{"id":398,"date":"2008-08-12T22:23:43","date_gmt":"2008-08-13T02:23:43","guid":{"rendered":"https:\/\/dandunn.org\/blog\/?p=398"},"modified":"2008-10-03T21:45:08","modified_gmt":"2008-10-04T01:45:08","slug":"mbta-screws-up-repeatedly","status":"publish","type":"post","link":"https:\/\/dandunn.org\/blog\/2008\/08\/mbta-screws-up-repeatedly\/","title":{"rendered":"MBTA Screws Up (Repeatedly)"},"content":{"rendered":"<p>It&#8217;s hard for me to characterize the MBTA&#8217;s most recent insanity: Are they in denial about their security problems?  Or are they so disconnected from reality that they think they can hide their security problems?  Let&#8217;s explore the question.<\/p>\n<p>First, a review of recent events: Three MIT students study the MBTA&#8217;s security and prepare a presentation to DEFCON 16.  (Their advisor is Professor Ron Rivest, the &#8220;R&#8221; in <a href=\"http:\/\/rsa.com\/\">RSA<\/a>.)  Dr. Rivest contacts the MBTA about the research.  The students, the professor, and the MBTA have a meeting.  Later that week the MBTA seeks an injunction in federal court to prevent them from delivering the presentation.  <a href=\"http:\/\/news.cnet.com\/8301-1009_3-10012612-83.html\">The injunction is granted<\/a> and the presentation is canceled.  The presentation is filed as a part of the request for injunction, making it a public record.  The presentation had also already been distributed on a disc to all of the DEFCON attendees.  <a href=\"http:\/\/www-tech.mit.edu\/V128\/N30\/subway\/Defcon_Presentation.pdf\">The article is readily available<\/a> on MIT&#8217;s student newspaper website, <a href=\"http:\/\/www-tech.mit.edu\/\">The Tech<\/a>.<\/p>\n<p>Did you <a href=\"http:\/\/www-tech.mit.edu\/V128\/N30\/subway\/Defcon_Presentation.pdf\">click the article<\/a>?  You should.  It&#8217;s a big file, almost 5 megs, but it&#8217;s chock full of great pictures and clear explanations.<\/p>\n<p>So, let&#8217;s review option 1, that the MBTA is in denial that there are security problems:<\/p>\n<ul>\n<li>Do you think MBTA General Manager Dan Grabauskas believes <a href=\"http:\/\/www.boston.com\/news\/local\/articles\/2008\/08\/12\/mit_students_report_makes_security_recommendations_to_t\/\">his own words<\/a> when he says that he&#8217;s &#8220;confident&#8221; that the claims  will be &#8220;dismissed or dealt with.&#8221;?  I&#8217;m assuming he looked at the same presentation I just did.  He really thinks the claims can be dismissed?  It seems to me that he&#8217;s spouting a line of bull, and the people who can contradict him have an injunction preventing them from proving him wrong.<\/li>\n<li>Did he see the same pictures that I did of open locks, exposed fiber cables, empty surveillance rooms, and unprotected keys?<\/li>\n<li>Maybe the MBTA is confused by that presentation. Maybe they just don&#8217;t understand how data is encoded in magnetic stripes.<\/li>\n<\/ul>\n<p>And option two, that the MBTA thought they could simply hide the problems?<\/p>\n<ul>\n<li>They sought the injunction, right?\u00c2\u00a0 That argues that they thought they could hide the information.  But if they&#8217;re trying to hide information, why did they file the information themselves as a public document?  (<a href=\"http:\/\/www.abcnews.go.com\/Technology\/Story?id=5564423&amp;page=1\">ABC News<\/a>: &#8220;But, not only had the presentation already been distributed at the Defcon convention, it was entered into public record when the MBTA filed its complaint.&#8221;)\u00c2\u00a0 It doesn&#8217;t add up.<\/li>\n<li>Maybe they thought that the injunction wouldn&#8217;t get any attention.\u00c2\u00a0 It&#8217;s possible, I guess.\u00c2\u00a0 But is the MBTA&#8217;s PR department that clueless?\u00c2\u00a0 That&#8217;s a reach, even for <a href=\"https:\/\/dandunn.org\/blog\/archives\/380\">Lydia Rivera<\/a>.<\/li>\n<\/ul>\n<p>I guess there is always option three, which is just incompetence.  There&#8217;s an argument to be made here.<\/p>\n<ul>\n<li>MBTA <a href=\"http:\/\/www.eff.org\/deeplinks\/2008\/08\/mit-students-response-mbta-statements\">couldn&#8217;t even get the timeline right<\/a> in its press release.<\/li>\n<li>Past history: <a href=\"https:\/\/dandunn.org\/blog\/archives\/118\">Two<\/a> <a href=\"https:\/\/dandunn.org\/blog\/archives\/380\">items<\/a> just from my blog.<\/li>\n<li>The aforementioned open locks, exposed fiber cables, empty surveillance rooms, and unprotected keys.<\/li>\n<\/ul>\n<p>It doesn&#8217;t really matter which explanation is the right one.\u00c2\u00a0 The presentation speaks for itself.\u00c2\u00a0 The MBTA is a security disaster.<\/p>\n<p>A final note: As a former editor of The Tech, I&#8217;m proud of their role in this.\u00c2\u00a0 Good for them for publishing the research.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s hard for me to characterize the MBTA&#8217;s most recent insanity: Are they in denial about their security problems? Or are they so disconnected from reality that they think they can hide their security problems? Let&#8217;s explore the question. First, a review of recent events: Three MIT students study the MBTA&#8217;s security and prepare a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,15,12],"tags":[],"class_list":["post-398","post","type-post","status-publish","format-standard","hentry","category-mbta","category-mit","category-technology"],"_links":{"self":[{"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/posts\/398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/comments?post=398"}],"version-history":[{"count":0,"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/posts\/398\/revisions"}],"wp:attachment":[{"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/media?parent=398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/categories?post=398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dandunn.org\/blog\/wp-json\/wp\/v2\/tags?post=398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}