FasTrak Toll Hacking: Dangerous Or Ridiculous?

A "Black Hat security researcher" claims he has discovered security flaws in the FasTrak toll transponder used by drivers in California and Colorado. However, the story is quickly dismantled as "baloney" by a toll road industry insider.

2 minute read

July 14, 2008, 2:00 PM PDT

By Chris Steins @planetizen


From the original article on the "Dark Reading" website:

"A Black Hat researcher recently reverse-engineered the popular RFID-based FasTrak toll tag that some drivers in the San Francisco Bay Area affix to their windshields for pre-paying highway tolls, and discovered some gaping security holes that leave these transponders vulnerable to sniffing, cloning, and surreptitious tracking of a driver's comings and goings. Nate Lawson, principal with Root Labs, will demonstrate at Black Hat USA next month in Las Vegas what he found inside those toll tags (hint: no encryption), and he will release an open-source tool for users to protect their toll tags from abuse."

From the evaluation by Toll Roads News, which concludes that the charge is dubious:

"Dark Reading reports: 'Lawson is also researching whether malware could be planted on a FasTrak transponder.' That sentence makes us think this guy Lawson is an amateur. The only "research" needed to establish whether anything could be planted on the FasTrak transponder is a visit to the website of the manufacturer...

If you cloned someone else's transponder account number you might put some tolls on someone else's account for a month or so, until the account holder saw the anomalous toll charges. Once notified, all the toll authority would have to do to catch you would be to program the violation cameras to retain pictures of the transactions on that account number, and they'd have you for fraud."

Thursday, July 10, 2008 in Toll Roads News

Rendering of electric scooters, electric cars, light rail train, and apartments in background.

Arizona’s ‘Car-Free’ Community Takes Shape

Culdesac Tempe has been welcoming residents since last year.

February 14, 2024 - The Cool Down

Aerial view of New York City architecture with augmented reality visualization, blue digital holograms over buildings and skyscrapers

4 Ways to Use AI in Urban Planning and City Design

With the ability to predict trends, engage citizens, enhance resource allocation, and guide decision-making, artificial intelligence has the potential to serve as planners’ very own multi-tool.

February 20, 2024 - ArchDaily

"It's The Climate" sign over street in Grants Pass, Oregon.

Oregon Town Seeks Funding for Ambitious Resilience Plan

Like other rural communities, Grants Pass is eager to access federal funding aimed at sustainability initiatives, but faces challenges when it comes to meeting grant requirements.

February 18, 2024 - The Daily Yonder

View from shore of Sepulveda Basin water catchment basin with marsh plants along shore.

LA’s ‘Spongy’ Infrastructure Captured Almost 9 Billion Gallons of Water

The city is turning away from stormwater management practices that shuttle water to the ocean, building infrastructure that collects and directs it underground instead.

February 25 - Wired

Front of an Spanish style bungalow with striped window awnings and a tree and yard landscaped with cacti.

‘Culinary Hubs’ Turn Homes Into Micro-Restaurants

Real estate developers around the country are converting old single-family homes into “culinary hubs,” reports The New York Times.

February 25 - The New York Times

Green rapid transit bus pulled into station in dedicated lane.

Indiana Once Again Considering Ban on Dedicated Transit Lanes

The proposed legislation would impact the construction of planned IndyGo Blue Line, the third phase of the city’s bus rapid transit system.

February 25 - Fox 59

Urban Design for Planners 1: Software Tools

This six-course series explores essential urban design concepts using open source software and equips planners with the tools they need to participate fully in the urban design process.

Planning for Universal Design

Learn the tools for implementing Universal Design in planning regulations.