this post was submitted on 11 Aug 2023
530 points (98.2% liked)

Technology

59298 readers
6313 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 16 points 1 year ago (1 children)

It's nice to see the MBTA being a bit more modern with their approach to security breaches. The overly hostile "We'll sue you if you tell anyone" tactic certainly would not encourage anyone to report anything they found so it could be fixed.

[–] [email protected] 7 points 1 year ago (1 children)

This is the ideal response to a system threat of this type, especially if they didn't know the vulnerability existed.

“It should be noted that the vulnerability identified by the students does NOT pose an imminent risk affecting safety, system disruption, or a data breach,” Pesaturo added.

That may be one of the most adult things ever said by an organization executive. Since they have a replacement system (hopefully more secure) in the works and they've used the data from he hackers to mitigate potential financial impacts to the system in the mean time, they're being completely level-headed about the process. It's a damned shame this doesn't happen more often.

[–] [email protected] 4 points 1 year ago

Absolutely. They even said in the article:

He’s also glad, on the other hand, that the MBTA took such a hardline approach to the 2008 talk that it got his attention and kickstarted the group’s research almost a decade and a half later. “If they hadn’t done that,” Harris says, “we wouldn’t be here.”

It's the Streisand Effect in full force; they drew attention to the vulnerability by fighting it so hard the first time. Who knows how many other people have found vulnerabilities since then that just haven't been vocal about it. (The article mentions one such person, even.)