• On TechRepublic: Why VISTA HATERS will love Windows 7
December 23, 2008 2:09 PM PST

MIT students to help Boston secure subway fare system

by Elinor Mills

MIT students Alessandro Chiesa, R.J. Ryan, and Zack Anderson show up at, but do not speak at, the Defcon conference in August.

(Credit: Declan McCullagh/News.com)

Three MIT students who were sued by the Massachusetts Bay Transit Authority over their research into subway card vulnerabilities are now working with the transit authority to improve the fare collection system.

The lawsuit against the students was dismissed after a judge lifted a gag order in August that prevented the students from discussing their work. The students had planned to present their research at the Defcon hacker conference in Las Vegas on August 10, but canceled their presentation after a judge granted the MBTA's request for an injunction the day before.

"This is a great opportunity for both the MBTA and the MIT students. As we continue to research ways to improve the fare system for our customers, we appreciate the cooperative spirit demonstrated by the MIT students," MBTA General Manager Daniel Grabauskas said in a statement published on the Electronic Frontier Foundation Web site on Monday. EFF attorneys represented the students in their legal defense.

One of the students, Zack Anderson, was quoted as saying: "We've always shared the goal of making the subway as safe and secure as can be. I am glad that we can work with the MBTA to help the people of Boston, and we are proud to be a part of something that puts public interest first."

As part of their presentation, entitled "The Anatomy of a Subway Hack: Breaking Crypto RFIDs and Magstripes of Ticketing Systems," the students planned to describe several attacks to break the CharlieCard, an RFID card that the MBTA uses on the Boston T subway line.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Report: Problems stymie U.S. cyberspy protection
Symantec's Ramzan on solving the antivirus puzzle
Apple fixing iPhone SMS security hole
Waledac worm targeting July 4 spam offensive
ATM vendor gets security talk pulled from conferences
Postini: Google's take on e-mail security
Botnets lead the way for spam
Stallman warns of Mono 'risk'
Add a Comment (Log in or register)
by myles taylor December 24, 2008 7:15 AM PST
That's cool. It's just counterproductive for the MBTA to sue them when the students weren't actually trying to circumvent the system. They could have just kept it quiet and waited for someone to take advantage of the flaws.
Reply to this comment
by Identity-Theft-Speaker December 26, 2008 5:08 AM PST
Hacking is not a dirty word as the MBTA would have the public believe. www.IDTheftSecurity.com
Reply to this comment
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right