https://www.wired.com/story/mtba-charliecard-hack-defcon-2023/ Skip to main content Open Navigation Menu To revist this article, visit My Profile, then View saved stories. Close Alert WIRED Teens Hacked Boston Subway Cards to Get Infinite Free Rides--and This Time, Nobody Got Sued * Backchannel * Business * Culture * Gear * Ideas * Science * Security More To revist this article, visit My Profile, then View saved stories. Close Alert Sign In Search * Backchannel * Business * Culture * Gear * Ideas * Science * Security * Podcasts * Video * Artificial Intelligence * Climate * Games * Newsletters * Magazine * Events * Wired Insider * Jobs * Coupons Andy Greenberg Security Aug 10, 2023 2:43 PM Teens Hacked Boston Subway Cards to Get Infinite Free Rides--and This Time, Nobody Got Sued In 2008, Boston's transit authority sued to stop MIT hackers from presenting at the Defcon hacker conference on how to get free subway rides. Today, four teens picked up where they left off. Person's hand holding up a subway payment card to a portable subway card reader machine Four teen hackers built their own touchscreen "vending machine" that can alter the data on the Boston subway's CharlieCards, adding money or designating them "employee cards" to get infinite free rides. Photograph: Roger Kisby Save Save In early August of 2008, almost exactly 15 years ago, the Defcon hacker conference in Las Vegas was hit with one of the worst scandals in its history. Just before a group of MIT students planned to give a talk at the conference about a method they'd found to get free rides on Boston's subway system--known as the Massachusetts Bay Transit Authority--the MBTA sued them and obtained a restraining order to prevent them from speaking. The talk was canceled, but not before the hackers' slides were widely distributed to conference attendees and published online. In the summer of 2021, 15-year-olds Matty Harris and Zachary Bertocchi were riding the Boston subway when Harris told Bertocchi about a Wikipedia article he'd read that mentioned this moment in hacker history. The two teenagers, both students at Medford Vocational Technical High School in Boston, began musing about whether they could replicate the MIT hackers' work, and maybe even get free subway rides. They figured it had to be impossible. "We assumed that because that was more than a decade earlier, and it had got heavy publicity, that they would have fixed it," Harris says. Bertocchi skips to the end of the story: "They didn't." Four young people posing together The Boston subway hackers (from left to right) Scott Campbell, 16; Noah Gibson, 17; Matty Harris, 17; and Zack Bertocchi, 17.Photograph: Roger Kisby Now, after two years of work, that pair of teens and two fellow hacker friends, Noah Gibson and Scott Campbell, have presented the results of their research at the Defcon hacker conference in Las Vegas. In fact, they not only replicated the MIT hackers' 2008 tricks, but took them a step further. The 2008 team had hacked Boston's Charle Ticket magstripe paper cards to copy them, change their value, and get free rides--but those cards went out of commission in 2021. So the four teens extended other research done by the 2008 hacker team to fully reverse engineer the CharlieCard, the RFID touchless smart cards the MBTA uses today. The hackers can now add any amount of money to one of these cards or invisibly designate it a discounted student card, a senior card, or even an MBTA employee card that gives unlimited free rides. "You name it, we can make it," says Campbell. Most Popular * AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Science AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Amit Katwala * Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Security Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Andy Greenberg * A New Experiment Casts Doubt on the Leading Theory of the Nucleus Science A New Experiment Casts Doubt on the Leading Theory of the Nucleus Katie McCormick * Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Backchannel Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Steven Levy * To demonstrate their work, the teens have gone so far as create their own portable "vending machine"--a small desktop device with a touchscreen and an RFID card sensor--that can add any value they choose to a CharlieCard or change its settings, and they've built the same functionality into an Android app that can add credit with a tap. They demonstrate both tricks in the video below: In contrast to the Defcon subway-hacking blowup of 2008--and in a sign of how far companies and government agencies have come in their relationship with the cybersecurity community--the four hackers say the MBTA didn't threaten to sue them or try to block their Defcon talk. Instead, it invited them to the transit authority headquarters earlier this year to deliver a presentation on the vulnerabilities they'd found. Then the MBTA politely asked that they obscure part of their technique to make it harder for other hackers to replicate. The hackers say the MBTA hasn't actually fixed the vulnerabilities they discovered and instead appears to be waiting for an entirely new subway card system that it plans to roll out in 2025. When WIRED reached out to the MBTA, its director of communications, Joe Pesaturo, responded in a statement that "the MBTA was pleased that the students reached out and worked collaboratively with the fare collection team." "It should be noted that the vulnerability identified by the students does NOT pose an imminent risk affecting safety, system disruption, or a data breach," Pesaturo added. "The MBTA's fraud detection team has increased monitoring to account for this vulnerability [and] does not anticipate any significant financial impact to the MBTA. This vulnerability will not exist once the new fare collection system goes live, due to the fact that it will be an account-based system versus today's card-based system." Most Popular * AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Science AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Amit Katwala * Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Security Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Andy Greenberg * A New Experiment Casts Doubt on the Leading Theory of the Nucleus Science A New Experiment Casts Doubt on the Leading Theory of the Nucleus Katie McCormick * Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Backchannel Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Steven Levy * The high schoolers say that when they started their research in 2021, they were merely trying to replicate the 2008 team's CharlieTicket hacking research. But when the MBTA phased out those magstripe cards just months later, they wanted to understand the inner workings of the CharlieCards. After months of trial and error with different RFID readers, they were eventually able to dump the contents of data on the cards and begin deciphering them. Unlike credit or debit cards, whose balances are tracked in external databases rather than on the cards themselves, CharlieCards actually store about a kilobyte of data in their own memory, including their monetary value. To prevent that value from being changed, each line of data in the cards' memory includes a "checksum," a string of characters computed from the value using the MBTA's undisclosed algorithm. Person's hand putting numbers into a portable subway card reader machine The hackers figured out how to reproduce a "checksum" calculation intended to prevent the value stored on CharlieCards from being changed, circumventing that anti-hacking protection.Photograph: Roger Kisby By comparing identical lines of memory on different cards and looking at their checksum values, the hackers began to figure out how the checksum function worked. They were eventually able to compute checksums that allowed them to change the monetary value on a card, along with the checksum that would cause a CharlieCard reader to accept it as valid. They computed a long list of checksums for every value so that they could arbitrarily change the balance of the card to whatever amount they chose. At the MBTA's request, they're not releasing that table, nor the details of their checksum reverse engineering work. Not long after they made this breakthrough, in December of last year, the teens read in the Boston Globe about another hacker, an MIT grad and penetration tester named Bobby Rauch, who had figured out how to clone CharlieCards using an Android Phone or a Flipper Zero handheld radio-hacking device. With that technique, Rauch said he could simply copy a CharlieCard before spending its value, effectively obtaining unlimited free rides. When he demonstrated the technique to the MBTA, however, it claimed it could spot the cloned cards when they were used and deactivate them. Most Popular * AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Science AI Is Building Highly Effective Antibodies That Humans Can't Even Imagine Amit Katwala * Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Security Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Andy Greenberg * A New Experiment Casts Doubt on the Leading Theory of the Nucleus Science A New Experiment Casts Doubt on the Leading Theory of the Nucleus Katie McCormick * Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Backchannel Grimes on Living Forever, Dying on Mars, and Giving Elon Musk Ideas for His Best (Worst) Tweets Steven Levy * Early this year, the four teenagers showed Rauch their techniques, which went beyond cloning to include more granular changes to a card's data. The older hacker was impressed and offered to help them report their findings to the MBTA--without getting sued. In working with Rauch, the MBTA had created a vulnerability disclosure program to cooperate with friendly hackers who agreed to share cybersecurity vulnerabilities they found. The teens say they were invited to a meeting at the MBTA that included no fewer than 12 of the agency's executives, all of whom seemed grateful for their willingness to share their findings. The MBTA officials asked the high schoolers to not reveal their findings for 90 days and to hold details of their checksum hacking techniques in confidence, but otherwise agreed that they wouldn't interfere with any presentation of their results. The four teens say they found the MBTA's chief information security officer, Scott Margolis, especially easy to work with. "Fantastic guy," say Bertocchi. The teens say that as with Rauch's cloning technique, the transit authority appears to be trying to counter their technique by detecting altered cards and blocking them. But they say that only a small fraction of the cards they've added money to have been caught. "The mitigations they have aren't really a patch that seals the vulnerability. Instead, they play whack-a-mole with the cards as they come up," says Campbell. "We've had some of our cards get disabled, but most get through," adds Harris. So are all four of them using their CharlieCard-hacking technique to roam the Boston subway system for free? "No comment." For now, the hacker team is just happy to be able to give their talk without the heavy-handed censorship that the MBTA attempted with its lawsuit 15 years ago. Harris argues that the MBTA likely learned its lesson from that approach, which only drew attention to the hackers' findings. "It's great that they're not doing that now--that they're not shooting themselves in the foot. And it's a lot less stressful for everyone," Harris says. He's also glad, on the other hand, that the MBTA took such a hardline approach to the 2008 talk that it got his attention and kickstarted the group's research almost a decade and a half later. "If they hadn't done that," Harris says, "we wouldn't be here." Update 5 pm ET, August 10, 2023: Added a statement form an MBTA spokesperson. Update 11:25 am, August 11, 2023: Clarified when the teens' meeting with the MBTA took place. Get More From WIRED * Don't miss our biggest stories, delivered to your inbox every day * Our new podcast wants you to Have a Nice Future * The cloud is a prison. Can the local-first software movement set us free? * The mystery of Chernobyl's post-invasion radiation spikes * An internet shutdown means Manipur is burning in the dark * This scorching summer is taking a toll on your favorite foods * Apps are rushing to add AI. Is any of it useful? * Our Gear team has branched out with a new guide to the best sleeping pads and fresh picks for the best coolers and binoculars [undefined] Andy Greenberg is a senior writer for WIRED, covering hacking, cybersecurity and surveillance. He's the author of the new book Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency. His last book was *[Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most... Read more Senior Writer * TopicsDefConhackscybersecuritypublic transportation More from WIRED Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Hackers Rig Casino Card-Shuffling Machines for 'Full Control' Cheating Security researchers accessed an internal camera inside the Deckmate 2 shuffler to learn the exact deck order--and the hand of every player at a poker table. Andy Greenberg How to Remove Your Info From Google With the 'Results About You' Tool How to Remove Your Info From Google With the 'Results About You' Tool You can also set up alerts for whenever your home address, phone number, or email address appears in Search. Reece Rogers Leaked Yandex Code Breaks Open the Creepy Black Box of Online Advertising Leaked Yandex Code Breaks Open the Creepy Black Box of Online Advertising As the international tech giant moves toward Russian ownership, the leak raises concerns about the volume of data it has on its users. Matt Burgess A Clever Honeypot Tricked Hackers Into Revealing Their Secrets A Clever Honeypot Tricked Hackers Into Revealing Their Secrets Security researchers set up a remote machine and recorded every move cybercriminals made--including their login details. Matt Burgess Are You Being Tracked by an AirTag? Here's How to Check Are You Being Tracked by an AirTag? Here's How to Check If you're worried that one of Apple's trackers is following you without consent, try these tips. Reece Rogers Microsoft's AI Red Team Has Already Made the Case for Itself Microsoft's AI Red Team Has Already Made the Case for Itself Since 2018, a dedicated team within Microsoft has attacked machine learning systems to make them safer. But with the public release of new generative AI tools, the field is already evolving. Lily Hay Newman New 'Downfall' Flaw Exposes Valuable Data in Generations of Intel Chips New 'Downfall' Flaw Exposes Valuable Data in Generations of Intel Chips The vulnerability could allow attackers to take advantage of an information leak to steal sensitive details like private messages, passwords, and encryption keys. Lily Hay Newman The Mystery of Chernobyl's Post-Invasion Radiation Spikes The Mystery of Chernobyl's Post-Invasion Radiation Spikes Soon after Russian troops invaded Ukraine in February 2022, sensors in the Chernobyl Exclusion Zone reported radiation spikes. A researcher now believes he's found evidence the data was manipulated. Kim Zetter WIRED WIRED is where tomorrow is realized. It is the essential source of information and ideas that make sense of a world in constant transformation. The WIRED conversation illuminates how technology is changing every aspect of our lives--from culture to business, science to design. The breakthroughs and innovations that we uncover lead to new ways of thinking, new connections, and new industries. * * * * * * More From WIRED * Subscribe * Newsletters * FAQ * Wired Staff * Press Center * Coupons * Editorial Standards * Archive Contact * Advertise * Contact Us * Customer Care * Jobs * RSS * Accessibility Help * Conde Nast Store * Do Not Sell My Personal Info (c) 2023 Conde Nast. All rights reserved. Use of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Your California Privacy Rights. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices Select international siteUnited States * UK * Italia * Japon