Bonum Certa Men Certa

GoTransit forces PRESTOCARD on transit commuters

Presto is WATCHING YOU

On June 1st 2012, Go Transit in the Greater Toronto Area started to phase out anonymous 2 ride and 10 ride paper based tickets. These 2 ride and 10 ride tickets would get stamped in a machine and it didn’t require giving Metrolinx your name and address or other personal information. You can still buy anonymous single ride and day passes but if you ride the bus every day this is a huge inconvenience and the price is higher. If you ride the bus every day you’re likely to opt-in to the PRESTOCARD system. The PRESTOCARD system is dangerous to your personal privacy because € it collects personal information that was never previously required to ride the bus. Personal information collected by the Government of Ontario is stored on computers running Microsoft Windows Server and is a blatant security risk.
Personal Information

Personal information that may be collected by PRESTO in connection with your use of the PRESTOCARD is recorded information that identifies individuals and may include:

a)€ € € € €  information relating to financial transactions in which you have been involved or will be involved with PRESTO, including your credit card number and your bank account information;

b)€ € € € €  any identifying number, symbol or other particular identifier assigned to you by PRESTO;

c)€ € € € € €  your address or telephone number;

d)€ € € € €  correspondence sent to PRESTO by you that is implicitly or explicitly of a private or confidential nature, and replies to that correspondence that would reveal the contents of the original correspondence; and/or

e)€ € € € €  your name where it appears with other personal information relating to you or where the disclosure of your name would reveal other personal information about you.

https://www.prestocard.ca/en/StaticContent/Privacy/
The claim from Metrolinx (whom owns Go Transit and Metrolinx) is that the information will only be used for a list of purposes although it says ‘among other things’ meaning the list is not complete:
PRESTO’s primary purpose for collecting your personal information is to provide the services and/or products requested by you. In addition, you agree that your personal information may be used, among other things, to:

a)€ € € € €  open and set-up your PRESTO Account;

b)€ € € € €  verify your identity and/or your eligibility for certain PRESTO Services;

c)€ € € € € €  mail to you your PRESTOCARD and other such items or communications;

d)€ € € € €  operate the PRESTO Services effectively;

e)€ € € € €  administer loyalty programs associated with the use of the PRESTO Services;

f)€ € € € € €  protect you and PRESTO from error and fraud

g)€ € € € €  better understand your needs and eligibility for products and services offered by PRESTO or the Service Providers;

h)€ € € € €  communicate to you those products and services that may be of interest to you;

i)€ € € € € € €  improve the products and/or services offered to you; and

j)€ € € € € € €  comply with legal and regulatory requirements.
What they do not list is the fact that the GO Transit system uses “tap on” and “tap off”. What this means is that you get on the bus, you tap your card and it makes a record that you boarded the bus. When you leave the bus you are required to “tap off” which makes a record that your trip ended. From a billing standpoint this means they keep track of your trip. They know where you get on the bus, and where you get off. This means the government (who owns Metrolinx) has your name & address, and can attach your trip information to their records and more readily build a personality profile on you.

The PRESTOCARD itself is RFID based and is read by an RFID reader on every bus. At some point the reader talks to head office, I suspect using WiFi communications. If anyone knows more about Presto and Wifi please leave a comment. I’ve discovered the Wifi prestocard client while on the bus using tools from the Aircrack-ng suite of utilities. My only guess is that this is how they update the billing records on the road.

Since Metrolinx is owned by the Government of Ontario, there will be no third party disclosure issues when handing the information over to the police, or other government agencies. When CCTV exists on Go Transit buses, facial recognition technology will get help via a list of names of people riding the bus since the trip is tracked for billing purposes. If you use your PRESTOCARD on Mississauga or Brampton Transit, it will already “out you” to CCTV. Not to mention the fact that the government will have information on your entire trip from start to finish. This information is valuable to the government and there are many uses. One of the more pragmatic things I can think of would be to give the government statistics it can use to market its incumbent political party to demographics more likely to vote for them.

What ever happened to the right to travel anonymously? Metrolinx, Go Transit and PRESTOCARD are all services that will remove this right and people will simply adapt before complaining. Those of us who don’t want to be tracked will stand out, we’ll get evil looks from bus drivers when we don’t tap on, and disgruntled looks from people waiting in line while people like me pay cash.

Comments

Recent Techrights' Posts

Free University of Bozen-Bolzano Proud to Host Free Software Talk by Richard Stallman
ahead of Monday's talk
Slopwatch: Anti-Linux Machine-Generated FUD (LLM Slop) From GBHackers, CybersecurityNews, and Guardian Digital, Inc (Google News Promotes Slop Plagiarism, Misinformation)
Companies that lie try to drown out the signal with falsehoods
 
Microsoft's Serial Strangler and Matthew J. Garrett Join Forces in Trying to Gag Techrights (for Exposing Microsoft Corruption and Crimes Against Women)
Whose terrible idea was it?
Links 22/02/2025: Labour Department Investigates Microsoft Infosys Amid Mass Layoffs, Large Law Firms Caught Red Handed With LLM Slop (Defrauding Clients and Courts)
Links for the day
Gemini Links 22/02/2025: Analog Stuff, Sigil, and SSGs
Links for the day
Microsoft's Market Share in Cameroon Falls to New Lows
This means a lot of Android users (iOS is about 4 times smaller), but Android does not mean freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 21, 2025
IRC logs for Friday, February 21, 2025
The Streisand Effect is Real
So don't be evil. Also, don't strangle women.
Links 21/02/2025: Linux Foundation Openwashing, Microsoft Copilot Goes Down
Links for the day
Links 21/02/2025: Doomscrolling and European Ham Radio Show
Links for the day
Links 21/02/2025: TikTok Layoffs, WebOS Software Patents in Bad Hands
Links for the day
Gemini Links 21/02/2025: Web Browsers, Mechanical Shortcuts, and Internet Hygiene
Links for the day
Richard Stallman 'Only' Founded the FSF
there's no reason to be upset at the FSF for keeping their founder in the Board
Techrights Disconnected From the United States Two Years Ago
Did people really need to wait for the US government to become this hostile towards the media before recognising the threat?
Before Trying Censorship by Extortion the Serial Strangler From Microsoft Literally Begged Us to Delete Pages
This is very clearly just a broad campaign of intimidation
Hype Watch: Weeks After Microsoft Disappointed Investors With "Hey Hi" It's Trying Some "Quantum" Hype (Adding Impractical Vapourware to Accompany This Hype and Even LLM Slop in 'News' Clothing)
Remember "metaverse"? What happened to media hype about "blockchain" and "IoT"?
Report About February Mass Layoffs at Microsoft (Third Wave of Microsoft Layoffs in 2025) Comes Back From the Dead
Yesterday we wrote about an article in CRN (reporting Microsoft layoffs) being removed without any reasons specified
Links 21/02/2025: Myanmar Scam Centre and Disruptions at USPTO
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 20, 2025
IRC logs for Thursday, February 20, 2025
gbhackers.com is Not Hackers, It's LLM Slop Outputs (Fake 'Articles') That Attack 'True Hackers'
A site called linuxsecurity.com keeps doing this and now we see the slopfarm gbhackers.com doing the same
Gemini Links 20/02/2025: Law of Warming and Cooling, Health, and Devlog
Links for the day
linuxsecurity.com Continues to Spread Lies or Machine-Generated FUD (Microsoft LLMs Likely the Source) About OpenSSH and Linux
this LLM problem is global
Links 20/02/2025: Microsoft Infosys Layoffs and IRS Layoffs (Good News for Rich Tax Evaders)
Links for the day
IBM Layoffs in Europe Already Happening or Underway (UK and Spain). They Try Not to Call These "Layoffs".
"CIO" in particular was repeatedly mentioned lately, as was Consulting
People Who Came From Microsoft Demanding Removal of Articles About Them, About Microsoft, and About Microsoft GitHub is "Generous" (According to Them)
Imagine choosing a law firm that borrows money in the same year just to avoid overdraft in the bank!
Possibly a Third Round of Mass Layoffs at Microsoft in 2025 ("Cloud Solution Architects, Customer Roles"), Report Removed or Censored
This is literally the top story for "microsoft layoffs" right now
Instead of 'DoS Protection' Cloudflare is Allegedly Conducting 'DoS Attacks' on Users of Browsers Other Than Firefox and GAFAM's DRM Sandboxes (Chrome, Safari and Others)
If you value the Web, you will avoid Cloudflare
Mixing Real With Fake in One 'Article' (by "Director of Content, Help Net Security")
From what we can gather, he got machines to generate some slop for him
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 19, 2025
IRC logs for Wednesday, February 19, 2025