Close Menu
  • Home
  • Crypto News
  • Tech News
  • Gadgets
  • NFT’s
  • Luxury Goods
  • Gold News
  • Cat Videos
What's Hot

$599 MacBook Neo for Students: Specs, Tradeoffs, and Best Uses

March 8, 2026

Funniest Cats and Dogs Clips 2026😼🐶Try Not To Laugh😜 Part 1

March 8, 2026

🔴 24/7 LIVE CAT TV NO ADS😺 Awesome Red Squirrels and Adorable Little Birds Forest Nut Party for All

March 8, 2026
Facebook X (Twitter) Instagram
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
KittyBNK
  • Home
  • Crypto News
  • Tech News
  • Gadgets
  • NFT’s
  • Luxury Goods
  • Gold News
  • Cat Videos
KittyBNK
Home » NYC subway security flaw makes it possible to track riders’ journeys
Tech News

NYC subway security flaw makes it possible to track riders’ journeys

August 30, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
NYC subway security flaw makes it possible to track riders’ journeys
Share
Facebook Twitter LinkedIn Pinterest Email

The contactless payment system for New York City’s subways has a security hole. Anyone with access to someone’s credit card number can see when and where they entered the city’s underground transit during the last seven days. The problem lies in a “feature” on the website for OMNY, the tap-to-pay system for the Metropolitan Transportation Authority (MTA), which allows you to view your recent ride history using only credit card info. Further, subway entries purchased using Apple Pay — which gives merchants a virtual number instead of your real one — still somehow link to your physical credit card number.

The MTA’s loose implementation could allow stalkers, abusive exes or anyone who hacks into or purchases a person’s credit card information online to find out when and where they typically enter the subway. Joseph Cox of 404 Media initially reported on the story, detailing how (with a rider’s consent) he tracked the stations they entered — with corresponding times. “If I had kept monitoring this person, I would have figured out the subway station they often start a journey at, which is near where they live,” Cox wrote. “I would also know what specific time this person may go to the subway each day.”

“This is a gift for abusers,” Eva Galperin, the Electronic Frontier Foundation’s director of cybersecurity, told Engadget. The OMNY website also allows passengers to create a password-protected account, but it sits below the more prominent “Check trip history” section atop the page, requiring only a number and expiration date without any further security input. “It is a real problem that the option to track your location — without any kind of password security — is available first on the website,” noted Galperin. She says the MTA could have “fixed this simply” by including a PIN or password requirement alongside the credit card field.

Metropolitan Transportation Authority

The website still shows your travel history even if you paid with Apple Pay. The iPhone maker says its tap-to-pay system gives merchants a virtual number rather than the physical card’s number. “And when you pay, your card numbers are never shared by Apple with merchants,” a marketing blurb on the company’s website reads. But an Engadget staffer confirmed that entering their actual credit card number linked to the used Apple Pay account — without having directly used that card to ride — still revealed their seven-day point-of-entry history.

When asked about the OMNY website linking the two regardless, the MTA told Engadget it can’t see the credit card numbers of customers who use Apple Pay. Apple didn’t immediately respond to an emailed request for comment about how the MTA website associates the two without vendors having access to the physical credit card number.

The MTA says it will consider security changes as it improves its system. “The MTA is committed to maintaining customer privacy,” MTA spokesperson Eugene Resnick wrote to Engadget in an email. “The trip history feature gives customers a way to check their paid and free trip history for the last 7 days without having to create an OMNY account. We also give customers the option of paying for their OMNY travel with cash. We’re always looking to improve on privacy, and will consider input from safety experts as we evaluate possible further improvements.”

Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Galaxy S26 Ultra, Galaxy Buds 4, Dell XPS 14 and more

March 7, 2026

Samsung Galaxy Buds 4 and 4 Pro review: Impressive audio, imperfect ANC

March 6, 2026

Possibly the most charming Pokémon game yet

March 6, 2026

A beautiful laptop that excels at almost everything… except typing

March 6, 2026
Add A Comment
Leave A Reply Cancel Reply

What's New Here!

Despite Lagging 42% Behind the Bitcoin Rally, Ethereum Is Set to Dominate the Next Market Cycle—Here’s Why!

October 29, 2025

Every New Car That Has An Inline-Six Engine In 2024

June 30, 2024

The Morning After: Apple reveals its new cheapest iPhone. What’s missing?

February 21, 2025

THE MYTHERESA X FLAMINGO ESTATE HOLIDAY HOUSE

November 22, 2023

Ethereum Crash! ETH To Reclaim $2.8K Or Plunge To $2.2K?

August 28, 2024
Facebook X (Twitter) Instagram Telegram
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA
© 2026 kittybnk.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.