Business - Written by Ian Da Silva on Monday, August 11, 2008 19:20 - 1 Comment

Hacking the hack – missed opportunity or just doing the “right” thing?

Late last week, newly-famed MIT students Zack Anderson, R.J. Ryan and Alessandro Chiesa were court-ordered to cancel their Sunday presentation entitled “Anatomy of a Subway Hack” at DEF CON , the world’s largest hacker conference. The banned presentation highlighted security weaknesses in the Massachusetts Bay Transportation Authority’s fare system that would potentially allow enterprising individuals with the appropriate technology and process (as intricately outlined in the presentation) to add monetary value to their existing CharlieCard or CharlieTicket to receive free transportation.

The injunction has ignited a debate over the ruling’s merit, which names each of the students as well as MIT in the temporary restraining order. The MBTA has taken issue with the fact that the “students offered to show others how to use the hacks before giving the transit system a chance to fix the flaws”, while the students’ representative from the Electronics Frontier Foundation (EFF) says “the students were simply trying to share their research and planned to omit key information that would make things easier for anyone who actually wanted to hack the payment system.”

In banning the presentation, which had already been distributed to conference attendees, and managed to make its way online, (go figure – handed out at a hacker conference and quickly made its way online) many have questioned whether the ruling has actually made things “worse”, helping the Hack gain increased publicity. According to EFF representative, Jennifer Granick, the ruling also leads down a “dangerous” path whereby “If you prevent legitimate researchers from talking about their findings, it’s not going to stop people from finding vulnerabilities. It’s going to stop the good guys from talking about them and from learning from each other.”

While I’m certainly not proposing anarchy here, I can’t help but wonder – with the knowledge of savvy individuals like Anderson, Ryan and Chiesa, does it make sense to alienate them with such court injunctions? As a result, has the MBTA missed an important opportunity, suppressing potentially valuable conversation that could/would have been a natural follow-on to the presentation, helping improve the MBTA and potentially other systems?



1 Comment

You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Camilla
Aug 13, 2008 19:08

I suspect the MBTA suppressed the presentation because they either didn’t have or didn’t want to have the money or resources available to fix the bug.

Leave a Reply

Comment

Browse Content

Business - Mar 19, 2010 16:57 - 0 Comments

Addressing the social media ‘support gap’

More In Business


Entertainment - Mar 9, 2010 16:58 - 3 Comments

Lessons in collaboration from B.B. King’s

More In Entertainment


Society - Mar 17, 2010 9:45 - 0 Comments

On unintended consequences

More In Society