University to Banks: Stick your Censorship


It feels as if everyone has told bankers where to get off in the past couple of years. That’s certainly the case with a letter written by Cambridge University, though this time it’s not a criticism of irresponsible lending and investment. Instead Britain’s banks have been told to go whistle after demanding that a student’s thesis be censored.

The thesis, by Omar Choudary of Darwin College, studying for a Master’s degree in Advanced Computer Science, built on work publicized earlier this year involving “chip and pin” security systems for debit and credit cards.

Choudary and colleagues discovered that it was possible to carry a card reader and stolen card in a bag, then present a dummy card for payment. By exploiting a loophole in the system and using a wireless connection to a laptop outside the store, someone could go around the new security measures.

At the time, the UK Cards Association dismissed the loophole as being too complicated in practice and maintained such misuse would trigger fraud alerts. Now it seems more concerned, writing to the college. The letter, which argues that Choudary’s thesis “breaches the boundary of responsible disclosure”, says that even though genuine fraudsters wouldn’t use the method, it could encourage “nuisance” attacks.

More fundamentally, the banks say they are concerned “that this type of research was ever considered suitable for publication by the University. It gives us cause to worry that future research, which may potentially be more damaging, may also be published in this level of detail.” The letter concluded with a request for the thesis to be removed from public access immediately.

To say the University’s reply was dismissive would be an understatement. After pointing out that technically it was Choudary rather than the university that published the thesis, and that it actually contained less detail than was previously made public, security professor Ross Anderson unleashed a blistering attack (PDF) on the entire principle of the banks’ request:

You seem to think that we might censor a student’s thesis, which is lawful and already in the public domain, simply because a powerful interest ?nds it inconvenient. This shows a deep misconception of what universities are and how we work. Cambridge is the University of Erasmus, of Newton, and of Darwin; censoring writings that offend the powerful is offensive to our deepest values. Thus even though the decision to put the thesis online was Omar’s, we have no choice but to back him. That would hold even if we did not agree with the material.

It’s fair to say the bank’s request has backfired spectacularly. Not only has the dispute drawn further media attention to the entire matter, but Anderson has responded by republishing the thesis as a report from the university, meaning it will be permanently available online in a high-profile fashion even if and when Choudary removes his own copy.


7 Responses to University to Banks: Stick your Censorship

    • Sad day for research…

      It's very unfortunate that when pointing out a flaw in someone's else's system instead of taking responsibility and doing the right thing, that is fix it, they point the finger of blame instead. The whole white hat and black hat is out there for a reason. This individual pointed out what the banks already knew could be done with the loophole in their system. That now becomes negligence on the parties involved with adopting that process. Forcing the student to take down his thesis is not the answer, fixing the problem or the loophole in the system is the answer!

      • This is a great day for research, Omars college stood behind him, and took it one step further. we need more people like those in the faculty and administration of Darwin college, and more people like Omar.

  1. The global monetary system is a den of vipers and thieves and by god we will rout them out! ~~~$y$tem Failure~~~

  2. Thank you Omar Choudary, and Darwin College. If people with valuable information and insight always bowed to corporate interests, and we all remained in the dark about our weaknesses, humanity would not last very long. I am glad that there are still people who value principle over the heavy handed interests of corporations.