DEF CON 31 - Infinite Money Glitch - Hacking Transit Cards - Bertocchi, Campbell, Gibson, Harris - DEFCONConference

How many of you enjoy taking public transportation in Boston?

A significant number of people raised their hands.

What did the MIT students figure out about Charlie tickets 15 years ago?

The MIT students figured out how to clone and reverse engineer Charlie tickets, adding values up to $600 on them.

What is My Fair Classic and what encryption algorithm does it use?

My Fair Classic is a standard for data storage and communication made by NXP. It uses a proprietary 48-bit encryption algorithm called Crypto1.

What did the speaker initially try to do with the Charlie tickets?

The speaker initially tried to clone the Charlie tickets by using some common algorithms for the checksum.

What did the speaker and Maddie eventually find out about the money on the Charlie cards?

The speaker and Maddie found out that the money is stored in two yellow bytes on the card, and it is in half pennies. They also found two transaction registers: current and last values.

What is the process of changing the value on a Charlie card?

The process involves isolating variables, xoring the money values to get a data modifier, and xoring the checksums to get a checksum modifier. Then, the data and checksum are xored by the modifiers to change the data within the line.

What happened at the meeting with the execs from the headquarters?

A meeting was held where y talked to the execs about their work and how they did it. They also discussed how the execs could prevent them from doing it in the future.

What did y do with the Charlie Card in the video?

In the video, y demonstrated adding money to the Charlie Card and changing its type to employee.

What was the reaction of the audience after the demo?

The audience applauded and thanked y for the demo.