Technology Review - Published By MIT
Advertisement
[1] 2 Next »

Thursday, August 14, 2008

How (Not) to Fix a Flaw

Experts say disclosing bugs prevents security flaws from festering.

By Erica Naone

smaller text tool iconmedium text tool iconlarger text tool icon
Credit: Technology Review

Efforts to censor three MIT students who found security flaws in the Boston subway's payment system have been roundly criticized by experts, who argue that suppressing such research could ultimately make the system more vulnerable.

The students were served with a temporary restraining order this weekend at the Defcon security conference in Las Vegas, preventing them from giving their planned talk on Boston subway's payment system.

According to slides submitted before the conference, which have also been posted online, their presentation "Anatomy of a Subway Hack" would have revealed ways to forge or copy both the old magnetic-stripe passes and the newer radio-frequency identification (RFID) cards used on Boston's subway, making it possible to travel for free. The restraining order was filed on behalf of the Massachusetts Bay Transportation Authority (MBTA), which spent more than $180 million to install the system, according to court documents. The MBTA has also brought a larger lawsuit accusing the students of violating the Computer Fraud and Abuse Act and accusing MIT of being negligent in its supervision of them.

One of the students involved, Zack Anderson, says his team had never intended to give real attackers an advantage. "We left out some details in the work we did, because we didn't want anyone to be able to attack the ticketing system; we didn't want people to be able to circumvent the system and get free fares," he says.

Marcia Hoffman, staff attorney with the Electronic Frontier Foundation, a digital-rights group that is assisting the MIT team with its defense, argues that researchers need to be protected as they investigate these types of flaws. "It's extremely rare for a court to bar anyone from speaking before that person has even had a chance to speak," she says. "We think this sets a terrible precedent that's very dangerous for security research."

The MBTA says it isn't trying to stop research, just buy time to deal with whatever flaws the students might have found. The agency also expressed skepticism about whether the MIT students had indeed found real flaws. "They are telling a terrific tale of widespread security problems, but they still have not provided the MBTA with credible information to support such a claim," says Joe Pesaturo, a spokesman for the MBTA. "It's that simple."

[1] 2 Next »

Comments

  • [no subject]
    zig158 on 08/14/2008 at 12:53 AM
    Posts:
    64
    Avg Rating:
    4/5
    “"They are telling a terrific tale of widespread security problems, but they still have not provided the MBTA with credible information to support such a claim," says Joe Pesaturo”
    If this is true, then why are they trying to shut them up?

    "It's extremely rare for a court to bar anyone from speaking before that person has even had a chance to speak," sounds to me like a blatant violation of the first amendment. Why does that not surprise me in today’s America?

    Sieg Heil!
    Rate this comment: 12345
    • Re:
      elkay3000 on 08/19/2008 at 2:57 PM
      Posts:
      1
      I'm by no means a security expert, but in business terms this situation resembles the Music industry's shut down of file sharing sites in the early part of this decade because they couldn't understand it and they couldn't control it.  In doing so they lost bazillions of dollars and alienated the very people they should have been trying to bring into their mix.

      When will these old timers learn that it's a new world out there now?  Being paranoid, secretive and trying to control everything on the internet is not the way to go.

      It's ironic that this article about clamping down and restricting is in the same issue as the article about Barack Obama's facillitation and openess web strategy.  Who came out on top?
      Rate this comment: 12345
  • Responsible Researchers
    carlii on 08/14/2008 at 5:43 AM
    Posts:
    25
    Avg Rating:
    3/5
    Based upon the article, the researchers omitted details to protect the public entity from fraud, while also providing some details to show there is a credible security flaw that needs to be addressed.  That sounds to me like they were being responsible researchers.  How about the public entity or the third party firm (a) pay the researchers for further details on the security flaws, (b) pay the researchers for information on how to detect when these security flaws are compromised, and (c) pay these researchers also to help to close down those security holes?  Alternatively, perhaps these researchers will create and license some new technology with better security to competing firms, or start their own firm, since these existing entities are so prone to sue those who'd help them.  It seems the researchers want to have the flaw resolved.  If these public entities sue anyone who would be willing to help them out, likely they'll lose a lot more money when others instead move to secretly exploit various security flaws that could have been remediated.
    Rate this comment: 12345
    • Re: Responsible Researchers
      dtutelman on 08/14/2008 at 10:20 AM
      Posts:
      23
      Avg Rating:
      4/5
      I agree that the public entity and the third party supplier should be paying the researchers instead of enjoining them. Paying for the details of the hack is spot-on. I'm more skeptical about the proposal to pay them for closing the security hole.

      Creating a security system and cracking it are two different talents. Yes, they require the same sort of technical knowledge. And there are people who can do both well. But most crackers are not good creators, and vice versa. I have no idea whether these particular researchers are as good at creating as at cracking.

      Bottom line: The notion of "security through obscurity" has been discredited repeatedly over the years. Probably close to a century, in fact. Punishing the messenger is stupid, and the courts' facilitating the punishment is unconscionable.
      Rate this comment: 12345
      • Pay fault finders
        nekote on 08/25/2008 at 12:20 PM
        Posts:
        122
        Avg Rating:
        4/5
        Makes so much more sense to reward "Black Hats" who find the cracks and don't publish.

        Versus not knowing, until the circumvention is detected in wide use!

        No reward?
        No reason not to publish.
        Rate this comment: 12345
Advertisement

Current Issue

Technology Review January/February 2009
Lifeline for Renewable Power
Without a radically expanded and smarter electrical grid, wind and solar will remain niche power sources.
•  Subscribe
Save 41%
•  Table of Contents
•  MIT News

Magazine Services

Career Resources

MIT Technology Insider

Stories and breaking news from inside MIT about the latest research, innovations, and startups--in a convenient monthly e-newsletter. Subscribe today
Advertisement

Follow us on Twitter

Twitter

Get Technology Review updates via the web, cellphone, or Instant Messager – Follow techreview on Twitter!

Advertisement

More Technology News from Forbes

Advertisement
Advertisement
TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology