Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • BitTorrent site ordered to enable server logs, turn them over to MPAA
  • Microsoft Misleads on Copyright Reform by Michael Geist
  • Have You Been Subjected to Suspicionless Laptop Search or Seizure at the Border?
  • How Privacy Vanishes Online
  • Wyndham Worldwide hacked and database breached, giving access to some payment card information
  • Security researchers warn of new 'clickjacking' browser bugs
  • ShmooCon: P2P snoopers know what's in your wallet

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

MIT Coders' Free Speech At Stake

Submitted by MacRonin on August 19, 2008 - 2:51pm
  • Academia
  • Activists
  • Alert
  • Appeals
  • Companies
  • Court (US)
  • Editorial
  • EFF
  • Exploits
  • First Amendment
  • Government
  • Hmmm
  • Legal
  • News Follow-up Update/Correction
  • Remember
  • Reports
  • Rights
  • Security
  • Spin Zone

MIT Coders' Free Speech At Stake - Via EFF.org Updates:

As regular Deeplinks readers know, EFF's Coders' Rights Project is defending the rights of three MIT students who were prevented from presenting their research on security vulnerabilities in Boston's transit fare payment system. The students were hit with a temporary restraining order that silenced their planned presentation at DEFCON.

Why this is Important

At first glance, the issues at play may appear obscure, and of interest only to technical researchers and lawyers. But as we noted in a post last week, the right to publish without pre-publication review is part of the purpose of the 1st amendment, and one of the reasons Americans fought the Revolutionary War. (The MBTA's stance is all the more ironic, considering Boston's role in that war.)

Beyond this core constitutional principle, EFF is defending the ability to conduct security research in the digital age. As we note in our Vulnerability Reporting FAQ, security researchers by definition raise questions that corporations and government agencies would prefer to keep quiet. But by investigating flaws in security, and alerting the public to vulnerabilities, researchers play an important role in keeping private and public institutions accountable.

The MIT students were behaving as good citizens within this culture of security research. They met with the MBTA before the presentation. They never planned to expose the full details of their successful expose of the vulnerability of the MBTA's fare system, and MBTA officials admit that students had provided them with "a written summary of every vulnerability that they claimed to have discovered and how to fix these vulnerabilities." As promised, the students provided a detailed 31 page analysis of the security vulnerability, and the MBTA has finally admitted that a vulnerability exists.

The free speech implications are even more important because showing faults with a government agency's systems is core political speech. The Boston Herald reports that an MBTA Advisory Council Member was concerned with the fare card payment systems (in light of this controversy), and noted that the "T gave a no-bid contract for CharlieCard services to a former government employee." This makes the public interest in this matter even stronger.

The MBTA is Seeking a Dangerous Precedent

Moreover, if the MBTA's unprecedented expansion of the federal computer intrusion law (considering a talk to people the same as transmission of a program to a computer, considering a piece of paper with a magnetic stripe to be a computer, etc.) is adopted by the federal court in Boston, it would also have the unintended consequence of chilling future academic research and discussion. An anti-virus researcher, for example, presenting virus code on the PowerPoint screen at an anti-virus software conference, could be charged with a similar offense. Releasing a computer security textbook which describes attacks and defenses to networks would become a crime. The court and the MBTA should think about the consequences beyond the scope of this lawsuit.

The MBTA is also misguided with its notion that anytime a security researcher dares looks at a vulnerability, he suddenly has an obligation to provide the vendor of the faulty code with all of the research materials and to stay silent until the vendor decides he can speak. They seem to believe that they have right to all of any such academic researchers' notes, drafts, tools, and anything else, because they did them a favor and told them about a vulnerability the vendor didn't know about previously. The MBTA not only asserts that the researchers have this as a moral obligation, but a legal obligation to allow the vendor pre-publication review.

The MBTA's strategy of shooting the messenger is not only counter-productive and shortsighted, it is dangerous. The vulnerability existed long before the students discovered it, and it could be (and may have been) discovered by others. The MBTA and its vendors are the one who adopted a faulty system for its payment cards, not the students. The MBTA's priority should be fixing the problem, not continuing needless litigation.

A Reasonable Way Forward

The only thing stopping the students and the MBTA from working together cooperatively to resolve the fare payment card security issues is the lawsuit itself. The students have offered to meet with the MBTA and voluntarily walk the transit agency through the security vulnerability and the student's suggestions for improvement--for no charge--if only the MBTA would drop this lawsuit. It appears that the MBTA, a public transit agency supported with billions in public money, would rather spend these taxpayer dollars on litigation in a misguided attempt to keep the vulnerability quiet than work with the students to resolve the situation.

On Tuesday morning, the federal court with either lift the restraining order, or convert the order to a preliminary injunction. EFF's Coders' Rights Project will be there, arguing for the First Amendment rights of the students, and for the right of researchers to investigate security flaws in the public interest.

(Read Original Article - Via EFF.org Updates.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
  • How Privacy Vanishes Online
  • Undercover Feds on Social Networking Sites Raise Questions
  • FBI Uses Fake Facebook Profiles To Spy On Suspects
  • Lawrence Lessig: Citizens Unite
  • Case Report – BCCA says aerial surveillance by telphoto zoom lens not a search
  • Obama threatens to veto greater intelligence oversight
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.