• On TechRepublic: Five super-secret features in Windows 7
August 18, 2008 9:26 AM PDT

MIT student defends MBTA hacking research

by Jim Kerstetter
  • Font size
  • Print
  • 6 comments

After he's done with his security dust up with the Massachusetts Bay Transportation Authority, Zack Anderson plans on slightly different work: A company that turns heat from a car's shock absorbers into energy for the car's engine.

Hopefully, a government agency won't take offense to that work, as well.

Anderson is one of three Massachusetts Institute of Technology students who were blocked by the MBTA and a judge's order from making a presentation on vulnerabilities in the T's card-based fare system at the recent Defcon conference in Las Vegas. They're still blocked from making that presentation under a gag order that expires Tuesday. A hearing will be held in federal court in Boston Tuesday morning to determine whether the temporary restraining order should be converted into a preliminary injunction.

In an interview with the The Boston Globe, Anderson defended the presentation the students planned to make at Defcon. "It wasn't to enable others to get a free fare or cause any sort of havoc," Anderson told The Globe. "It was really to show how major the issues are in this system, which also might resonate in many other systems around the world."

The MBTA, not surprisingly, doesn't seem so willing to participate in this particular scientific discourse. In a hearing last week, a federal judge ordered the students to hand over classroom material and any correspondence they've had with Defcon organizers. The students have already provided the judge and T officials with two reports, including a 30-page paper that included details the students say they didn't intend to reveal in their Defcon talk.

The students and the MBTA are still fighting over what documents they should have to reveal, including unpublished research notes.

Jim Kerstetter has been writing about the high-tech industry for more than 13 years, as a senior editor at PC Week, a Silicon Valley correspondent at BusinessWeek, and now an executive editor at CNET News. He moved back to Boston because he missed the Red Sox. E-mail Jim.
advertisement
Click Here
Recent posts from Security
IBM buys database security firm Guardium
Microsoft actively urges IE 6 users to upgrade
Microsoft investigating 'black screen of death'
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
by tekwiz4u August 18, 2008 12:58 PM PDT
I think the MIT students should be restrained on this. I know that you might find it objectionable, but its within reason. They are exploiting a secret that constitutes the security of a public system. I cant imagine if a terrorist got a hold of this exploit and use it to his advantage, posing a great threat.

I'm all for free speech, but this really steps the line with public security then bragging rights.
Reply to this comment
by Dalkorian August 18, 2008 3:30 PM PDT
by tekwiz4u August 18, 2008 12:58 PM PDT
I cant imagine if a terrorist got a hold of this exploit and use it to his advantage, posing a great threat.
------------------------------------------------------
Care to elaborate on that? What "threat" can a "terrorist" pose by getting free rides on a subway? Better yet, how can we avert that threat by keeping it secret from the public in general? Do you really think "terrorists" learn their trade by reading newspapers?

The MBTA is only trying to cover their own butts. They spent millions on an insecure system and they don't want anyone to criticize them for it. They want to fix the problems - now that it's made the news. But before then they weren't to concerned about it, were they.
by mementh August 18, 2008 8:21 PM PDT
sorry but your wrong.. the info is *ALREADY* out there. its just not "released".
its like the dns bug.. once someone KNEW there was a bit.. it was EASY and trivial to figure it out (and this was not knowhing squat about the bug)


So think about that and i hope you realize... if terrorist wanted it.. they would have it already.
by Snowboardb86 August 18, 2008 3:40 PM PDT
I understand what the students are saying but they went about it the wrong way. I do however also think when you say if it gets in the hands of terrorists that this can be a safety issue is ridiculous. If a terrorist wants to ride the subway I don't think they will spend thousands of dollars to hack the fare card so that then they can add the $2.50 fare. That is ridiculous. With the money it costs to buy the tools you need, you can pay for subway fare for a year. I don't know that they should have had a gag order put on them but being that this is a real issue with the transportation system I think that the MBTA needs to be a little less up tight and at least listen to them and try to resolve the issue.
Reply to this comment
by Perry_Clease August 18, 2008 4:14 PM PDT
" If a terrorist wants to ride the subway I don't think they will spend thousands of dollars to hack the fare card so that then they can add the $2.50 fare."

A reason could be so that they couldn't be tracked as they cased the system. Providing that the MBTA has a way of tracking a pass to a particular person.

All of that aside I feel that the MBTA is more concerned about the loss of revenue if the sale of pirated passes becomes rampant. Playing the terrorism card is just way of getting the court order.
Reply to this comment
by eyemroot August 26, 2008 10:10 AM PDT
This whole issue really weighs on my mind considering the industry ramfications. Jon Longoria wrote an interesting, albeit brief, article regarding the plausible thought process MBTA took going into this. You can check it out here: http://thereformed.org/2008/08/25/mbta-put-profit-before-security/
Reply to this comment
(6 Comments)
  • prev
  • 1
  • next

S.F. hacker space: Heaven for the DIY set?

The Noisebridge hacker space offers sewing and Mandarin classes, soldering workshops, Internet-controlled front door access, and a server room with no door.
• Photos: Circuits, code, community

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right