Commentary

George Hulme
 

MBTA: Legally Shackling Security Researchers Rarely Works

As many security and technology followers know, three MIT students had planned on presenting their findings on a number of vulnerabilities they found in the Massachusetts Bay Transportation Authority's CharlieTicket and CharlieCard payment cards at last week's Defcon conference. That was, until a gag order was put in place to keep them quiet. Today, a federal judge in Boston let the temporary restraining order stand. And so this Saga of Stupidity continues.

As many security and technology followers know, three MIT students had planned on presenting their findings on a number of vulnerabilities they found in the Massachusetts Bay Transportation Authority's CharlieTicket and CharlieCard payment cards at last week's Defcon conference. That was, until a gag order was put in place to keep them quiet. Today, a federal judge in Boston let the temporary restraining order stand. And so this Saga of Stupidity continues.The hearing held in Boston today was to decide if it was OK for the MIT students to talk about the bevy of vulnerabilities they found in the Boston T. And let me tell you, if Russell Ryan, Zack Anderson, and Alessandro Chesa's presentation slides are an accurate indication of the state of security in the city's transportation system, one of the important questions remaining is why hasn't the Boston T been pwned long, long ago. We're talking about a system rife with all kinds of vulnerabilities. In fact, it may very well already have been compromised.

Part of their scheduled talk, Anatomy of a Subway Hack, would have provided details in how it's possible to generate stored-value fare cards, reverse engineer magstripes, and tap into the fare vendor network. And I think it's reasonable to assume others already have figured some of this out.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Because U.S. District Judge George O'Toole has decided not to decide until next Tuesday, this story may not move forward until Aug. 19. The problem of trying to solve security vulnerabilities like this through the legal stifling of speech are manifold. Like the fact that it does nothing to solve the underlying security problems, and steals energy away from actually mitigating the problem. Chris Wysopal summed it up very well in his Zero In A Bit blog at VeraCode:

"Security problems go away by mandating independent security testing before a product is accepted, not by trying to get security researchers to be quiet. This is a good example of how the reactive approach doesn't work. The flaws are still in the system and suing researchers has just shined a bright light on them."

Wysopal is right, and if the energy used to stifle the MIT students from publishing their research had been used to test the payment systems before it was deployed, you'd be reading about something else right now. So if you're upset at these researchers for finding these flaws, your anger is misplaced: it should be directed at the authorities for buying such a sheep of a system.

The idiocy of this all, especially now, is that the student's PowerPoint presentation was given to the thousands of Defcon attendees, and a 5-page vulnerability analysis already has become public. Not to forget, as ZDNet's Richard Koman noted earlier, that the MBTA, in its legal compliant, put a 30-page confidential report written by the students into the public record.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links