Court blocks MIT students from showing subway hack


Recommended Posts

LAS VEGAS (AP) -- A federal judge ordered three college students to cancel a Sunday presentation at a computer hackers' conference where they planned to show security flaws in the automated fare system used by Boston's subway.

The temporary restraining order, issued by a U.S. district judge in Massachusetts, prevented the Massachusetts Institute of Technology students from demonstrating at the Defcon conference in Las Vegas how to use the vulnerabilities to get free rides.

The Electronics Frontier Foundation, which is representing MIT students Zack Anderson, R.J. Ryan and Alessandro Chiesa, plans to fight the order, said Jennifer Granick, the group's civil liberties director.

The Massachusetts Bay Transportation Authority said in a complaint filed Friday that the students offered to show others how to use the hacks before giving the transit system a chance to fix the flaws. MIT is also named in the suit.

But Granick told The Associated Press on Sunday that the students were simply trying to share their research and planned to omit key information that would make things easier for anyone who actually wanted to hack the payment system.

Lawyers for the transit system did not immediately return phone calls seeking comment on Sunday.

Electronic copies of the 87-slide presentation circulating the Internet disparaged the transit system's physical security and showed photographs of unlocked doors, turnstile control boxes and exposed computer monitors at subway stations.

One slide explains that the presentation would teach attendees how to generate fare cards, reverse engineer magnetic stripes on cards and hack radio frequency identification (RFID) cards.

The next slide says: ''And this is very illegal! So the following material is for educational use only.''

The presentation was distributed to conference attendees on CDs on Thursday, before the conference officially began and the transit system filed suit.

In court documents, Gary Foster, chief technology officer for the transit system said the presentation would ''inflict significant damage'' if the Massachusetts Bay Transportation Authority did not have a chance to correct the flaws.

''It is extremely important to maintain the security and integrity of the Fare Media systems,'' Foster said in a court declaration. ''With an insecure, compromised system, even basic revenue controls, to name one example, become significantly challenging.''

The MIT students' presentation was supposed to demonstrate hacks for the system's primary two payment cards -- CharlieCard and CharlieTicket -- which work on the system's subways and buses. The transit system plans to implement the cards' use on its commuter rail, boats and ferries, according to its Web site.

Granick said ordering the students to not share their findings would be ''dangerous,'' and have a chilling effect on legitimate researchers who want to point out flaws that lead to system improvements.

''If you prevent legitimate researchers from talking about their findings, it's not going to stop people from finding vulnerabilities. It's going to stop the good guys from talking about them and from learning from each other,'' Granick said. ''The bad guys are still going to be looking for the vulnerabilities and still be finding them.''

Defcon, attended by many of the world's best-known security experts, has become an annual showcase of the latest discovered weaknesses in computers, phone equipment and other machines.

source

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I noticed this was already happening within my organization; my teams location will change between remote and on-site without me having to do anything. Is it possible this is live already for select customers?
    • I wonder what it will show when I'm plugged in with my ethernet cable at home and not using WiFi.
    • While LibreOffice is not pleased to see a new competitor, they are absolutely correct in stating that Euro-Office using a MS file standard as a default is not being truly "European." Using a MS standard just means Euro-Office is just a "bastardized MS Office Suite." (Wasn't a major purpose of Euro-Office was to get away from being captive and enslaved to MS's Office Suite??)
    • Microsoft continues its long-term policy of spying on their users--despite vehement denials. That feature will be disabled (or removed) either "elegantly" with MS providing a true way to disable it, or "quick and dirty" via a third-party who WILL come up with a way to disable it. Your choice MS...
    • Helium Browser 0.13.3.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.3.1 changelog: f53b28d update: helium 0.13.3.1 (#292) b3cbb2ba revision: bump to 3 (#1925) bcacb8c7 chromium: update to 149.0.7827.114 (#1924) Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      179
    3. 3
      PsYcHoKiLLa
      140
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      78
  • Tell a friend

    Love Neowin? Tell a friend!