125 kHz 2 bits/cycle = 250 bits /sec
A 2^40 bit string has 1099511627776 combinations, and would require 1099511627776 40 = 43980465111040 bits to besent to try all of them. That would take 43980465111040/250 seconds or about 5575 years
And that's under ideal "spherical object in a vacuum" conditions.
So yeah your right, unless they get lucky.
125kHz = 125,000 cycles/sec * 2 bits/cycle = 250,000 bits/sec
250,000 bits/sec / 40 bits/code = 6250 codes/sec
2^40 = 1,099,511,627,776 possible codes / 6250 codes/sec ~= 175,921,860 sec ~= 5.578 years
While this is still an extremely long time for the worst case, by the looks of other comments, as well as the author's video, it appears extremely doubtful that most RFID readers have anywhere near 40 bits of security - and it takes about 10 seconds (65536/6250) for the fuzzer to brute force all codes 16 bits or less.
The small amount of IT security work I've done has taught me that such hopes are quickly and frequently dashed. Even products specifically designed for security applications have silly glaring vulnerabilities.
However most keycard systems in the real world use a dumb unencrypted card that broadcasts an ID. This is vulnerable to sniffing, cloning as well as bruteforce (as this project demonstrates).
Modern fare systems (Vancouver Compass for example) use the DESfire EV1 and it's as secure as it gets.
The issue in their case was that 1) they didn't set the configuration of the card properly, so the blocks they were using weren't actually configured to be decrement only, and 2) the validation machines checked whether a card had enough trips and then decremented the block without checking whether the decrement was successful. I was able to make the remaining fares block read-only while the card was full, essentially making an infinite card.