On the Struggle Bus: A Detailed Security Analysis of the m-tickets App

Jorge Sanz Maroto, Haoyu Liu, Paul Patras

Research output: Chapter in Book/Report/Conference proceedingChapter

Abstract

The growing shift from private to public transportation and the increasing use of smartphones have lead to the development of digital transport ticketing systems. Such systems allow transport operators to enhance their services and income, therefore are important assets that require secure implementation and protocols. This paper uncovers a range of vulnerabilities in the m-tickets app used by Lothian Buses, one of the leading transport operators in the United Kingdom (UK). The vulnerabilities identified enable attackers to predict, reactivate and modify tickets, all of which can have damaging consequences to the operator’s business. We further reveal poor implementation of encryption mechanisms, which can lead to information leakage, as well as how adversaries could harness the operator’s infrastructure to launch Denial of Service attacks. We propose several improvements to mitigate the weaknesses identified, in particular an alternative digital ticketing system, which can serve as a blueprint for increasing the robustness of similar apps
Original languageEnglish
Title of host publicationInformation Security (ISC 2020)
EditorsWilly Susilo, Robert H. Deng, Fuchun Guo, Yannan Li, Rolly Intan
PublisherSpringer
Pages234-252
Number of pages17
ISBN (Electronic)978-3-030-62974-8
ISBN (Print)978-3-030-62973-1
DOIs
Publication statusPublished - 25 Dec 2020
Event23rd Information Security Conference - Virtual Conference
Duration: 16 Dec 202020 Dec 2020
https://isc2020.petra.ac.id/

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume12472
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference23rd Information Security Conference
Abbreviated titleISC 2020
CityVirtual Conference
Period16/12/2020/12/20
Internet address

Keywords / Materials (for Non-textual outputs)

  • Mobile app security
  • Reverse-engineering
  • Information leakage

Fingerprint

Dive into the research topics of 'On the Struggle Bus: A Detailed Security Analysis of the m-tickets App'. Together they form a unique fingerprint.

Cite this