The Tech (MIT student newspaper) publishes the banned DEFCON slides
www-tech.mit.edu
www-tech.mit.edu
The amount of work that went into this is awesome. They're hacking real life.
"Among the documents the MTBA filed with its declaration to the court today is a vulnerability assessment report (http://blog.wired.com/27bstroke6/files/vulnerability_assessm...) that the three students gave the MTBA about the flaws in its system. The document is dated August 8, the day the MTBA filed its lawsuit against the students, and is essentially the information the students declined to give the MTBA before it filed its lawsuit."
I can't help but think Wired got this wrong. Knowing who the students' advisor is, I find it pretty hard to believe that the students refused to give the assessment to the MBTA before publishing this presentation.
The people designing these high human traffic systems are usually much more concerned about other factors (low latency at the turnstile, minimal number of network connections to wire, card reliability, etc.) than they are about security.
Oh well, at least the politicians can give their contractor buddies my money!
What about institutionalizing white hat hacking, somehow? I could imagine a system where two competing tiger teams ensure good results. Basically, pay bonuses for actually breaking the security measures. If only one team succeeds in breaking in, then they get both team's bonus.
I can just imagine going into some back room to buy a $1,000 metro card for $5. However I can't imagine many people really bothering, an unlimited card is only $81 a month. When rent is $2500 a one bedroom apartment in brooklyn, and lunch is $15 every day, $81 for all of your transportation really isn't a big deal.
Excellent hack though.
Hell, I pay $140/month to take the Orange line two stops west and a flat-fee bus to its second stop on the route. And people wonder why we have such awful traffic: Driving is often cheaper!
Get some bread and make a sandwich, already!
While the security tzars are focused on the electronic hackers just having fun the majority of losses are probably coming from kids who jump the turn styles or go through 2 at a time.
The customer is probably better off with a spec for proper security in the first place, so they can avoid the cost of refitting or replacing the entire system.
So, is this security through stupidity?
Granted 10 years ago storing value on each card would have been more useful but the turn styles should easily be able to handle the full database.
I imagine that there are better ways to solve the problem at hand (security) that don't involve adding thousands of lines of code, miles of fiber, and hundreds of thousands of dollars.
See him leaning out of the window with that mocking grin, waiving his forged card in triumph and thinking, "Suckers!"
Just hope the media and security services (and alarmists) in general don't use it to go on about anti-terrorism and how we are all under constant terrorist threat (and push more anti-terror measures).
Go USA - We're Number One!
What's to say they can't or haven't?
I want one. :)
Having said that, I also have to say that there's an underlying attitude that often exists from folks showing off security loopholes that bugs me - "we're just showing all the ways in which this system sucks, so we're really the good guys." Right. And if I walk up to you on the street and stab you in the eye with my pen, I'm just showing you how vulnerable you are by not wearing body armor and a helmet with a face shield.
In this case it's probably more like this: Government is selling everyone body expensive armour that claims to protect your vitals against BIC pen stabbings, built by contractors who are buddies with those in power. A group of hackers walk around and take pictures of holes on people's armours. They also demonstrate stabbing a dummy wearing said expensive armour.
I am seriously tempted to buy one now, though.
However, these slides go beyond that, briefly covering many avenues that seem to be more aimless mischief than serious analysis. Most of the slides remind me more of the Anarchist Cookbook than a vulnerability disclosure. I wonder why they didn't include the "hop over the gate" and "pay with counterfeit money" exploits?
I tried the Scribd vacuum link right after posting and I got an error saying that the PDF was encrypted, so it wouldn't be able to show it. I think that result gets cached and Scribd just redirects to the PDF for subsequent requests.
Still, I'm glad to know what the best minds of my generation are up to: utilizing their magnificent collective genius to steal the occasional nickel. The occasional dime. Great work, guys. Here's a quarter. Einstein always held out for the quarters...
Here's a tip: Just pay the goddamned fare and get some real work done. Thanks.
Seymour cray [iirc] had an algorithm for buying the best car:
1. Enter dealership.
2. Point at car.
3. Purchase car.
...point is: Don't worry about the trivial parts of life.