this post was submitted on 31 Aug 2023
105 points (99.1% liked)

Privacy

29852 readers
1220 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

During all this monitoring, I wasn’t anywhere near the rider. I didn’t even need to see them with my own eyes. Instead, I was sitting inside an apartment, following their movements through a feature on a Metropolitan Transportation Authority (MTA) website, which runs the New York City subway system.

top 11 comments
sorted by: hot top controversial new old
[–] otter@lemmy.ca 12 points 10 months ago (4 children)
[–] seSvxR3ull7LHaEZFIjM@feddit.de 46 points 10 months ago (2 children)

With their consent, I had entered the rider’s credit card information—data that is often easy to buy from criminal marketplaces, or which might be trivial for an abusive partner to obtain—and punched that into the MTA site for OMNY, the subway’s contactless payments system. After a few seconds, the site churned out the rider’s travel history for the past 7 days, no other verification required.

From the article

[–] Pantherina@feddit.de 10 points 10 months ago

Credit cards are as secure as carrying your passwords around you on a piece of paper, and telling it loots of people always.

[–] otter@lemmy.ca 6 points 10 months ago

Thank you! I was on the bus and couldn't get the article to load

[–] atomicpeach@pawb.social 14 points 10 months ago (1 children)

From the article, you can get a detailed usage history of MTA transactions by simply supplying the credit card number (which they state can very often be bought on the dark web). The lack of identity confirmation to pull the report is the concern.

[–] UnverifiedAPK@lemmy.ml 1 points 10 months ago (1 children)

You want to force people to show ID to use the subway?

Why is this info even public? That's the real issue.

[–] zagaberoo@beehaw.org 3 points 10 months ago

Not to use the subway, to access a payment card's complete ride history.

[–] hatchet@sh.itjust.works 5 points 10 months ago

Credit card info -> see timestamped transit transacting history, including station name (location)

[–] yA3xAKQMbq@lemm.ee 2 points 10 months ago (1 children)
[–] otter@lemmy.ca -1 points 10 months ago
[–] library_napper@monyet.cc 7 points 10 months ago

This is why I always pickup someone's old card from the ground in a subway station and reload it with cash.

We need more metros that use paper mag swipe cards that cost less than a penny to produce, so they can be recycled anonymously in this way. RFID metro cards are cancer