> I wonder why people rolling out such systems never seem to see the obvious(?) writing on the wall:
The writing isn't at all obvious, otherwise they wouldn't have come up with it. I guess they've come to the conclusion that forging Oyster cash is similar to forging paper ticket or real cash. I don't know exactly how the Oyster card is implemented, but if it has some level of transaction log trail (however asynchronous), it's possible to detect forgeries (if you've only ever deposited £20, but since spend £100, you're cheating).
> Moreover I don't understand why they don't simply leverage the device that everyone already has in their pocket - the cellphone.
Scanning a barcode on a cellphone screen has three problems:
1: There are still loads and loads of cellphones not reliably capable of displaying a scannable barcode.
2: Barcodes are 100% copyable and include 0 cryptography - they have the same security as a barcode printed on a piece of paper, which, incidentally, is what they replace in airports.
3: A barcodes is read-only and requires online access to verify and record the transaction which is not feasible on the scale required for TfL.
Bluetooth has similar problems:
1: While most phones might be BT equipped, developing and supporting software for enough different phonemodels is very complex.
2: BT is designed for communication between specific devices, not a "class" of trusted devices. You can't trust all TfL checkpoints under one, so you'd have to navigate some sort of interaction every time you check in and out of a station/bus. Also, this interaction is different for each phone type = support hell.
3: BT is long range, compared to an RFID card. Sure, an RFID card might be skimmed from a difference, but it's easy for a reader to tell the card directly on the reader from every other card in the room. No so much for BT.
The solution including cellphones we need is NFC, which is basically RFID that can leverage the processing power of the cellphone. It just doesn't exist on very many phones yet.