• On TechRepublic: Five super-secret features in Windows 7
August 18, 2008 9:26 AM PDT

MIT student defends MBTA hacking research

by Jim Kerstetter

After he's done with his security dust up with the Massachusetts Bay Transportation Authority, Zack Anderson plans on slightly different work: A company that turns heat from a car's shock absorbers into energy for the car's engine.

Hopefully, a government agency won't take offense to that work, as well.

Anderson is one of three Massachusetts Institute of Technology students who were blocked by the MBTA and a judge's order from making a presentation on vulnerabilities in the T's card-based fare system at the recent Defcon conference in Las Vegas. They're still blocked from making that presentation under a gag order that expires Tuesday. A hearing will be held in federal court in Boston Tuesday morning to determine whether the temporary restraining order should be converted into a preliminary injunction.

In an interview with the The Boston Globe, Anderson defended the presentation the students planned to make at Defcon. "It wasn't to enable others to get a free fare or cause any sort of havoc," Anderson told The Globe. "It was really to show how major the issues are in this system, which also might resonate in many other systems around the world."

The MBTA, not surprisingly, doesn't seem so willing to participate in this particular scientific discourse. In a hearing last week, a federal judge ordered the students to hand over classroom material and any correspondence they've had with Defcon organizers. The students have already provided the judge and T officials with two reports, including a 30-page paper that included details the students say they didn't intend to reveal in their Defcon talk.

The students and the MBTA are still fighting over what documents they should have to reveal, including unpublished research notes.

Jim Kerstetter has been writing about the high-tech industry for more than 13 years, as a senior editor at PC Week, a Silicon Valley correspondent at BusinessWeek, and now an executive editor at CNET News. He moved back to Boston because he missed the Red Sox. E-mail Jim.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
by tekwiz4u August 18, 2008 12:58 PM PDT
I think the MIT students should be restrained on this. I know that you might find it objectionable, but its within reason. They are exploiting a secret that constitutes the security of a public system. I cant imagine if a terrorist got a hold of this exploit and use it to his advantage, posing a great threat.

I'm all for free speech, but this really steps the line with public security then bragging rights.
Reply to this comment
by Dalkorian August 18, 2008 3:30 PM PDT
by tekwiz4u August 18, 2008 12:58 PM PDT
I cant imagine if a terrorist got a hold of this exploit and use it to his advantage, posing a great threat.
------------------------------------------------------
Care to elaborate on that? What "threat" can a "terrorist" pose by getting free rides on a subway? Better yet, how can we avert that threat by keeping it secret from the public in general? Do you really think "terrorists" learn their trade by reading newspapers?

The MBTA is only trying to cover their own butts. They spent millions on an insecure system and they don't want anyone to criticize them for it. They want to fix the problems - now that it's made the news. But before then they weren't to concerned about it, were they.
by mementh August 18, 2008 8:21 PM PDT
sorry but your wrong.. the info is *ALREADY* out there. its just not "released".
its like the dns bug.. once someone KNEW there was a bit.. it was EASY and trivial to figure it out (and this was not knowhing squat about the bug)


So think about that and i hope you realize... if terrorist wanted it.. they would have it already.
by Snowboardb86 August 18, 2008 3:40 PM PDT
I understand what the students are saying but they went about it the wrong way. I do however also think when you say if it gets in the hands of terrorists that this can be a safety issue is ridiculous. If a terrorist wants to ride the subway I don't think they will spend thousands of dollars to hack the fare card so that then they can add the $2.50 fare. That is ridiculous. With the money it costs to buy the tools you need, you can pay for subway fare for a year. I don't know that they should have had a gag order put on them but being that this is a real issue with the transportation system I think that the MBTA needs to be a little less up tight and at least listen to them and try to resolve the issue.
Reply to this comment
by Perry_Clease August 18, 2008 4:14 PM PDT
" If a terrorist wants to ride the subway I don't think they will spend thousands of dollars to hack the fare card so that then they can add the $2.50 fare."

A reason could be so that they couldn't be tracked as they cased the system. Providing that the MBTA has a way of tracking a pass to a particular person.

All of that aside I feel that the MBTA is more concerned about the loss of revenue if the sale of pirated passes becomes rampant. Playing the terrorism card is just way of getting the court order.
Reply to this comment
by eyemroot August 26, 2008 10:10 AM PDT
This whole issue really weighs on my mind considering the industry ramfications. Jon Longoria wrote an interesting, albeit brief, article regarding the plausible thought process MBTA took going into this. You can check it out here: http://thereformed.org/2008/08/25/mbta-put-profit-before-security/
Reply to this comment
(6 Comments)
  • prev
  • 1
  • next
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right