I Tracked an NYC Subway Rider's Movements with an MTA ‘Feature’
404media.co
404media.co
It echoes the well documented privacy issues that OMNY has over the years. [0][1]
[0] https://www.stopspying.org/omny [1] https://www.fastcompany.com/90788367/the-mtas-switch-to-omny...
Joseph Cox from 404 Media did a stellar job investigating and contacting the MTA & Apple - it even looks like the MTA will re-evaluate their stance.
I predict/hope they’ll remove the public trip history page [0] soon. Forcing users to create an account wouldn’t make anything more secure as you could still add any other person’s card to your account… adding a verification of the credit card’s billing address would also be pretty ineffectual. Unsure of what to do (except not offer this feature).
See this past conversation (and detailed tech explanation) here some months ago [1].
404 Media found that MTA’s trip history feature still works even when the user pays with Apple Pay. Apple told 404 Media it does not store or have access to the used card numbers, and does not provide these to merchants, including transit systems. Apple did not respond when asked to clarify how the MTA website feature works when a rider uses Apple Pay.
Per https://www.apple.com/apple-pay/ marketing, "When you make a purchase, Apple Pay uses a device-specific number and unique transaction code. So your card number is never stored on your device or on Apple servers. And when you pay, your card numbers are never shared by Apple with merchants. Your purchases stay private."
So something strange is going on for sure...
https://news.ycombinator.com/item?id=35698169
TLDR: Omny gets a hash of the Apple Pay card, and later, they can one way hash a card (that you give them) and match it to past purchases/travels. They (OMNY/MTA) presumably do not have access to the original card number that Apple Pay is 'masking'.
But I agree with you that the language on Apple's site makes it seem like it's more anonymous than it really is (as this hash exception makes obvious)
While the OMNY "Trip history" feature would make it even trivial (it's not unheard of for ex-parterns to have seen each other's credit cards during the relatinoship) for someone to stalk their ex's movements, I'm also thinking that requiring an OMNY account would be a minor friction point for a bad actor. Assuming most OMNY users don't register an account, a stalker who knows their ex's credit card number could simply create an OMNY account using any email address they want — in the scenario where their ex never registered their OMNY card with an account.
A complicated situation...I guess one compromise could be for OMNY to only give access to the Trip History feature for registered users. After all, if we can assume most subway riders don't want to bother with an OMNY account, we might also assume most don't need to check their own trip history. In the case of a financial dispute, they can bring their card to a subway teller in person (yes this creates a hassle, but everything security-related has tradeoffs)