Judge refuses to lift gag order in subway-hack case

By Jaikumar Vijayan, Computerworld |  Security, Defcon, vulnerabilities Add a new comment

A federal judge in Boston Thursday refused to lift a temporary restraining order preventing three MIT students from publicly discussing details of several security vulnerabilities that they found in the electronic ticketing system used by the city's mass transit authority.

The decision means that the gag order imposed on the students last Saturday will remain unchanged at least until Aug. 19, when U.S. District Judge George O'Toole is scheduled to hold another hearing in the case. The restraining order, which was issued in response to a lawsuit filed by the Massachusetts Bay Transportation Authority (MBTA), will expire that same day unless it's extended or turned into a permanent injunction.

At Thursday's hearing, O'Toole also asked the MIT students to submit a copy of a class paper in which they detailed the vulnerabilities that they had found, according to the Electronic Frontier Foundation (EFF), a high-tech civil rights group that is representing the students in the case. The MBTA requested a copy of the paper in a motion that it filed, the EFF said.

In addition, O'Toole asked the three undergrads -- Zack Anderson, Russell "RJ" Ryan and Alessandro Chiesa -- to provide copies of programming code that they included in a planned presentation to show how the MBTA's e-ticketing system could be hacked.

The San Francisco-based EFF had filed a motion in court this week asking O'Toole to lift the restraining order (download PDF). A spokeswoman for the group expressed disappointment at the judge's refusal to do so and said that the EFF will now go ahead with a planned appeal of the decision to issue the gag order.

The restraining order was handed down by another judge one day before Anderson, Ryan and Chiesa were scheduled to detail the MBTA's vulnerabilities at the Defcon hacker convention in Las Vegas. In its motion requesting the restraining order (download PDF), the MBTA claimed that it was forced to seek the court's intervention because neither MIT nor the students had given the transit agency enough information to assess the vulnerabilities that were about to be publicly disclosed.

The MBTA said in its court filings that its intention wasn't to permanently gag the students but to give itself some time to determine the validity and seriousness of the issues being raised by the students and to develop a course of action for addressing them.

In a statement sent via e-mail Thursday, the MBTA said it was pleased that a second federal judge had upheld the restraining order, but "disappointed at the defendants' continued resistance to provide the information" requested by the agency. The MBTA added that it remains hopeful that all of the defendants will be "cooperative" as the case continues.

Although the students had to cancel their talk, the slides that they put together for the presentation were included on a CD given to Defcon attendees and thus have become publicly available.

The EFF has called the restraining order a violation of the students' First Amendment rights as well as a prior restraint on free speech. Along with the filing that requested the lifting of the order, the EFF submitted a letter in support of the students signed by 11 computer science professors and security researchers (download PDF).

David Farber, a professor of computer science and public policy at Carnegie Mellon University's School of Computer Science, was one of the people who signed the letter. He said today that the decision to issue the restraining order was a "bad, bad idea."

Based on the available information, the students appear to have notified MBTA officials about their research and even provided them with confidential information relating to the vulnerabilities, Farber said. The students also appear to have assured the MBTA in advance that their presentation wouldn't provide the level of detail needed for someone to actually exploit the vulnerabilities, he said. For the MBTA to then ask a court to gag the students was totally out of line, according to Farber.

What makes its actions even more egregious, he claimed, is the fact that the paper the students were scheduled to present had been vetted by MIT Professor Ron Rivest, who Farber described as one of more respected figures in the security community.

It could be argued that the students could have worked with the MBTA to fix the issues before publicly disclosing them, Farber acknowledged. But it is unconstitutional to prevent them from speaking about their discoveries just because the MBTA felt that it wasn't given adequate notice, he contended. "In practice," Farber said, "a good middle ground is to keep the courts out of it."

But Gartner Inc. analyst John Pescatore said the MBTA wasn't given a reasonable amount of time to fix the problems or develop work-arounds for them.

The intent of disclosing flaws should be to make software and systems more secure, "not to make headlines or sell tickets to security conferences," Pescatore said. In this case, he added, "the students went for publicity."

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question