TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Activists release code to generate free public transportation tickets in U.K

117 pointsby balokiover 5 years ago

12 comments

stevecatover 5 years ago
I&#x27;ve used these apps before in the UK, and it is great being able to generate a ticket offline, but it appears they&#x27;ve achieved that by including the private keys in the app. Oh dear.<p>Would there be any fool proof alternative to allow for offline ticket creation in a mobile app when that app can be reverse engineered?
评论 #20858422 未加载
评论 #20858508 未加载
评论 #20858191 未加载
评论 #20858178 未加载
评论 #20858490 未加载
评论 #20858400 未加载
评论 #20859289 未加载
评论 #20858866 未加载
评论 #20862781 未加载
Jonnaxover 5 years ago
&quot;The reason we’ve decided not to go down the responsible disclosure path is being strong believers in public transportation being a common good that should be free for everyone, and this research is our contribution to get us closer to that end.&quot;<p>This is trolling, right?
评论 #20859073 未加载
评论 #20858846 未加载
评论 #20858746 未加载
评论 #20858811 未加载
评论 #20861623 未加载
afarrellover 5 years ago
If this is activism, what is political goal here? It seems like all this does is enable people with a highly-paid skill (accessing tor, then deploying&#x2F;running scripts) to not pay for transport.
评论 #20858748 未加载
评论 #20858599 未加载
T3OU-736over 5 years ago
Technical cock-up aside, why the term &quot;activists&quot;?<p>Not questioning the title of the HN post, rather, wondering if I missed something going on I have missed in the news which would justify the term (instead of &quot;hackers&quot; or, even &quot;security researchers&quot;, though the later seems to stretch the definition of responsible disclosure)
评论 #20859191 未加载
fredleyover 5 years ago
Seems like they baked secrets into their app bundle (RSA keys). Basic engineering fuckup.
评论 #20858663 未加载
评论 #20859629 未加载
gnufxover 5 years ago
People complaining might note that there is already a free bus service in central Manchester: <a href="https:&#x2F;&#x2F;tfgm.com&#x2F;public-transport&#x2F;bus&#x2F;free-bus" rel="nofollow">https:&#x2F;&#x2F;tfgm.com&#x2F;public-transport&#x2F;bus&#x2F;free-bus</a>
tomglynchover 5 years ago
I&#x27;ve run the app through Immuniweb to see if the keys show up. There&#x27;s quite a few issues but I don&#x27;t see the private keys.<p>Link here: <a href="https:&#x2F;&#x2F;www.immuniweb.com&#x2F;mobile&#x2F;?id=hprUh4hL" rel="nofollow">https:&#x2F;&#x2F;www.immuniweb.com&#x2F;mobile&#x2F;?id=hprUh4hL</a>
boomskatsover 5 years ago
Ahh, this reminds me of BT Cellnet storing those first pay-as-you-go credit ledgers locally on the Philips C12 &#x2F; Diga handsets, and just hoping nobody would notice.
mehhover 5 years ago
So who was the developer of this app, I assume the transport company outsourced it?
评论 #20859092 未加载
CodeBiscuitover 5 years ago
Looks like it&#x27;s been removed, anyone take a copy of the post?
评论 #20859130 未加载
评论 #20859128 未加载
Smithaliciousover 5 years ago
Holy mother of entitlement. Taking something without paying for it because you think it should be free isn&#x27;t activism, it&#x27;s, well, theft.
bradleyjgover 5 years ago
I’m sympathetic to the idea that public transit should have means tested fares, but outright free is a bad idea. It costs something to provide, quite a bit actually, and has limited capacity so there needs to be some mechanism to gate access. Price, which forces users to consider trade-offs, is the most straightforward way to do so.
评论 #20858886 未加载