DC metro smartcard failure/exploit?

Anne & Lynn Wheeler lynn at garlic.com
Wed Mar 9 13:52:51 EST 2005

anybody hear of a DC metro (smartrip) smartcard failure/exploit?

you have a smartcard that supposedly has $10-something left ... and the 
next time you go to the station ... the turnstyle says "not acceptable, 
see stationmaster". the stationmaster puts the card in a reader and the 
display comes up and says the card has negative $5 balance. in theory, 
the transactions with the smartcard are encrypted (and possibly the 
values stored in the chip are also encrypted). somehow the card has had 
a failure/exploit that made it look like the card has a negative $5 balance?

