August 12, 2008 10:34 PM PDT

MIT students: Mass. agency 'misrepresents' what led to lawsuit

by Declan McCullagh
  • Font size
  • Print
  • 3 comments

Three MIT students are disputing the Massachusetts transit agency's version of the events that led to the state filing a lawsuit last week--and obtaining a restraining order against their talk on subway card security scheduled for Sunday.

The latest dispute originates in comments made by to CNET News by Massachusetts Bay Transportation Authority spokesman Joe Pesaturo in in a report published Monday. In his e-mail to us, he said the students "agreed to provide the MBTA with a copy of the presentation" scheduled for the Defcon hacker conference on Sunday but never did.

A response posted Tuesday by the Electronic Frontier Foundation, which is representing the students, said MBTA "misrepresents" the situation:

After the Monday meeting, the students understood that the MBTA's concerns were resolved, and that the students were to provide a confidential vulnerability assessment by the end of the week. Contrary to the MBTA statement, the students did not believe that the MBTA wanted to see a copy of the presentation slides, and they did not agree to provide them to the MBTA.

(It is undisputed that the students--Zack Anderson, R.J. Ryan, and Alessandro Chiesa--wrote a separate analysis (PDF) for the MBTA marked "confidential" and presented it to the agency.)

Opposing parties in lawsuits often tell different stories. Human memories are imperfect. People may honestly remember the same sequence of events differently. So why is this particular dispute important?

One reason is that the judge in this lawsuit has until August 19 to renew the restraining order (by turning it into a preliminary injunction) or let it expire. Whoever can reasonably claim to have acted in good faith will have a better chance of prevailing.

It's unclear who's telling the truth; if the lawsuit continues, e-mails and spoken testimony will probably answer these questions. But it does seem likely that the MBTA requested a copy of the Defcon presentation--they knew it was scheduled; why would they not want to see it?--and never received it. The defendants would have had a very good reason for this; the slides are prepared with a hacker audience in mind and include warnings like "AND THIS IS VERY ILLEGAL!"

Oops. This is what lawyers call an "admission against interest."

Another bit of unresolved intrigue is that the MBTA told us on Monday that it wanted to meet with the students again. EFF has steadfastly refused to say whether it would consider such a meeting--making it, uncharacteristically, even less forthcoming than a bunch of government bureaucrats.

[Update: See our related story on a court hearing scheduled for Thursday in this case, and what both sides plan to ask the judge.]

Declan McCullagh, CNET News' chief political correspondent, chronicles the intersection of politics and technology. He has covered politics, technology, and Washington, D.C., for more than a decade, which has turned him into an iconoclast and a skeptic of anyone who says, "We oughta have a new federal law against this." E-mail Declan.
Recent posts from Security
Kingston flash drives suffer password flaw
Q&A: Researcher Karsten Nohl on mobile eavesdropping
RockYou sued over data breach
Hacker Gonzalez pleads guilty in Heartland breach
Microsoft rebuts IIS vulnerability claims
More attacks expected on Facebook, Twitter in 2010
GSM crypto code cracked, engineer says
Web-based Lookout protects mobile devices, data
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
by kodybryson August 12, 2008 11:38 PM PDT
Um, what would the EFF or the students have to gain from another meeting? If I were involved in a serious lawsuit with someone I'd probably be vary wary of meeting with the out of court too. It's the same reason defense lawyers don't have their clients testify. There's a lot to lose and not much to gain.

Being forthcoming is not a goal when there's a potential criminal lawsuit. And if they have to choose between the appearance of guilt and a guilty verdict, they, like most people, will chose the appearance a guilt any day.

Hold it, I just reread that. Are you actually upset because the EFF has not told you personally whether they would _consider_ a meeting? Well, I'll give you that answer: yes they are considering it. Whether they do it or not remains to be seen.
Reply to this comment
by declan00 August 13, 2008 1:12 AM PDT
You're mistaken: If a meeting makes the lawsuit go away, and there are no other downsides, it's an option that should be on the table.

See our related story for how this is likely to play out, though.
by benjaminstraight August 13, 2008 8:16 AM PDT
Here comes the attempts to persuade a public opinion.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right