How to Crack Mifare Classic Cards
firefart.at
firefart.at
When you tap the card on the reader the transaction happens locally with the card and the reader, this means that there is no latency and the system can continue to operate even if the central server goes down.
Every minute or so the machines sync with a central server and if at any point a machine saw a card with a balance or journey history that conflicted with the server copy then that card gets blacklisted and no machine will accept it any more. This means if you clone a card you can use it to start your journey but by the time you get to your destination you won't be able to get out.
I had heard that the OrcaCard system had an issue early on where a number of cards were disabled as a result of a TVM not being synced back to the database. There certainly was a large number of completely dead cards for a couple of weeks in 2010.
[0] http://en.wikipedia.org/wiki/OV-chipkaart [1] http://www.computable.nl/artikel/ict_topics/security/2735292...
* Perhaps even using the UID combined with some encrypted data on card, as the UID can be changed on questionable mifare cards.
Of course, this does not prevent cloning with chinese knockoffs where the UID can be overwritten.