Alexi Mostrous
Win tickets to the ATP finals

Millions of identity cards are carrying a serious security flaw that allows them to be cloned by anyone with a standard laptop,The Times has learnt.
The Mifare smartcard, which is used to gain access to thousands of schools, hospitals and government departments around Britain, as well as providing the technology behind 17 million Oyster cards for travel in London, was hacked into by scientists at a Dutch university.
Bart Jacobs, of Radboud University, used a commercial laptop to clone a swipe access card to a public building in the Netherlands. His team then travelled to London, where they used the same technique to ride on the Underground for a day without paying.
Security experts said that the breach posed a serious risk to security as swipe cards to sensitive areas could be cloned with ease.
After learning of the breach in April, the Dutch Government posted armed guards outside all its buildings and it now plans to spend millions of euros upgrading its systems. It also postponed the introduction of a €1 billion transport payment system similar to the Oyster card until security issues were addressed.
“We take this extremely seriously,” a spokesman for the Dutch Interior Ministry said. “It’s a national security issue. We’re in the process of replacing the cards of all 120,000 civil servants at central government level at a cost of about €5 for each card.”
The Cabinet Office refused to confirm yesterday which government buildings used the system.
About ten million Mifare smartcards are sold in Britain each year, providing access to public buildings as well as cashless payment systems for transport systems and colleges. Six million were issued recently to pensioners for free travel on public transport.
“You only have to walk down the street to see contactless access control systems everywhere,” said Adam Laurie, a security researcher. “It used to be a magnetic strip, now it’s a card held up to a reader on the wall. A large percentage of these will have Mifare technology and are very vulnerable to attack. They should all be replaced.”
He added: “The cryptography is simply not fit for purpose. It’s very vulnerable and we can expect the bad guys to hack into it soon, if they haven’t already.”
To perform the London experiment, Dr Jacobs used a computer to reverse the Mifare algorithmic code, allowing him to put credit back on his Oyster card. The cards use a similar wireless technology to that found in biometric passports and the planned national identity card.
“When we found these vulnerabilities we gave a clear security warning to the Dutch Government, which was then passed on to the UK authorities in April”.
Buildings accessible by photo ID cards were particularly vulnerable to attack, Dr Jacobs said. “An employee can be cloned by bumping into that person with a portable card reader,” he said. “The person whose identity is being stolen may then be completely unaware that anything has happened.
“At the technical level there are currently no known countermeasures.”
The technology is owned by NXP Semiconductors, a company based in the Netherlands and founded by Philips. A spokesman for the company said: “We are aware that the Dutch researchers have reverse engineered the algorithm and we are taking this issue very seriously. We’ve informed all of our system integrators and advised them to closely assess their systems. We’re talking to the guys at Radboud University and have identified various counter measures.”
Transport for London denied yesterday that any security breach had taken place. “This was not a hack of the Oyster system,” a spokesman said. “It was a single instance of a card being manipulated.”
There are an estimated two billion Mifare Classic cards worldwide.
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
36-month car lease
on contract hire for
£359.99 plus VAT pm
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
The UK's leading alternative to showroom finance.
Finance packages tailored to your needs.
Minimum loan of £15,000
Car Insurance
£12,578 per annum
The Independent Housing Ombudsman
London
Competitive
Barclaycard
Not Specified
The Sheppard Trust
London
£80-95,000
Clay McGuire Executive Selection
Moments from Battersea Park.
For sale with Winkworth.
See your free Experian credit report beforehand
Book now & save over £100pp.
11 cool resorts, lowest prices... Early Booking offers 15 Nov.
20% off selected Azores holidays taken in October with Sunvil Discovery
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.