Skip Links

Network World

  • Social Web 
  • Email 
  • Close

EFF to appeal court order halting subway hacker talk

By Robert McMillan , IDG News Service , 08/09/2008
  • Share/Email
  • Comment
  • Print

The Electronic Frontier Foundation plans to appeal a U.S. District Court order imposing a temporary injunction on a Defcon presentation that would have detailed flaws in the Massachusetts Bay Transportation Authority electronic ticketing system.

"The court ultimately came to a very, very wrong conclusion," EFF senior staff attorney Kurt Opsahl said during an EFF discussion at Defcon a few hours after Judge Douglas Woodlock of the U.S. District Court for the District of Massachusetts issued a court order halting the planned talk about the transit-system security flaws.

The MBTA filed a lawsuit Friday seeking to stop three Massachusetts Institute of Technology students from giving the talk. The lawsuit also names MIT as a defendant. The Boston-area transportation authority argued that the presentation would cause "significant damage to the MBTA's transit system," according to an online posting of the lawsuit.

MIT students Zack Anderson, Russell "RJ" Ryan and Alessandro Chiesa had been scheduled to talk about "The Anatomy of a Subway Hack: Breaking Crypto RFIDs & Magstripes of Ticketing Systems" at the Defcon conference Sunday. They received an "A" grade on the project in an MIT class, Opsahl said.

"The first notice that the MBTA provided that they were going to the court was after they had gone to the court," Opsahl said at the EFF session. The judge cited a computer intrusion statute in issuing the order, he said.

"The statute on its face appears to be discussing sending code programs or similar type of information to a computer and does not appear to contemplate somebody who is giving a talk to humans," Opsahl said. "Nevertheless, the court disagreed with that interpretation."

The court order seems to say that a magnetic strip on a paper card or a smartcard counts as a computer and the EFF disagrees with that interpretation, he said.

The temporary restraining order "reflects the court's view that they believe that the Massachusetts Bay Transit Authority was likely to succeed on the merits -- we think that's actually not the case," Opsahl said.

Some of the material in the students' talk regarding security problems with the MBTA's electronic ticketing system had been previously reported in the Boston Globe and Boston Herald newspapers, Opsahl said.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed