Hacker News new | ask | show | jobs
by geebee 1405 days ago
Isn't there a hack/scam where you could (in the absence of a same-station charge) pay less or nothing to ride bart?

I remember people talking bout this ages ago (like, 20 years ago). You keep two bart cards going, and use the same one to enter and leave the same station. If there's a same-station charge, you can use it to enter/leave a nearby station, avoiding the higher fee for longer trips.

Is there a possibility that the same-fare charge is kept around to prevent this hack?

3 comments

> Isn't there a hack/scam where you could (in the absence of a same-station charge) pay less or nothing to ride bart?

Well, if you have someone going the opposite route, you could swap tickets at either endpoint (or at a transfer station in between.)

> Is there a possibility that the same-fare charge is kept around to prevent this hack?

I'm pretty sure that's why the excursion fare exists.

Wouldn't a time check fix this? Enter/leave within 10 minutes, no charge. Enter/leave outside 10 min window, charge the exclusion fee.
Tap/swipe in with one card, tap swipe out with the same card but don't actually leave. Hand the card to your buddy who swipes in and enters with you. Do the same thing on exit. You can then have as many people as you want travel for the cost of one.
A technological countermeasure would be to make it like an airlock - you have to get through the first set of gates (which won't let you return), and then have to tap your card to pass the second gate to finally exit.

Obviously, this is not a realistic solution - building new exit gates is simply not worth it.

Practically, such behavior if done repeatedly can be detected as an anomaly in card usage patterns, and a human reviewer can surely figure out what you're doing.

Blocking exit gates are a safety issue even under what would otherwise be normal operating conditions (e.g., no declared threat).

Absent some sort of ranged tag detection (e.g., NFC or RFID), exit determination is exceedingly difficult. I'd argue that NFC/RFID operating beyond a few cm range are themselves a major infosec threat and privacy invasion.

You can trivially jump the fare gates. BART fares are enforced by inspectors checking proof-of-payment; if your group was stopped they’d be caught out by only having one card with an active trip.
I've seen somewhere an analysis of which station pairs this works on. It was either for BART or the Washington Metro, both of which have distance-based fares. (This is amazingly ungooglable.)