The Register® — Biting the hand that feeds IT

Feeds

Transit agency to work with hackers who found vulns

First gagged, now recruited

Agentless Backup is Not a Myth

A New England transit agency has vowed to work with three Massachusetts Institute of Technology undergraduates whom it had previously sued when they discovered serious flaws in the agency's electronic payment systems.

The Massachusetts Bay Transit Authority (MBTA) said it would work with Zack Anderson, RJ Ryan, and Alessandro Chiesa to make improvements to the agency's fare collection system "that will be as straightforward and inexpensive to address as possible." In August, the MBTA obtained a court order gagging the trio just hours before they were scheduled to speak about the gaping holes at the Defcon hacker conference in Las Vegas.

"It feels really good," Zack Anderson said on Monday. "I'm glad after all that has happened the lawsuit is behind us."

The MBTA claimed the students would be in violation of the Computer Fraud and Abuse Act merely by presenting research showing it was possible to add hundreds of dollars to cards used pay subway fares. Many of their findings were based on research that had been released months earlier showing how to compromise the Mifare smartcard, the underlying technology used in the MBTA's CharlieCard.

Ten days later, the gag order was lifted after a federal judge rejected the MBTA's arguments.

"Basically, that meant the case was over," said Jennifer Granick, a staff attorney for the Electronic Frontier Foundation who represented the students. "It just took some time for the MBTA to dismiss the case and to work out an agreement separate from the dismissal ... for the students to meet with the MBTA and talk to them about their research in a more friendly setting."

The MBTA dropped its lawsuit in October, but the parties held off discussing the dismissal publicly until they worked out a plan to work together, Granick said. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

@brian

Yep!

@AC

Indeed, the Real World (TM), where corporations selling/nursing expensive but faulty products/systems prefer to shoot down any messengers of doom as a short-term fix. Sure, the researchers wanted to get some kudos in the white-hat community, just as the company wanted not to have to admit that their equipment was less than fit for purpose, or develop and roll out a fix. Or to put it another way:

It's not my job to run the train, the whistle I can't blow,

It's not my job to tell how far the train's allowed to go,

It's not my job to let off steam, nor even clang the bell,

But watch the damned thing jump the tracks and see who catches Hell!

0
0

Another bunch of tosser students

These know-it-all students who soon discover they know very little about how the real world ticks are finally getting an introduction into the real world. Maybe now they understand that embarrassing a company for its poor level of security is not the best way to fix the problem.... but hey, we all know they were really after fame and fortune at some silly defcon.

0
0

CharlieCard?

Seriously? You couldn't make this shit up.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?