• KoboldCoterie
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 year ago

    It’s nice to see the MBTA being a bit more modern with their approach to security breaches. The overly hostile “We’ll sue you if you tell anyone” tactic certainly would not encourage anyone to report anything they found so it could be fixed.

    • Overzeetop@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 year ago

      This is the ideal response to a system threat of this type, especially if they didn’t know the vulnerability existed.

      “It should be noted that the vulnerability identified by the students does NOT pose an imminent risk affecting safety, system disruption, or a data breach,” Pesaturo added.

      That may be one of the most adult things ever said by an organization executive. Since they have a replacement system (hopefully more secure) in the works and they’ve used the data from he hackers to mitigate potential financial impacts to the system in the mean time, they’re being completely level-headed about the process. It’s a damned shame this doesn’t happen more often.

      • KoboldCoterie
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        Absolutely. They even said in the article:

        He’s also glad, on the other hand, that the MBTA took such a hardline approach to the 2008 talk that it got his attention and kickstarted the group’s research almost a decade and a half later. “If they hadn’t done that,” Harris says, “we wouldn’t be here.”

        It’s the Streisand Effect in full force; they drew attention to the vulnerability by fighting it so hard the first time. Who knows how many other people have found vulnerabilities since then that just haven’t been vocal about it. (The article mentions one such person, even.)