Fifteen years ago, a couple of MIT students planned to give a talk at Defcon about a vulnerability in the Massachusetts Bay Transit Authority's (MBTA) subway fare system. It was entitled Free Subway Rides For Life. The MBTA sued the students, and got a restraining order, canceling the talk and preventing the students from communicating truthful information to the public. I represented them (along with other EFF attorneys).
Fast forward to now. Two high school students have replicated the vuln, extended the research and gave a talk at Defcon this year. No, MTBA didn't bother to fix the problem.... BUUUT they did refrain from suing the researchers this time. And they even invited the students to HQ to give a presentation about their research.
I love this story and these students and am proud to have been a part of this history, and even more pleased that authorities have learned a lesson about appreciating hackers and the important work that you do.
https://www.wired.com/story/mtba-charliecard-hack-defcon-2023/
