Surely this is massively vulnerable to double spend attacks?
Surely this is massively vulnerable to double spend attacks?
FeliCa uses mutual authentication with eventual bookkeeping and sync. I believe that there are some theoretical attacks on older cards but the terminals are regularly synchronized and get a ban list. In-practice, you’ll also be reported to the police, probably.
So to execute the double spend you would have to find an authorized card provider, convince them to load and sign your double spend-capable program onto the smartcard (with their signature!), and then be found out within a week when reconciliation is off.
So doing a double spend will be found out, and not only will you be on a bunch of cameras doing the thing, whoever made your card will also have been compromised.
I think that in practice the "eventual" reconciliation is fairly quick nowadays. Just that the offline spend can happen quickly, and then the packet gets sent over the wire maybe a minute later rather than before the spend is approved.
This is definitely the case, and it's also "relatively instant" in the happy path. There are cases like vending machines, or during system outages where the reconciliation happens much later, but those instances are definitely becoming rarer!
...And as you expect it is vulnerable to double spend attacks. Hilariously the vulnerability was revealed in 2014 and nothing has been done to mitigate it. Yes, you can double spend in Taiwan today if you don't mind risking jail time.
From my (rudimentary) understanding of CAP, there is no prefect solution to this. I wonder how Japan handles it.
Much easier than double spending would be to use a student or other reduced fare card.