Live data from Hacker News

I “found” the database of a college app (2018)

yoginth.com

71–80 of 107 posts

Re: I “found” the database of a college app (2018)

#71
post #67

Earlier quoted context omitted.

The first linked tweeter thread is from July 2018, the second is from November 2018. I don't classify that as "too old". And your article is dated October 25, 1028, so it's approximately the same period of time. Also, your article is extremely similar to https://medium.com/@fs0c131y/how-i-found-the-database-of-the... (Oct 16, 2018)

That's the time I found the bug by the inspiration of "Elliot Alderson"

For example compare:

> Static Analysis

> From my phone, I exported the APK to my computer. I used the app called APK Export

> Play Store Link

> I used apktool to get the resources of the app.

> I used jadx to obtain the decompiled source code from the extracted DEX file.

> Now, I have everything I need.

----- with ------

> Static Analysis

> 1) From my phone, I exported the APK to my computer. You can use this app for example:

> [APK Export (Backup & Share) - Apps on Google Play]

> 2) An APK is a ZIP file, so I unzipped it and extracted the DEX file.

> 3) Thanks to jadx, I managed to obtain the decompiled source code from the extracted DEX file.

> 4) To finish, I used apktool to get the resources of the app.

> Now, I have everything I need.

Re: I “found” the database of a college app (2018)

#72
post #69

Earlier quoted context omitted.

You've built an entire online presence by copying everything from other people's work - from your blog theme to your content "without knowing"? Adorable. Also, by briefly reading the docs on the "platform" you are trying to peddle, I'm getting fairly certain you also copied that as well, as it is too well written in comparison to the drivel on your blog.

In all fairness on that last point, if you're referring to his "Gitote" project, the author has stated here [0] that it was a fork of Gogs, and seems to have retained the proper copyright notices in the source files: "// Copyright 2015 - Present, The Gogs Authors. All rights reserved. // Copyright 2018 - Present, Gitote. All rights reserved." [1] I agree it should probably have been given more prominent mention, but…

It was accepted by the founder itself https://twitter.com/jc_unknwon/status/1066713466524848128

Re: I “found” the database of a college app (2018)

#73
post #62

Earlier quoted context omitted.

Hey, that is too old and I have done it without knowledge, it's my mistake and I apologized for all of them personally and publicly! Here this app belongs to my college, it's my attendance and work is mine!

You've built an entire online presence by copying everything from other people's work - from your blog theme to your content "without knowing"? Adorable. Also, by briefly reading the docs on the "platform" you are trying to peddle, I'm getting fairly certain you also copied that as well, as it is too well written in comparison to the drivel on your blog.

[deleted]

Re: I “found” the database of a college app (2018)

#74

A school that tracks attendance cannot be called a college or university. Kindergarten, I can swallow.

I'm not sure if you are in the industry, but attendance tracking is high up on most institutions lists of metrics to track. Aside from helping out the usual back office data, it's often a key indicator for students who are in trouble. The institution can then reach out and assist these students.

In the UK, I think universities have to track attendance if only to make the immigration authorities happy.

Re: I “found” the database of a college app (2018)

#75
post #21

Earlier quoted context omitted.

Security and usability are always at the opposite end of the spectrum. Balance it wisely.

This is such a dangerous false dichotomy. Plenty of security systems benefit user experience.

And the security of a system can be completely undermined if nobody uses it because of poor user experience.

Re: I “found” the database of a college app (2018)

#76
post #21

Earlier quoted context omitted.

Security and usability are always at the opposite end of the spectrum. Balance it wisely.

This is such a dangerous false dichotomy. Plenty of security systems benefit user experience.

And in fact some systems are only usable because of their security. A bank that gives all accounts the same password could hardly be considered usable, neither could many websites if they did the same.

Re: I “found” the database of a college app (2018)

#77

Earlier quoted context omitted.

I'm not sure if you are in the industry, but attendance tracking is high up on most institutions lists of metrics to track. Aside from helping out the usual back office data, it's often a key indicator for students who are in trouble. The institution can then reach out and assist these students.

In the UK, I think universities have to track attendance if only to make the immigration authorities happy.

Yes, it's part of the conditions to be a sponsor of "Tier 4" (student) visas.

Re: I “found” the database of a college app (2018)

#78
post #55

Earlier quoted context omitted.

> he didn't do anything special to hack... Someone who snatched a purse out the hand of someone else isn’t “doing anything special” either. The illegality doesn’t hinge on the difficulty of the action. Why is that so hard to grasp for technical crowds? If you find a car with the keys in the ignition and the door unlocked, you won’t get away with driving it a block down the road by telling the judge: “Oh, but it was o…

This is more like walking up to the bank at night and jiggling the door handle then telling everyone it’s unlocked and the alarm isn’t on.

The author straight up admits to scraping the database!

That's clearly a point at which "Hm... I think this is insecure, can I actually pull this?" turns into criminal behavior.

Re: I “found” the database of a college app (2018)

#79
post #33

The media would have a field day and say that he hacked his school database. It's crazy how so many institutions are doing the digital equivalent of leaving an unlocked car in a bad neighbourhood and no one holds them accountable. Most people understand the concept of an unlocked car, not many understand that he didn't do anything special to hack his school db. He just strolled right in.

Not only are they leaving it unlocked, they are handing the keys to anyone who downloads the app.

Re: I “found” the database of a college app (2018)

#80
post #55
post #33

The media would have a field day and say that he hacked his school database. It's crazy how so many institutions are doing the digital equivalent of leaving an unlocked car in a bad neighbourhood and no one holds them accountable. Most people understand the concept of an unlocked car, not many understand that he didn't do anything special to hack his school db. He just strolled right in.

> he didn't do anything special to hack... Someone who snatched a purse out the hand of someone else isn’t “doing anything special” either. The illegality doesn’t hinge on the difficulty of the action. Why is that so hard to grasp for technical crowds? If you find a car with the keys in the ignition and the door unlocked, you won’t get away with driving it a block down the road by telling the judge: “Oh, but it was o…

The data that's available isn't the school, it's student data! The school left the students "cars unlocked" and no one holds them accountable. They just say that people shouldn't steal cars.
Post reply on HN