Subway agency wants to keep MIT students quiet over hack

By Ed Oswald | Published August 15, 2008, 10:36 AM

Update ribbon (small)

10:30 am EDT August 15, 2008 - A federal judge has sided with the Massachusetts Bay Transit Authority, ordering the students to continue to stay quiet beyond the original Tuesday expiration of their restraining order.

Presiding Judge George O'Toole, Jr. scheduled a hearing for that same Tuesday to debate the order's merits, and will decide then whether it should be modified or lifted altogether. As was reported initially early Thursday, copies of the presentation continued to be available on the Internet.

In addition, the judge also ordered the students to surrender code that was to be released as part of the presentation, along with a report that was to be submitted to their professor on the topic.

The Electronic Frontier Foundation, representing the students, said it would appeal the ruling. It also argued that the judge's most recent demands ran afoul of the student's First Amendment rights.

1:27 pm EDT August 14, 2008 - Although the Defcon conference has ended, Massachusetts' transit agency is looking to prevent three student researchers who uncovered holes in its fare collection system from divulging their discoveries to anyone else.

The two sides had attempted to work things out through negotiations. The Massachusetts Bay Transit Authority offered to engage in mediation through a third-party without any preconditions. The Electronic Frontier Foundation apparently rejected that offer, but would not confirm so publicly, saying it would not disclose any discussions with the agency.

Rather, the EFF seems to be interested in the legal route. It is urging a federal court in Boston to lift what it calls "an unconstitutional gag order," and arguments are scheduled there Thursday.

Modifications to the original restraining order have been proposed by the MBTA, which is asking the courts to only prohibit "non-public information." However, the EFF said in its own motion to dismiss that no harm was meant by the presentation, and that it was aimed instead at urging the agency to improve security.

"The First Amendment does not allow people to be silenced because their speech exposes flaws, even if those flaws might someday be illegally misused by others," EFF civil liberties director Jennifer Granick said. "To protect our clients' rights, we had no choice but to ask the court to reconsider the gag order."

Continuing the gag order on the students specifically may now be pointless, as details of the presentation, including actual slides, are now available online; and complete copies of the presentation were given to all conference attendees in DEFCON's materials, during registration. This may be part of the reason why the MBTA proposed a motion to modify the restraining order.

The original ruling was set to expire on August 19. After that, the court can either extend the order in the form of a preliminary injunction, or do nothing. In the latter case, the MIT students would then be allowed to speak on the topic, or even give the presentation elsewhere.

Comments

View comments by with a score of at least

what is needed is "DIS-INFORMATION"

just call the white house and ask them how its done..

Score: 0

|

ITS ALREADY LEAKED SO IT DOESNT MATTER YOU FOOLS!

ITS ALREADY LEAKED SO IT DOESNT MATTER YOU FOOLS!

ITS ALREADY LEAKED SO IT DOESNT MATTER YOU FOOLS!

ITS ALREADY LEAKED SO IT DOESNT MATTER YOU FOOLS!

Score: 0

|

Denial has worked wonders for the DRM community.

Score: 0

|

"Ordering the students to continue to continue"

Huh? Ed?

Score: 0

|

Proofreading is for the weak!

Score: 0

|

What has become rather evident is that, like so many aspects of Defcon, the effort was not an attempt to merely mitigate a problem, it is instead the attempt to gain notoriety through the exploitation of a weakness at others expense...but like so many others do when they stand to benefit but who scream the loudest when they are the victims (ie P2P music distribution), unfortunately the principle of the freedom of speech is NOT the fundamental concern here.

Score: 0

|

How about someone fixes the flaws? Then, it doesn't matter anymore.

Score: 0

|

Hush !

(If they did that, then there would be no need for lawyers, press conferences, committee meetings and political grandstanding. Also, it wouldn't be a controversial news story and fodder for the media to have endless interviews with their "experts".)

Score: 0

|

We don't know the nature of the flaws, but chances are that they will take some time to fix and test. A public transportation system is both large and critical, so you can't just throw something together on a whim. On top of that, we all know about the efficiency of government efforts.

Score: 0

|

Did these students take the ethical route of bringing the the holes to the attention of the agency and allow for a reasonable amount of time for a fix?

Should they be able to share their findings freely? Probably. The big issue in the security research field is in dealing with the DMCA, which has severely stifled the sharing of information. It's very shaky legal ground and just not worth the risk for many.

The motivation behind such cracking isn't always the most noble, but it helps people learn from their mistakes and therefore build stronger systems. In the meantime though, the current iterations get kind of screwed.

Score: 0

|

SKAPIG: Did these students take the ethical route of bringing the the holes to the attention of the agency and allow for a reasonable amount of time for a fix?

Exactly. If you find a problem you tell the appropriate people so they can fix the issue. If they don't then maybe spilling the beans about the loophole will get their butts in gear. Thats a serious loss of revenue to them, placing a gag order will not fix the problem!

Score: 0

|

I agree that the gag order will not fix the problem, but its the government's way of ignoring the problem and hoping it will go away. Things like this have happened many times before and will continue to happen because they never learn their lesson.

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?