug




More information about the GLLUG mailing list