• About
  • Advertise
  • Contact Us
URECOMM
  • Home
  • Crime
    • USA Crime News
    • Canada Crime News
  • Entertainment
  • Technology
  • Travel
  • Automotive
  • Luxury Lifestyle
  • Food & Drinks
  • Crypto
    • News
    • Crypto Tube
    • Altcoins
    • Regulation
    • NFT
    • Metaverse
    • COINS
      • XRP
      • BTC
      • ETH
      • XMR
      • LTC
    • THE CRYPTO SHOP
      • Crypto Miners
      • Crypto Wallet
      • Trade
No Result
View All Result
  • Home
  • Crime
    • USA Crime News
    • Canada Crime News
  • Entertainment
  • Technology
  • Travel
  • Automotive
  • Luxury Lifestyle
  • Food & Drinks
  • Crypto
    • News
    • Crypto Tube
    • Altcoins
    • Regulation
    • NFT
    • Metaverse
    • COINS
      • XRP
      • BTC
      • ETH
      • XMR
      • LTC
    • THE CRYPTO SHOP
      • Crypto Miners
      • Crypto Wallet
      • Trade
No Result
View All Result
URECOMM
No Result
View All Result
ADVERTISEMENT
Home Technology

NYC subway security flaw makes it possible to track riders’ journeys

URECOMM NEWS by URECOMM NEWS
August 30, 2023
in Technology
0
NYC subway security flaw makes it possible to track riders’ journeys
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The contactless payment system for New York City’s subways has recently come under scrutiny due to a security loophole. It has been discovered that anyone with access to someone’s credit card number can trace their recent subway rides within the last seven days. This vulnerability is a result of a “feature” on the OMNY website, which is the tap-to-pay system for the Metropolitan Transportation Authority (MTA). By using only credit card information, individuals can view their ride history. This poses a serious privacy concern as it allows stalkers, abusive ex-partners, or those who have obtained credit card information illegally to track someone’s movements and determine when and where they typically ride the subway.

The issue was initially reported by Joseph Cox of 404 Media, who tested the system by tracking a rider’s movements with their consent. He found that he could gather information about the stations they entered and the corresponding times. Cox stated that if he had continued monitoring this person’s activity, he could have easily identified the subway station they often start their journeys at, which would have revealed their approximate place of residence. Consequently, this security flaw presents a gift to abusers and individuals with malicious intent, allowing them to track someone’s movements with relative ease.

Related articles

Peloton co-founder Tom Cortese is stepping down

Peloton co-founder Tom Cortese is stepping down

September 27, 2023
The Writers Guild of America’s strike ends at midnight

The Writers Guild of America’s strike ends at midnight

September 27, 2023
ADVERTISEMENT

Eva Galperin, the Director of Cybersecurity at the Electronic Frontier Foundation, emphasized the seriousness of this loophole. She stated, “This is a gift for abusers.” Galperin pointed out that while the OMNY website does offer the option to create a password-protected account, it is overshadowed by the prominently placed “Check trip history” section, which only requires a credit card number and expiration date without any additional security measures. She argued that the MTA could have easily resolved this issue by implementing a PIN or password requirement alongside the credit card information field. By doing so, it would have provided an additional layer of security and deterred unauthorized access to a rider’s travel history.

Even if a rider paid using Apple Pay, the problem persists. Apple Pay uses a virtual number when conducting transactions, which prevents merchants from accessing the actual credit card number. Apple has advertised this feature, ensuring that card numbers are never shared with merchants. However, it has been confirmed that even if the actual credit card number linked to an Apple Pay account was not directly used for a ride, entering the number on the OMNY website reveals the rider’s seven-day point-of-entry history. This discrepancy raised questions about how the MTA website associates the two without vendors having access to the physical credit card number. The MTA claims that it cannot see the credit card numbers of customers who use Apple Pay, but Apple has yet to provide a response regarding this association.

In response to these security concerns, the MTA has stated that it will consider making security changes as part of its ongoing system improvements. MTA spokesperson Eugene Resnick assured the public that maintaining customer privacy is a priority for the organization. The trip history feature was introduced to allow customers to easily check their paid and free trip history within the last seven days without the need to create an OMNY account. The MTA also offers the option of paying for OMNY travel with cash. Resnick acknowledged the importance of privacy and stated that the MTA would welcome input from safety experts as they continue to evaluate possible improvements.

In conclusion, the security loophole in New York City’s subway contactless payment system raises significant concerns about privacy and personal safety. The ability for individuals to track someone’s subway travel history with just a credit card number poses a risk for harassment, stalking, and abuse. The MTA and Apple Pay must address this issue urgently to ensure the protection of riders’ personal information. Implementing stronger security measures, such as requiring additional authentication or encryption, would be a crucial step towards mitigating this security vulnerability. By prioritizing customer privacy and listening to the advice of safety experts, the MTA can take the necessary steps to address this issue and ensure the safety and security of its riders.

Share76Tweet47

Related Posts

Peloton co-founder Tom Cortese is stepping down

Peloton co-founder Tom Cortese is stepping down

by URECOMM NEWS
September 27, 2023
0

Tom Cortese, co-founder and chief product officer of Peloton, has announced that he will be stepping down from his position....

The Writers Guild of America’s strike ends at midnight

The Writers Guild of America’s strike ends at midnight

by URECOMM NEWS
September 27, 2023
0

After an intense struggle that lasted nearly five months, the Writers Guild of America (WGA) has finally called off its...

X previews its ‘shadowban’ alerts

X previews its ‘shadowban’ alerts

by URECOMM NEWS
September 27, 2023
0

X, the social media platform, is on the brink of releasing its long-awaited feature that will notify users about whether...

Apple and Google are changing how you listen to podcasts

Apple and Google are changing how you listen to podcasts

by URECOMM NEWS
September 27, 2023
0

In the latest issue of Hot Pod, Amrita Khalid and Ariel Hauptman cover three major developments in the podcasting industry....

Apple Watch Series 9 Unboxing #shorts

Apple Watch Series 9 Unboxing #shorts

by URECOMM NEWS
September 27, 2023
0

Unboxing Apple's latest series 9 watch. Apple Watch Series 9 First Look: Double Tap Gesture, Faster Performance ... source

Load More
  • Trending
  • Comments
  • Latest
16z and Greenoaks Back ‘Pirate Nation’ Studio with $33M Funding

16z and Greenoaks Back ‘Pirate Nation’ Studio with $33M Funding

September 24, 2023
Rep. Lauren Boebert Says Hookup Theater Guy Won’t Get Another Date

Rep. Lauren Boebert Says Hookup Theater Guy Won’t Get Another Date

September 18, 2023
Huge leak reveals Microsoft will launch an all-digital Xbox Series X and new gyro controller

Huge leak reveals Microsoft will launch an all-digital Xbox Series X and new gyro controller

September 19, 2023
Hulk Hogan Marries Sky Daily in Intimate Florida Wedding Ceremony

Hulk Hogan Marries Sky Daily in Intimate Florida Wedding Ceremony

September 23, 2023
Gang Member Free On Bond For Capital Murder When He Executed Boy, Stepfather, Gets Life Without Parole

Gang Member Free On Bond For Capital Murder When He Executed Boy, Stepfather, Gets Life Without Parole

September 27, 2023
Kroy Biermann Moving Forward With Kim Zolciak Divorce Despite Recently Having Sex

Kroy Biermann Moving Forward With Kim Zolciak Divorce Despite Recently Having Sex

September 27, 2023
Peloton co-founder Tom Cortese is stepping down

Peloton co-founder Tom Cortese is stepping down

September 27, 2023
Writers Guild Deal Reached With Studios, Potentially End of Strike – The Hollywood Reporter

Writers Guild Tentative Agreement Details Released – The Hollywood Reporter

September 27, 2023
URECOMM

From breaking news and thought-provoking features to entertainment and lifestyle trends, we have something for everyone.

  • Contact Us
  • Advertise
  • Privacy Policy

© 2023 URECOMM - Garcia CO

No Result
View All Result
  • Home
  • Crime
    • USA Crime News
    • Canada Crime News
  • Entertainment
  • Technology
  • Travel
  • Automotive
  • Luxury Lifestyle
  • Food & Drinks
  • Crypto
    • News
    • Crypto Tube
    • Altcoins
    • Regulation
    • NFT
    • Metaverse
    • COINS
      • XRP
      • BTC
      • ETH
      • XMR
      • LTC
    • THE CRYPTO SHOP
      • Crypto Miners
      • Crypto Wallet
      • Trade

© 2023 Urecomm - Garcia CO