<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: gag]]></title>
    <link>http://securityratty.com/tag/gag</link>
    <description></description>
    <pubDate>Thu, 14 Aug 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ Mythbusters Episode on RFID Security Nixed]]></title>
      <link>http://securityratty.com/article/cdb83c68d92b899f0de2ab938d8e6cd6</link>
      <guid>http://securityratty.com/article/cdb83c68d92b899f0de2ab938d8e6cd6</guid>
      <description><![CDATA[Seems that the idea was killed by lawyers under pressure from the credit card industry. Or maybe not; the person who started this rumor has retracted his comments. Or maybe those same lawyers made him...]]></description>
      <content:encoded><![CDATA[<p>Seems that the idea <a href="http://www.tomshardware.com/news/Mythbuster-RFID-HOPE,6313.html">was</a> <a href=http://news.cnet.com/8301-13772_3-10030509-52.html?tag=newsEditorsPicksArea.0">killed</a> <a href="http://consumerist.com/5043831/mythbusters-gagged-credit-card-companies-kill-episode-exposing-rfid-security-flaws">by</a> <a href="http://www.youtube.com/watch?v=-St_ltH90Oc">lawyers</a> under pressure from the credit card industry.  Or maybe not; the person who started this rumor has retracted his comments.  Or maybe those same lawyers made him retract his comments.</p>

<p>Don't they know that security by gag order never works, except temporarily?</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=krFXL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=krFXL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=o045L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=o045L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 10:34:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card industry">credit card industry</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/pressure">pressure</category>
      <category domain="http://securityratty.com/tag/retract">retract</category>
      <category domain="http://securityratty.com/tag/gag">gag</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/idea">idea</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/mythbusters_epi.html"> Mythbusters Episode on RFID Security Nixed</source>
    </item>
    <item>
      <title><![CDATA[Judge Lifts Gag Order on Flaw-Finding MIT Students]]></title>
      <link>http://securityratty.com/article/4f47ebdae22e47ac2a0af21da3c2f930</link>
      <guid>http://securityratty.com/article/4f47ebdae22e47ac2a0af21da3c2f930</guid>
      <description><![CDATA[A federal judge lifted a gag order against three MIT students, freeing them to publicly discuss security flaws that they found in the ticketing system of Boston's mass-transit...]]></description>
      <content:encoded><![CDATA[A federal judge lifted a gag order against three MIT students, freeing them to publicly discuss security flaws that they found in the ticketing system of Boston's mass-transit agency.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=tSmB87"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=tSmB87" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/373934491" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 00:30:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/mass-transit agency">mass-transit agency</category>
      <category domain="http://securityratty.com/tag/gag">gag</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/373934491/article.do">Judge Lifts Gag Order on Flaw-Finding MIT Students</source>
    </item>
    <item>
      <title><![CDATA[3 takeaways from MBTA, MIT student legal flap]]></title>
      <link>http://securityratty.com/article/96a37cd079ca363e33ed1819c1d64e90</link>
      <guid>http://securityratty.com/article/96a37cd079ca363e33ed1819c1d64e90</guid>
      <description><![CDATA[Earlier this week, a federal judge in Boston lifted a gag order that had blocked three MIT students them from publicly discussing security flaws they discovered in the fare-payment system used by the...]]></description>
      <content:encoded><![CDATA[Earlier this week, a federal judge in Boston lifted a gag order that had blocked three MIT students them from publicly discussing security flaws they discovered in the fare-payment system used by the city's mass-transit agency.]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mass-transit agency">mass-transit agency</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/fare-payment system">fare-payment system</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/gag">gag</category>
      <category domain="http://securityratty.com/tag/publicly">publicly</category>
      <source url="http://www.networkworld.com/news/2008/082208-3-takeaways-from-mbta-mit.html?fsrc=rss-security">3 takeaways from MBTA, MIT student legal flap</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
    <item>
      <title><![CDATA[Gag order against MIT students dissolved by judge]]></title>
      <link>http://securityratty.com/article/df6ab1afba8fe7ae11e5a3d618ef499f</link>
      <guid>http://securityratty.com/article/df6ab1afba8fe7ae11e5a3d618ef499f</guid>
      <description><![CDATA[A federal judge lifted a restraining order that had blocked three MIT students from publicly discussing security flaws they found in the Boston-area transit agency's ticketing...]]></description>
      <content:encoded><![CDATA[A federal judge lifted a restraining order that had blocked three MIT students from publicly discussing security flaws they found in the Boston-area transit agency's ticketing system.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=rbRMJZ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=rbRMJZ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/369285736" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/boston-area transit agency">boston-area transit agency</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/publicly">publicly</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/369285736/article.do">Gag order against MIT students dissolved by judge</source>
    </item>
    <item>
      <title><![CDATA[Gag order against MIT students gets another day in court]]></title>
      <link>http://securityratty.com/article/f39c89809d68a8df92b5f27b1689cc2a</link>
      <guid>http://securityratty.com/article/f39c89809d68a8df92b5f27b1689cc2a</guid>
      <description><![CDATA[A federal judge in Boston will decide on Tuesday whether to extend or let expire a restraining order enjoining three students at MIT from publicly speaking about security flaws they discovered in the...]]></description>
      <content:encoded><![CDATA[A federal judge in Boston will decide on Tuesday whether to extend or let expire a restraining order enjoining three students at MIT from publicly speaking about security flaws they discovered in the electronic fare-payment system used by the city's mass transit agency.]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mass transit agency">mass transit agency</category>
      <category domain="http://securityratty.com/tag/electronic fare-payment system">electronic fare-payment system</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/mit">mit</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/extend">extend</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/081908-gag-order-against-mit-students.html?fsrc=rss-security">Gag order against MIT students gets another day in court</source>
    </item>
    <item>
      <title><![CDATA[Judge dissolves gag order against MIT students]]></title>
      <link>http://securityratty.com/article/6965e186a19999735479985f3fdc4b20</link>
      <guid>http://securityratty.com/article/6965e186a19999735479985f3fdc4b20</guid>
      <description><![CDATA[A U.S. District court judge on Tuesday dissolved a gag order against a trio of MIT students who say they found flaws in the Massachusetts transit authority's ticketing...]]></description>
      <content:encoded><![CDATA[A U.S. District court judge on Tuesday dissolved a gag order against a trio of MIT students who say they found flaws in the Massachusetts transit authority's ticketing system.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=67109?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=67109?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/massachusetts transit authority">massachusetts transit authority</category>
      <category domain="http://securityratty.com/tag/district court judge">district court judge</category>
      <category domain="http://securityratty.com/tag/gag">gag</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/trio">trio</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/081908-judge-dissolves-gag-order-against.html?fsrc=rss-security">Judge dissolves gag order against MIT students</source>
    </item>
    <item>
      <title><![CDATA[Judge disolves gag order against MIT students]]></title>
      <link>http://securityratty.com/article/a21ac39cf02792eb7ab4fe9caae208f1</link>
      <guid>http://securityratty.com/article/a21ac39cf02792eb7ab4fe9caae208f1</guid>
      <description><![CDATA[A U.S. District Court judge on Tuesday dissolved a gag order against a trio of MIT students who said they found flaws in the Massachusetts transit authority's ticketing...]]></description>
      <content:encoded><![CDATA[A U.S. District Court judge on Tuesday dissolved a gag order against a trio of MIT students who said they found flaws in the Massachusetts transit authority's ticketing system.]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/massachusetts transit authority">massachusetts transit authority</category>
      <category domain="http://securityratty.com/tag/district court judge">district court judge</category>
      <category domain="http://securityratty.com/tag/gag">gag</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/trio">trio</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/081908-judge-disolves-gag-order-against.html?fsrc=rss-security">Judge disolves gag order against MIT students</source>
    </item>
    <item>
      <title><![CDATA[Gag Order Slapped on MIT Students for Finding Security Flaws]]></title>
      <link>http://securityratty.com/article/cf4f4667d3c6bbdacd8155768aa60875</link>
      <guid>http://securityratty.com/article/cf4f4667d3c6bbdacd8155768aa60875</guid>
      <description><![CDATA[A court order put a stop to a planned presentation at the Defcon hackers convention by three MIT students who found security flaws in the electronic ticketing system used by the mass transit authority...]]></description>
      <content:encoded><![CDATA[A court order put a stop to a planned presentation at the Defcon hackers convention by three MIT students who found security flaws in the electronic ticketing system used by the mass transit authority in Boston. But the ruling reopened the schism in the IT security community over the issue of how vulnerabilities should be publicly disclosed.]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 18:40:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/mass transit authority">mass transit authority</category>
      <category domain="http://securityratty.com/tag/defcon hackers convention">defcon hackers convention</category>
      <category domain="http://securityratty.com/tag/security community">security community</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://digg.com/security/Gag_Order_Slapped_on_MIT_Students_for_Finding_Security_Flaws">Gag Order Slapped on MIT Students for Finding Security Flaws</source>
    </item>
    <item>
      <title><![CDATA[Judge refuses to lift gag order on MIT students in Boston subway-hack case]]></title>
      <link>http://securityratty.com/article/8a1f16a75fa0fa6e28d5a67d6fbe5aff</link>
      <guid>http://securityratty.com/article/8a1f16a75fa0fa6e28d5a67d6fbe5aff</guid>
      <description><![CDATA[A federal judge left in place a temporary restraining order barring three MIT students from publicly discussing details of security flaws they found in the e-ticketing system used by Boston's mass...]]></description>
      <content:encoded><![CDATA[A federal judge left in place a temporary restraining order barring three MIT students from publicly discussing details of security flaws they found in the e-ticketing system used by Boston's mass transit authority.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=q6caOA"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=q6caOA" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/365074281" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/mass transit authority">mass transit authority</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/temporary">temporary</category>
      <category domain="http://securityratty.com/tag/publicly">publicly</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/365074281/article.do">Judge refuses to lift gag order on MIT students in Boston subway-hack case</source>
    </item>
  </channel>
</rss>
