Version: 2008

Comments on: Judge leaves gag order intact on subway card-hacking students

In a setback to Electronic Frontier Foundation, judge postpones decision on whether three MIT students can reveal "information" about security problems in Boston subway cards.

Add a Comment (Log in or register) (17 Comments)
  • prev
  • 1
  • next
by Michichael August 14, 2008 10:40 AM PDT
Wow, this is absolutely ridiculous. It's been accepted in Europe that it is not only a violation of basic rights, but a fallacy in security to restrict a researcher from presenting his findings on the RFID vulnerabilities. I'm smelling something incredibly fishy here between the "impartial" judge and Massachusetts, and I'm not one for conspiracy theories.
Reply to this comment
by DeltaBravo August 14, 2008 2:38 PM PDT
Nothing fishy here. Just a judge with a good sense of right and wrong. These "researchers", being spoiled brats, are trying to puff up their public image by harming an innocent company. If they wanted to practice free speech responsibly they would have revealed what they know to the company and offered to help correct the problem. If the company didn't do anything about it, after a reasonable period of time (which could take several months), then a public announcement would be appropriate.
by The_Decider August 14, 2008 4:44 PM PDT
Innocent?

The problems they found can only be explained by saying that MTBA is grossly incompetent.
by protagonistic August 14, 2008 10:47 AM PDT
What can I say, most judges in this country at that level are little more than political hacks. They do not even understand the concept of freedom anymore. I think it must be a requirement these days that to graduate from law school you have to prove you have eliminated the last vestige of common sense from your reasoning.
Reply to this comment
by DeltaBravo August 14, 2008 2:35 PM PDT
The judge understands the concept of freedom. The problem is that neither you nor these three spoiled brats understands the concept of responsibility.
by The_Decider August 14, 2008 4:31 PM PDT
It is the transit system avoiding responsibility.

The problem is that you don't seem to understand the issues. If you point out a fire hazard, would you expect to get a gag order? These kids found many fire hazards and should be commended.
by fdunn3 August 14, 2008 12:47 PM PDT
I think that the MBTA is afraid that the public will find out that the hack is being used on a daily basis and that they have done nothing about it.

The EFF should subpoena security records and ridership data on the T cards as I think they will find it interesting reading. (Such as duplicated cards.)

Only then will the MBTA back off as they know they have been busted.
Reply to this comment
by DeltaBravo August 14, 2008 2:33 PM PDT
While I have no problem with honest "hackers" uncovering vulnerabilities in software, I feel they have a moral obligation to notify the companies affected rather than make public revelations that can only serve to help others harm innocent individuals and companies. These guys are looking to puff themselves up in the eyes of others by hurting a company that doesn't deserve such treatment. They claim free speech rights but have no concept of free speech responsibility. One can not work without the other. I don't know if the Judge's decision can be upheld on appeal but these jerks need to grow up and MIT needs to do a better job of teaching their students something about morality and adulthood.
Reply to this comment
by aphoog August 14, 2008 2:52 PM PDT
Why are the students actions immoral? If you happen to keep all your money in a safe made of straw and I just happen to state that straw is combustible.... was I immoral or is the owner of the straw safe stupid?
by The_Decider August 14, 2008 4:34 PM PDT
MBTA deserves this. Look at the power point slides. A group of drunken monkeys could produce a more secure system.

Or do you think that it is OK to have critical network gear in a publicly accessible, unlock room?

In no way is finding and pointing out serious security issues is immoral. Some of what they did might be illegal, but not immoral.

Funny how people who rail against these kids are technically illiterate and can't grasp the magnitude of the flaws(some tech related, many not) were not fixed by MBTA.
by ktappe August 14, 2008 7:36 PM PDT
First, MBTA is not a "company", it is a publicly-owned service that is funded by taxpayers. No individual entity is being "hurt" by these students--they are attempting to perform a public service and bring about more security on that public service.
Second, they DID (if you read the article) submit a security brief to the MBTA over a week before the conference. So they did act morally.
Third, if the MBTA was aware of the security deficiencies in the system already, then it most certainly did deserve to be treated like this. Worse, in fact.
So lastly, these people are not "jerks" as you call them. They seem like they are performing an admirable, necessary function. Without them, would anyone currently be discussing the MBTA's security flaws?
by ghifarix August 14, 2008 4:01 PM PDT
For others to hack into any software program it shows up that program to be unfinished incomplete or the hack to be different or otherwise new perhaps superior. Therefore this Hack should not have been subjugate as a patent violation in any way for or manner. These MIT students are being repressed because the culture of monopoly reject competition-lets say improvement. If any thing moral were to show its principle head it should have been the owners of the old software negotiating with the creators of the new. The learned judge not only robed the MIT developers she simply said that America have reach the pinnacle of developing - gate closed- lets move on to China.
Reply to this comment
by The_Decider August 14, 2008 4:38 PM PDT
Not only that, many of the flaws were not technical at all. Leaving rooms with switches and routers unlocked and publicly accessible, is one example. Turnstile boxes were found unsecured. Crap like that.

Every executive and employee that has anything remotely to do with security should be fired and jailed for violating the public trust in such an incompetent manner.
by LarryLarryLarryLarry August 14, 2008 4:32 PM PDT
The students' report is online. I read the 87 page pdf file yesterday. I won't say where, because then I'm the bad guy, but hmmm, if you wanted to find some supressed document, what is the most obvious website that would show such a document?
Reply to this comment
by KenHaggerty August 14, 2008 10:12 PM PDT
It's surprisingly easy to hack the subway system and actually works for multiple subway systems. I read through the file and even as an architecture student I could understand it. I agree that the MBTA maybe should have had prior notice as a courtesy but the fact is that at least the students are bringing the issue to public attention and not keeping it secret and looting money off the MBTA.
Reply to this comment
by Maccess August 15, 2008 2:06 AM PDT
Why not just fix the vulnerability so the hacking information becomes worthless?
Reply to this comment
by Jimmu411 August 15, 2008 8:22 AM PDT
We MUST maintain the principles of security by ignorance! If we muzzle these three, surely no one else will be able to figure out the weaknesses in the system!
Reply to this comment
(17 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement