Transit agency to work with hackers who found vulns
First gagged, now recruited
A New England transit agency has vowed to work with three Massachusetts Institute of Technology undergraduates whom it had previously sued when they discovered serious flaws in the agency's electronic payment systems.
The Massachusetts Bay Transit Authority (MBTA) said it would work with Zack Anderson, RJ Ryan, and Alessandro Chiesa to make improvements to the agency's fare collection system "that will be as straightforward and inexpensive to address as possible." In August, the MBTA obtained a court order gagging the trio just hours before they were scheduled to speak about the gaping holes at the Defcon hacker conference in Las Vegas.
"It feels really good," Zack Anderson said on Monday. "I'm glad after all that has happened the lawsuit is behind us."
The MBTA claimed the students would be in violation of the Computer Fraud and Abuse Act merely by presenting research showing it was possible to add hundreds of dollars to cards used pay subway fares. Many of their findings were based on research that had been released months earlier showing how to compromise the Mifare smartcard, the underlying technology used in the MBTA's CharlieCard.
Ten days later, the gag order was lifted after a federal judge rejected the MBTA's arguments.
"Basically, that meant the case was over," said Jennifer Granick, a staff attorney for the Electronic Frontier Foundation who represented the students. "It just took some time for the MBTA to dismiss the case and to work out an agreement separate from the dismissal ... for the students to meet with the MBTA and talk to them about their research in a more friendly setting."
The MBTA dropped its lawsuit in October, but the parties held off discussing the dismissal publicly until they worked out a plan to work together, Granick said. ®
Indeed, the Real World (TM), where corporations selling/nursing expensive but faulty products/systems prefer to shoot down any messengers of doom as a short-term fix. Sure, the researchers wanted to get some kudos in the white-hat community, just as the company wanted not to have to admit that their equipment was less than fit for purpose, or develop and roll out a fix. Or to put it another way:
It's not my job to run the train, the whistle I can't blow,
It's not my job to tell how far the train's allowed to go,
It's not my job to let off steam, nor even clang the bell,
But watch the damned thing jump the tracks and see who catches Hell!
Another bunch of tosser students
These know-it-all students who soon discover they know very little about how the real world ticks are finally getting an introduction into the real world. Maybe now they understand that embarrassing a company for its poor level of security is not the best way to fix the problem.... but hey, we all know they were really after fame and fortune at some silly defcon.
Seriously? You couldn't make this shit up.