Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Judge denies five-month gag in transit hack case

  • Email a Friend
  • Print Page
By Dan Kaplan
Aug 21, 2008 10:30 AM
Tags: Judge | denies | five-month | gag | in | transit | hack | case
A U.S. District Court judge has sided with three Massachusetts Institute of Technology (MIT) students in their quest to present findings on vulnerabilities in the Massachusetts Bay Transportation Authority's (MBTA) subway fare collection system.

Ten days ago, a judge in Boston issued a temporary restraining order to the students -- Zack Anderson, R.J. Ryan and Alessandro Chiesa, preventing them from giving their planned talk Aug. 10 at the Defcon hacker conference in Las Vegas.

The students were set to show how flaws in the MBTA's transit fare payment system -- namely its CharlieCard and CharlieTicket passes -- could be exploited through forgery and cloning to gain passengers free rides. The project had earned them an "A" from their MIT computer science professor.

The judge who issued the gag order said the students were in violation of the federal Computer Fraud and Abuse Act. But the Electronic Frontier Foundation (EFF), a digital rights watchdog representing the students, said the law applied to computer intrusions -- not research talks at conferences.

On Tuesday, the MBTA asked another judge to extend the restraining order for five months while it fixed the vulnerabilities.

U.S. District Judge George O'Toole Jr., however, ruled against this request, agreeing with the EFF that federal computer intrusion laws do not apply to this case.

"A presentation at a security conference is not some sort of computer intrusion," EFF Staff Attorney Marcia Hofmann said in a statement. "It's protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing research does not improve security -- the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not."

The MBTA has filed a separate lawsuit against MIT and the students. The EFF said this has prevented the students and the agency from working together cooperatively.

But MBTA said it wants to try.

"Now that the court proceedings are behind us, I renew my invitation to the students to sit down with us and discuss their findings," MBTA General Manager Daniel Grabauskas said in a statement. "A great opportunity now presents itself."

The MIT students also could not be reached on Wednesday.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers