Police hackers

Peter Gutmann pgut001 at cs.auckland.ac.nz
Sat, 16 Mar 2002 13:10:14 +1300 (NZDT)


"Peter Tomlinson" <pwt@iosis.co.uk> writes:

>Our local bus company started 2002 by issuing season tickets with expiry dates
>in 2004. Mag stripe tickets, they don't allow you to read the exp date on the
>stripe for yourself. It was blamed on a software error in the ticket machines.

I did a straw poll of PC time problems for a paper on problems with crypto
implementation, the worst-case time I found was a PC with a clock several
decades out of step (the owner hadn't noticed until then).  More common errors
are tens of minutes (clock drift), hours and days (time zones, DST, etc), and
various weeks or months.  The conclusion was that in an environment of Windows
machines, relying on timestamps in certificates for validity checks was, uh,
wishful thinking.

Peter.