Skip to search boxSkip to navigationSkip to main content

Free Rides in Denmark: Lessons from Improperly Generated Mobile Transport Tickets

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Open access

Publication Information

Output type

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 159-174

Publication milestones

  • Published - 2017

Publication status

Published - 2017

Publisher

Springer, United States, Germany

Book series

  • Book series name: Lecture Notes in Computer Science
    Volume: 10674
    ISSN: 0302-9743

ISBN (Electronic)

978-3-319-70290-2

Publication IDs

  • Scopus: 85034239583

Host publication title

22nd Nordic Conference on Secure IT Systems (NordSec)

Abstract

The term security ceremony describes a technical system extended with its human users. In this paper, we examine the inspection ceremony for the mobile transport ticket in Denmark. We find several security weaknesses that are ascribable to both human and computer components of the ceremony. The main vulnerabilities are due to the design choices of how the visual inspection ceremony is organised and the lack of information that is stored into the 2D barcode. These vulnerabilities allow a ticket holder to travel up to 8 zones with a 2-zone subscription and enable several people to travel with the same subscription. The attack is significant as it can be automated, and rather modest skills are necessary to break the inspection ceremony. We state four principles that aim at strengthening the security of inspection ceremonies and propose an alternative ceremony whose design is driven by the stated principles.

Publication metrics

PlumX, opens in new tab

Citations
3
Captures
7