Live data from Hacker News

A fraudster got $12M out of a Canadian university

thestar.com

81–90 of 119 posts

Re: A fraudster got $12M out of a Canadian university

#81
post #40

Earlier quoted context omitted.

>it’ll likely pay for itself soon enough. Thats the problem though right? "Paying for itself" means students paying higher costs which is the problem.

Only the students who feel the need to attend a university with state of the art facilities.

Unfortunately it's not such an easy decision when businesses value degrees more from universities with state of the art facilities.

Re: A fraudster got $12M out of a Canadian university

#82
post #40
post #38

Earlier quoted context omitted.

It’s not clear to me that $180 million is an unreasonable amount of money to spend on a state-of-the-art building with multiple music studios and dance halls, necessary for music or dance programs that the school (presumably) offers. Between the tuition the students pay, grants from government, and potential commercial use of the space (for concerts, shows, etc.) it’ll likely pay for itself soon enough. Also bear in…

>it’ll likely pay for itself soon enough. Thats the problem though right? "Paying for itself" means students paying higher costs which is the problem.

Ideally the school offers no facilities so the students don’t need to pay anything /s

That was the upshot of the second paragraph of my post - in Canada, students don’t pay an absurd amount, so it’s not really a problem.

Re: A fraudster got $12M out of a Canadian university

#83
post #71
post #21

Earlier quoted context omitted.

While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.

I disagree. Taking email out of the loop is a technical solution to a problem that is inherently social, not technical.

I don't see it as a technical solution, but fixing a broken process.

Re: A fraudster got $12M out of a Canadian university

#84
post #70

They quickly discovered that while the email appeared to have been sent by “accounts.recievable@clarkbuilders.com” the email address had been “spoofed.” The display name of the email was different than the actual originating account. Isn't this glaring security issue trivially fixable from the perspective of an email client developer?

No, because SMTP "accounts" are trivially spoofable as well. (Edit: Although you wouldn't want to spoof that if you need to get replies, so maybe there is something the client can do here.) Maybe you could try to do some kind of trust-on-first-use on the chain of Received headers but that's going to generate false positives.

We do have several solutions in place for that, though. SPF, DKIM, among others. If this University were running on gmail I suspect this email would have been flagged for phishing (the builder did publish an SPF record), or outright rejected. However they run their own email servers[1].

[1] - They could of course do the same checks and even more, but among self-hosted installs it is common to disregard those additional securities.

Re: A fraudster got $12M out of a Canadian university

#85
post #21

Earlier quoted context omitted.

While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.

Note that in this particular case the email in question had a signed document attached. So the scam could of been done with regular mail.The problem here was the lack of verification, not the medium of communication. The ease of forging emails is more of an issue where the spear phish email is trying to disguise itself as coming from inside the company.

Which is why I said it's a process problem. But you definitely want email out of the process since it's not reliable.

Re: A fraudster got $12M out of a Canadian university

#86

Did they ever find out who the masterminds were and were they charged criminally? I couldn't tell from the article.

I believe one unnamed person in China was caught with $5 million or so; but $960,000 CAD was still missing; so maybe not? Even if they only walked away with 8% of the total originally 'stolen', that's still pretty damn good.

Plus, it would probably bring the heat off of you. The investigators and the university get to say 'we successfully recovered 92% of it!' because that makes a great headline where 'justice was served' and have the case take a lower priority.

Re: A fraudster got $12M out of a Canadian university

#87

MacEwan was in the midst of constructing the $180-million Allard Hall: a state-of-the-art building boasting music studios and dance halls with room for 1,800 students Why does a college need a building that costs a large fraction of a billion dollars? Early this week we had an article about college education costs being one corner of the "Bermuda triangle" of personal finance. Out of control spending on new, shiny th…

I am not sure if this completely answers your question, however as a Edmontonian I can give a little feedback. The school has a very active arts and music department. These programs used to be taught in a separate building from the main campus, that was aging, and in a not so nice part of the city. For this reason I think it was consolidated to the main campus, and upgraded. You can read a bit about it here: https://…

>So although some may think that things like music studios are not a necessity, they are in this case.

No one said it was unnecessary; the GP questioned why it needed to be "state of the art".

Re: A fraudster got $12M out of a Canadian university

#88

Earlier quoted context omitted.

I think colleges are doing these things because of federally guaranteed student loans, because of the following chain of events: 1. Students are price insensitive for college if they don't have to pay for it up front. 2. Banks are incentivized to loan unlimited money to students because the federal government guarantees the loans with zero exceptions-- the bank gets repaid no matter what, so it's very low risk. 3. Co…

> The solution seems obvious to me. But nobody want to do it because it's political suicide. I like that this works for both readings. If you say to yourself "Obviously the solution is to eliminate federally backed student loans" that's political suicide because it means most people can't have a tertiary education (even if at some future date this chance means the institutions charge less than today) If you say to yo…

I'd like to eliminate federally backed student loans and replace that spending with federally backed student grants for the best students under a certain household income. That wouldn't make tuition rise in the same way, and it would still help poorer people go to college. AND they wouldn't have to pay back loans.

Re: A fraudster got $12M out of a Canadian university

#90

I get incomprehensible bills from the hospital whenever I get a test or see a physical therapist, etc. Sometimes I get bills about a service that happened 2 years ago, don't remember what the service was, and it seems they can't tell me because that would violate my privacy or something. I've always wondered if I sent an invoice to the hospital for unspecified services if they'd pay it.

> they can't tell me because that would violate my privacy or something

If someone can't tell you why you owe a bill, don't pay it. If they can't tell you, they can't tell a court.

Post reply on HN