SlideShare ist ein Scribd-Unternehmen logo
1 von 13
Audit of the Charlie Ticketing SystemFor the Massachusetts Bay Transportation Authority Team China Auditing Luke, Dylan, Scott, and Craig.
The Incident Three MIT students explored the obvious weaknesses at the MBTA. The MBTA’s fare-collection system named the Charlie Card was “hacked” to show false values. The entire MBTA facility was shown to be lacking security in general.
What Happened? The students got into the building through unlocked doors. Many locks were unlocked on rooms, phone boxes, and networking systems.  They also found a key and other physical identification that should not have been laying around. They also eventually hacked the Charlie card’s mag-stripe value and then explored the RFID cards. They documented their entire experience with photos and assembled a slideshow.  Link Here
Recommendations Risk Assessment (Internal & Third-party) Improve Physical Security Access Control Hardware & Software Visitor Management System
Risk Assessment Regularly scheduled (Internal & Third-party) Management, Security and end-user involvement Reports to identify risk areas and levels CounterMeasures® – Risk Analysis Software $14,500 (CounterMeasures®, n.d.) RFP’s to be reviewed for vendor selection
Physical Security Access Control Hardware & Software Increase security by eliminating keys Provide management, audit tracking and incident response Typical installations $1500 - $2500 per door (Access control, n.d.) RFP’s to be reviewed for vendor selection
Physical Security Visitor Management System – Lobby Track™ Increased control and security of visitors in MBTA facilities Security desk, on-line or self-registration kiosk check-in available $1800 per location (Edition Comparison, n.d.)
Questions?
Thank You Team China Auditing Luke, Dylan, Scott, and Craig.
References Access control system pricing. (n.d.). Retrieved May 6, 2010, from BuyerZone: http://www.buyerzone.com/security/access_control/buyers_guide6.html Ahlers, M. M., & Quijano, E. (2009, May 20). National Archives loses hard drive with Clinton era records. Retrieved March 10, 2010, from  	CNN Politics:http://www.cnn.com/2009/POLITICS/05/20/lost.hard.drive.clinton/   Baxter, C. (2008, August 12). MIT students' report makes security recommendations to T. Retrieved April 20, 2010, from The Boston  Globe:http://www.boston.com/news/local/articles/2008/08/12/mit_students_report_makes_security_recommendations_to_t/   B., B. (2008). CRACKING THE CHARLIE CARD. CSO Magazine, 7(8), 17. Retrieved from Risk Management Reference Center database.    COBIT Student Book. (2004). COBIT in Academia. Rolling Measows, IL: IT Governance Institude.  	http://alarcos.inf-cr.uclm.es/doc/Auditoria/Cobit_Student_Book.pdf     CounterMeasures®Enterprise Platform 8.1. (n.d.). Retrieved May 10, 2010, from CounterMeasures Risk Analysis Software: http://www.countermeasures.com/enterprise_platform_product.htm Edition Comparison. (n.d.). Retrieved May 10, 2010, from Jolly Lobby Track: http://www.jollytech.com/products/lobby_track/systems/edition_comparison.php Lewis, D. (2008, 8 20). MIT CharlieCard Hackers Gag Free. Retrieved April 6, 2010, from LiquidMatrix Security Digest:http://www.liquidmatrix.org/blog/2008/08/20/mit-charliecard-hackers-gag-free/   McGraw-Herdeg, M. (2008, August 14). Public Documents Seem to Show Free T Fare. Retrieved March 10, 2010, from The Tech, Online Edition:http://tech.mit.edu/V128/N30/subwayvulnerabilities.html  
References Cntd. McNamara, P. (2008, 8 11). Exclusive: 'MBTA vs. MIT' lawsuit really about Charlie, not CharlieCard. Retrieved April 6, 2010, from Network World:http://www.networkworld.com/community/node/30940   Mills, E. (2008, Decemer 23). MIT students to help Boston secure subway fare system. Retrieved March 10, 2010, from CNET 	News:http://news.cnet.com/8301-1009_3-10128632-83.html?tag=mncol;title National Archives Offers Reward of Up to $50,000 for Return of a Missing Clinton Administration Hard Drive. (2009, May 29). Retrieved March 10, 2010,  from The National  Archives:http://www.archives.gov/press/press-releases/2009/nr09-89.html    Pesaturo. (2007, 3 05). MBTA Transit Police Charge Retiree with Theft. Retrieved April 6, 2010, from MBTA:http://www.mbta.com/about_the_mbta/news_events/?id=11063&month=&year=   Russell, R., Zack, A., & Alessandro, C. (2008, August 8). Anaomy of a Subway Hack. Retrieved March 10, 2010, 	from http://tech.mit.edu/V128/N30/subway/Defcon_Presentation.pdf   Szaniszlo, M. (2008, August 10). MIT students barred from exposing MBTA security flaws. Retrieved March 10, 2010, from Boston Herald: http://news.bostonherald.com/news/regional/general/view.bg?articleid=1112081&srvc=home&position=emailed   Szaniszlo, M. (2008, 8 14). Board member demands MBTA audit. Retrieved April 6, 2010, 	from http://www.bostonherald.com:http://www.eff.org/files/filenode/MBTA_v_Anderson/Exhibit%207.pdf   Szaniszlo, M. (2008, 8 15). MIT students must turn in CharlieCard data today. Retrieved April 6, 2010, from Boston Herald:http://www.bostonherald.com/news/regional/general/view.bg?articleid=1113095   Vijayan, J. (2008). Flap Over Transit Flaws Exposes Disclosure Divide. (Cover story). Computerworld, 42(33), 10. Retrieved from Academic Search Premier database.

Weitere ähnliche Inhalte

Andere mochten auch

Lista de jodecure 2012
Lista de jodecure 2012Lista de jodecure 2012
Lista de jodecure 2012
rhinojosa72
 
Diapositivas etapas de lowenfeld
Diapositivas  etapas de lowenfeldDiapositivas  etapas de lowenfeld
Diapositivas etapas de lowenfeld
lina3122
 
F1 ricardo hernández-mipresentación
F1 ricardo hernández-mipresentaciónF1 ricardo hernández-mipresentación
F1 ricardo hernández-mipresentación
Richard Cope
 
Convergencia Analisi 1
Convergencia Analisi 1Convergencia Analisi 1
Convergencia Analisi 1
José gonz?ez
 

Andere mochten auch (20)

Lista de jodecure 2012
Lista de jodecure 2012Lista de jodecure 2012
Lista de jodecure 2012
 
Best of Microsoft Dev Camp 2015
Best of Microsoft Dev Camp 2015Best of Microsoft Dev Camp 2015
Best of Microsoft Dev Camp 2015
 
Telecom frecuencias
Telecom frecuenciasTelecom frecuencias
Telecom frecuencias
 
Diapositivas etapas de lowenfeld
Diapositivas  etapas de lowenfeldDiapositivas  etapas de lowenfeld
Diapositivas etapas de lowenfeld
 
Business and career opportunities around 3D printing
Business and career opportunities around 3D printingBusiness and career opportunities around 3D printing
Business and career opportunities around 3D printing
 
USGS Study of Marcellus Shale Wastewater Radioactivity Levels
USGS Study of Marcellus Shale Wastewater Radioactivity LevelsUSGS Study of Marcellus Shale Wastewater Radioactivity Levels
USGS Study of Marcellus Shale Wastewater Radioactivity Levels
 
Plasma Buch - Keshe Foundation
Plasma Buch - Keshe FoundationPlasma Buch - Keshe Foundation
Plasma Buch - Keshe Foundation
 
Metnor3 comp
Metnor3 compMetnor3 comp
Metnor3 comp
 
Tienda Virtual
Tienda Virtual Tienda Virtual
Tienda Virtual
 
A Case study scenario on collaborative Portal Risk Assessment
A Case study scenario on collaborative Portal Risk Assessment A Case study scenario on collaborative Portal Risk Assessment
A Case study scenario on collaborative Portal Risk Assessment
 
Productos Financieros
Productos FinancierosProductos Financieros
Productos Financieros
 
Catalog Metasol Susol ACB LS technical
Catalog Metasol Susol ACB LS technicalCatalog Metasol Susol ACB LS technical
Catalog Metasol Susol ACB LS technical
 
F1 ricardo hernández-mipresentación
F1 ricardo hernández-mipresentaciónF1 ricardo hernández-mipresentación
F1 ricardo hernández-mipresentación
 
Presentación Gabriel Neumeyer
Presentación Gabriel NeumeyerPresentación Gabriel Neumeyer
Presentación Gabriel Neumeyer
 
Encuesta
EncuestaEncuesta
Encuesta
 
Dinámica de detección de necesidades formativas
Dinámica de detección de necesidades formativasDinámica de detección de necesidades formativas
Dinámica de detección de necesidades formativas
 
PBO Fisioterapia
PBO FisioterapiaPBO Fisioterapia
PBO Fisioterapia
 
Convergencia Analisi 1
Convergencia Analisi 1Convergencia Analisi 1
Convergencia Analisi 1
 
Proyecto kandinsky
Proyecto kandinskyProyecto kandinsky
Proyecto kandinsky
 
The unlucky 13 - the early warning signs of potential workplace violence
The unlucky 13   - the early warning signs of potential workplace violenceThe unlucky 13   - the early warning signs of potential workplace violence
The unlucky 13 - the early warning signs of potential workplace violence
 

Ähnlich wie Audit Of The Charlie Ticketing System

Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
Kenneth Hans
 
LECTURE 5 - Cyberculture
LECTURE 5 - CybercultureLECTURE 5 - Cyberculture
LECTURE 5 - Cyberculture
Kim Flintoff
 
Managing insider threat
Managing insider threatManaging insider threat
Managing insider threat
milliemill
 
2010 06-08 chania stochastic web modelling - copy
2010 06-08 chania stochastic web modelling - copy2010 06-08 chania stochastic web modelling - copy
2010 06-08 chania stochastic web modelling - copy
vafopoulos
 

Ähnlich wie Audit Of The Charlie Ticketing System (20)

Data Provenance for Data Science
Data Provenance for Data ScienceData Provenance for Data Science
Data Provenance for Data Science
 
Avoiding Machine Learning Pitfalls 2-10-18
Avoiding Machine Learning Pitfalls 2-10-18Avoiding Machine Learning Pitfalls 2-10-18
Avoiding Machine Learning Pitfalls 2-10-18
 
10probs.ppt
10probs.ppt10probs.ppt
10probs.ppt
 
How Future Technologies Could Impact the Silicon Valley Express Lanes
How Future Technologies Could Impact the Silicon Valley Express LanesHow Future Technologies Could Impact the Silicon Valley Express Lanes
How Future Technologies Could Impact the Silicon Valley Express Lanes
 
Criticality analysis of Critical Infrastructures (CI) – parameters and criter...
Criticality analysis of Critical Infrastructures (CI) – parameters and criter...Criticality analysis of Critical Infrastructures (CI) – parameters and criter...
Criticality analysis of Critical Infrastructures (CI) – parameters and criter...
 
Guest Lecture bw - soc 208 urban sociology
Guest Lecture bw  - soc 208 urban sociologyGuest Lecture bw  - soc 208 urban sociology
Guest Lecture bw - soc 208 urban sociology
 
Barbara Walters - Guest Lecture for SOC 208 Urban Sociology
Barbara Walters  - Guest Lecture for SOC 208 Urban SociologyBarbara Walters  - Guest Lecture for SOC 208 Urban Sociology
Barbara Walters - Guest Lecture for SOC 208 Urban Sociology
 
Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
Digital In Banking - Summary Trends - Virginia Bankers Association - March 2015
 
DEF CON 27 - BRENT STONE - reverse enginerring 17 cars
DEF CON 27 - BRENT STONE - reverse enginerring 17 carsDEF CON 27 - BRENT STONE - reverse enginerring 17 cars
DEF CON 27 - BRENT STONE - reverse enginerring 17 cars
 
China's internet policies and regulations
China's internet policies and regulationsChina's internet policies and regulations
China's internet policies and regulations
 
Security In an IoT World
Security In an IoT WorldSecurity In an IoT World
Security In an IoT World
 
Social Implications and Ethics
Social Implications and EthicsSocial Implications and Ethics
Social Implications and Ethics
 
Social and ethic.ppt
Social and ethic.pptSocial and ethic.ppt
Social and ethic.ppt
 
LECTURE 5 - Cyberculture
LECTURE 5 - CybercultureLECTURE 5 - Cyberculture
LECTURE 5 - Cyberculture
 
Managing insider threat
Managing insider threatManaging insider threat
Managing insider threat
 
Enhancing Cybersecurity in Public Transportation
Enhancing Cybersecurity in Public TransportationEnhancing Cybersecurity in Public Transportation
Enhancing Cybersecurity in Public Transportation
 
Intelligent transport systems from a freight company perspective
Intelligent transport systems from a freight company perspectiveIntelligent transport systems from a freight company perspective
Intelligent transport systems from a freight company perspective
 
ISTE Presentation Resource List
ISTE Presentation Resource ListISTE Presentation Resource List
ISTE Presentation Resource List
 
Avoiding Machine Learning Pitfalls 2-10-18
Avoiding Machine Learning Pitfalls 2-10-18Avoiding Machine Learning Pitfalls 2-10-18
Avoiding Machine Learning Pitfalls 2-10-18
 
2010 06-08 chania stochastic web modelling - copy
2010 06-08 chania stochastic web modelling - copy2010 06-08 chania stochastic web modelling - copy
2010 06-08 chania stochastic web modelling - copy
 

Kürzlich hochgeladen

Making and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdfMaking and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdf
Chris Hunter
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
QucHHunhnh
 
An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
SanaAli374401
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
kauryashika82
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
QucHHunhnh
 

Kürzlich hochgeladen (20)

Making and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdfMaking and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdf
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptx
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 

Audit Of The Charlie Ticketing System

  • 1. Audit of the Charlie Ticketing SystemFor the Massachusetts Bay Transportation Authority Team China Auditing Luke, Dylan, Scott, and Craig.
  • 2. The Incident Three MIT students explored the obvious weaknesses at the MBTA. The MBTA’s fare-collection system named the Charlie Card was “hacked” to show false values. The entire MBTA facility was shown to be lacking security in general.
  • 3. What Happened? The students got into the building through unlocked doors. Many locks were unlocked on rooms, phone boxes, and networking systems. They also found a key and other physical identification that should not have been laying around. They also eventually hacked the Charlie card’s mag-stripe value and then explored the RFID cards. They documented their entire experience with photos and assembled a slideshow. Link Here
  • 4. Recommendations Risk Assessment (Internal & Third-party) Improve Physical Security Access Control Hardware & Software Visitor Management System
  • 5.
  • 6. Risk Assessment Regularly scheduled (Internal & Third-party) Management, Security and end-user involvement Reports to identify risk areas and levels CounterMeasures® – Risk Analysis Software $14,500 (CounterMeasures®, n.d.) RFP’s to be reviewed for vendor selection
  • 7. Physical Security Access Control Hardware & Software Increase security by eliminating keys Provide management, audit tracking and incident response Typical installations $1500 - $2500 per door (Access control, n.d.) RFP’s to be reviewed for vendor selection
  • 8. Physical Security Visitor Management System – Lobby Track™ Increased control and security of visitors in MBTA facilities Security desk, on-line or self-registration kiosk check-in available $1800 per location (Edition Comparison, n.d.)
  • 9.
  • 11. Thank You Team China Auditing Luke, Dylan, Scott, and Craig.
  • 12. References Access control system pricing. (n.d.). Retrieved May 6, 2010, from BuyerZone: http://www.buyerzone.com/security/access_control/buyers_guide6.html Ahlers, M. M., & Quijano, E. (2009, May 20). National Archives loses hard drive with Clinton era records. Retrieved March 10, 2010, from CNN Politics:http://www.cnn.com/2009/POLITICS/05/20/lost.hard.drive.clinton/   Baxter, C. (2008, August 12). MIT students' report makes security recommendations to T. Retrieved April 20, 2010, from The Boston Globe:http://www.boston.com/news/local/articles/2008/08/12/mit_students_report_makes_security_recommendations_to_t/   B., B. (2008). CRACKING THE CHARLIE CARD. CSO Magazine, 7(8), 17. Retrieved from Risk Management Reference Center database.    COBIT Student Book. (2004). COBIT in Academia. Rolling Measows, IL: IT Governance Institude.   http://alarcos.inf-cr.uclm.es/doc/Auditoria/Cobit_Student_Book.pdf     CounterMeasures®Enterprise Platform 8.1. (n.d.). Retrieved May 10, 2010, from CounterMeasures Risk Analysis Software: http://www.countermeasures.com/enterprise_platform_product.htm Edition Comparison. (n.d.). Retrieved May 10, 2010, from Jolly Lobby Track: http://www.jollytech.com/products/lobby_track/systems/edition_comparison.php Lewis, D. (2008, 8 20). MIT CharlieCard Hackers Gag Free. Retrieved April 6, 2010, from LiquidMatrix Security Digest:http://www.liquidmatrix.org/blog/2008/08/20/mit-charliecard-hackers-gag-free/   McGraw-Herdeg, M. (2008, August 14). Public Documents Seem to Show Free T Fare. Retrieved March 10, 2010, from The Tech, Online Edition:http://tech.mit.edu/V128/N30/subwayvulnerabilities.html  
  • 13. References Cntd. McNamara, P. (2008, 8 11). Exclusive: 'MBTA vs. MIT' lawsuit really about Charlie, not CharlieCard. Retrieved April 6, 2010, from Network World:http://www.networkworld.com/community/node/30940   Mills, E. (2008, Decemer 23). MIT students to help Boston secure subway fare system. Retrieved March 10, 2010, from CNET News:http://news.cnet.com/8301-1009_3-10128632-83.html?tag=mncol;title National Archives Offers Reward of Up to $50,000 for Return of a Missing Clinton Administration Hard Drive. (2009, May 29). Retrieved March 10, 2010, from The National Archives:http://www.archives.gov/press/press-releases/2009/nr09-89.html    Pesaturo. (2007, 3 05). MBTA Transit Police Charge Retiree with Theft. Retrieved April 6, 2010, from MBTA:http://www.mbta.com/about_the_mbta/news_events/?id=11063&month=&year=   Russell, R., Zack, A., & Alessandro, C. (2008, August 8). Anaomy of a Subway Hack. Retrieved March 10, 2010, from http://tech.mit.edu/V128/N30/subway/Defcon_Presentation.pdf   Szaniszlo, M. (2008, August 10). MIT students barred from exposing MBTA security flaws. Retrieved March 10, 2010, from Boston Herald: http://news.bostonherald.com/news/regional/general/view.bg?articleid=1112081&srvc=home&position=emailed   Szaniszlo, M. (2008, 8 14). Board member demands MBTA audit. Retrieved April 6, 2010, from http://www.bostonherald.com:http://www.eff.org/files/filenode/MBTA_v_Anderson/Exhibit%207.pdf   Szaniszlo, M. (2008, 8 15). MIT students must turn in CharlieCard data today. Retrieved April 6, 2010, from Boston Herald:http://www.bostonherald.com/news/regional/general/view.bg?articleid=1113095   Vijayan, J. (2008). Flap Over Transit Flaws Exposes Disclosure Divide. (Cover story). Computerworld, 42(33), 10. Retrieved from Academic Search Premier database.