On CHOW: Why do onions make you cry?
BNET Business Network:
BNET
TechRepublic
ZDNet

August 11th, 2008

Hack-the-T presentation hits the Web

Posted by Richard Koman @ August 11, 2008 @ 4:43 PM

Categories: Security, State & Local Govt

Tags: Card, Web, Open Source, Student, Presentation, MBTA, Productivity, Richard Koman

So, the presentation of hacking the T that three MIT students were barred from presenting is now on the Web, hosted on MIT’s own servers. Apparently, this is OK because the presentation was included in the MBTA’s complaint.

News.com reports though that MBTA says the availability of the PowerPoint doesn’t obviate the need for the injunction.

“The MBTA will reserve comment on the substance of the presentation until staff has had a sufficient period of time to thoroughly review the information, and meet with the students and their professor.”

Key to the injunction is that it forbids not only the presentation but also the release of code the students planned to release at web.mit.edu/zacka/www/subway/. A planned demo of this code was a major point of controversy in the hearing on Saturday. The EFF lawyer emphasized that while the students relied on techniques in the public domain, their special contribution was finding a way to determine the checksum on the CharlieCard, according to a recording of the hearing (WMA).

It’s a demonstration that the technology needs improvement but without providing a critical ingredient for an attacker. They’ve presented the existing information in their academic field, what new research they’ve done to push the envelope but they have responsibly decided to withhold a piece of information that would allow anybody to make a fraudulent fare card.

But MBTA’s lawyers said that the students intended to release open source libraries and other code intended to make it easy for others to hack into the system.

EFF claimed the software tools are not targeted to hacking MBTA’s system but “generalized tools for reading magnetic cards, for analyzing information on cards and for using open source radio software to listen to signals from RFID cards. They are not tools that some malicious hacker could come along and use.”

  • Talkback
  • Most Recent of 8 Talkback(s)
Nice
Right up there with making names/passwords publicly available by the prosecution entering them into evidence in the Terry Childs case.... (Read the rest)
Posted by: seanferd Posted on: 08/12/08 You are currently: a Guest | | Terms of Use
MBTA made it publically available anyway...  javajunkie@... | 08/11/08
Nice  seanferd | 08/12/08
RE: Hack-the-T presentation hits the Web  terryhmc@... | 08/11/08
RE: Don't shoot the messenger  workInProgress | 08/12/08
There was a meeting  rkoman@... | 08/12/08
RE: the MIT kids had it coming  johndoe445566 | 08/12/08
Hack the T Presentation  ktechman | 08/12/08
Meanwhile... UK  BlueBerry Pick'n | 08/12/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here