<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: MBTA drops lawsuit against MIT subway hackers</title>
	<atom:link href="http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:59:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: mykeyfinn</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56577</link>
		<dc:creator><![CDATA[mykeyfinn]]></dc:creator>
		<pubDate>Fri, 26 Dec 2008 02:11:23 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56577</guid>
		<description><![CDATA[Not just could have, but probally did.  All the did was expose and fed up system, whereas someone else would have just used the info and said nothing.  Sometimes it takes threat to get people to fis there problems.  I had to pen test my bank and show the branch manager the results in non-geek to get them to upgrade security, same deal.]]></description>
		<content:encoded><![CDATA[<p>Not just could have, but probally did.  All the did was expose and fed up system, whereas someone else would have just used the info and said nothing.  Sometimes it takes threat to get people to fis there problems.  I had to pen test my bank and show the branch manager the results in non-geek to get them to upgrade security, same deal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zypher</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56403</link>
		<dc:creator><![CDATA[zypher]]></dc:creator>
		<pubDate>Wed, 24 Dec 2008 08:49:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56403</guid>
		<description><![CDATA[Could brute force that with Legos. = lulz]]></description>
		<content:encoded><![CDATA[<p>Could brute force that with Legos. = lulz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TJHooker</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56401</link>
		<dc:creator><![CDATA[TJHooker]]></dc:creator>
		<pubDate>Wed, 24 Dec 2008 08:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56401</guid>
		<description><![CDATA[@joe: Anyone could do it based off the information in the PDF, and probably without it. It would of been cool if it used some type of self modifying code and obfuscation though to make the attack seem sophisticated.

Most people ignored I think because nobody cares about public transit that much.]]></description>
		<content:encoded><![CDATA[<p>@joe: Anyone could do it based off the information in the PDF, and probably without it. It would of been cool if it used some type of self modifying code and obfuscation though to make the attack seem sophisticated.</p>
<p>Most people ignored I think because nobody cares about public transit that much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56325</link>
		<dc:creator><![CDATA[Joe]]></dc:creator>
		<pubDate>Tue, 23 Dec 2008 20:06:44 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56325</guid>
		<description><![CDATA[The system was pathetically covered. If you read the slides it is obvious that the co that build it halfassed it. For instance, the top secret checksum was only 5 bits with a whopping 64 possible permutations. Could brute force that with Legos.

I read some of these cards when they first came out in &#039;06 and thought it looked simple. The barn door was freaking wide open and the just happened to be the ones to tell the world. 

Read up, it is a great hoot, especially the gag request court papers. Starts out with an entire page of credentials by the MBTA security head. Then says the system is supersecure and that no one could easily break in. Even says cards were heavily encrypted. False on all counts when you look at the decon report.

MBTA is a mess, and likely will continue to be. let them blame it all on those insanely smart kids in Cambridge. Who else could pull it off? Its too bad they had to be &quot;MIT&quot; kids to do it, which makes people think that it was very complex, but the folks down at Bunker Hill Community College could have done most of it too.]]></description>
		<content:encoded><![CDATA[<p>The system was pathetically covered. If you read the slides it is obvious that the co that build it halfassed it. For instance, the top secret checksum was only 5 bits with a whopping 64 possible permutations. Could brute force that with Legos.</p>
<p>I read some of these cards when they first came out in &#8217;06 and thought it looked simple. The barn door was freaking wide open and the just happened to be the ones to tell the world. </p>
<p>Read up, it is a great hoot, especially the gag request court papers. Starts out with an entire page of credentials by the MBTA security head. Then says the system is supersecure and that no one could easily break in. Even says cards were heavily encrypted. False on all counts when you look at the decon report.</p>
<p>MBTA is a mess, and likely will continue to be. let them blame it all on those insanely smart kids in Cambridge. Who else could pull it off? Its too bad they had to be &#8220;MIT&#8221; kids to do it, which makes people think that it was very complex, but the folks down at Bunker Hill Community College could have done most of it too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TJHooker</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56316</link>
		<dc:creator><![CDATA[TJHooker]]></dc:creator>
		<pubDate>Tue, 23 Dec 2008 19:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56316</guid>
		<description><![CDATA[When I heard MIT students where being threatened I knew the EFF would be all over it. Good thing they didn&#039;t go to a state university(sarcasm.)

I wonder where all the non-commercial-interest digital rights advocates that supported the eff went.

I won&#039;t list all the cases the eff has completely ignored over at least the past two and a half years. There execs must of done lunch with the prosecutions execs during the trials.]]></description>
		<content:encoded><![CDATA[<p>When I heard MIT students where being threatened I knew the EFF would be all over it. Good thing they didn&#8217;t go to a state university(sarcasm.)</p>
<p>I wonder where all the non-commercial-interest digital rights advocates that supported the eff went.</p>
<p>I won&#8217;t list all the cases the eff has completely ignored over at least the past two and a half years. There execs must of done lunch with the prosecutions execs during the trials.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tommy</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56288</link>
		<dc:creator><![CDATA[Tommy]]></dc:creator>
		<pubDate>Tue, 23 Dec 2008 16:50:07 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56288</guid>
		<description><![CDATA[@aaron:  Much more diplomatic about cranial location than I would have been.
:-)]]></description>
		<content:encoded><![CDATA[<p>@aaron:  Much more diplomatic about cranial location than I would have been.<br />
:-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://hackaday.com/2008/12/23/mbta-drops-lawsuit-against-mit-subway-hackers/comment-page-1/#comment-56286</link>
		<dc:creator><![CDATA[Aaron]]></dc:creator>
		<pubDate>Tue, 23 Dec 2008 16:24:26 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7166#comment-56286</guid>
		<description><![CDATA[From what I remember, the students went to the MBTA and they didn&#039;t want to listen to them in the first place.  Now they want to work together and improve the security.  Finally the MBTA woke up and got their heads out of the sand.]]></description>
		<content:encoded><![CDATA[<p>From what I remember, the students went to the MBTA and they didn&#8217;t want to listen to them in the first place.  Now they want to work together and improve the security.  Finally the MBTA woke up and got their heads out of the sand.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

