Live data from Hacker News

I “found” the database of a college app (2018)

yoginth.com

81–90 of 107 posts

Re: I “found” the database of a college app (2018)

#81
post #60
post #33

The media would have a field day and say that he hacked his school database. It's crazy how so many institutions are doing the digital equivalent of leaving an unlocked car in a bad neighbourhood and no one holds them accountable. Most people understand the concept of an unlocked car, not many understand that he didn't do anything special to hack his school db. He just strolled right in.

The car analogy would be: He saw a car He tried the doors until he found one that was open He climbed in and searched everywhere until he found personal information about other users of the system Even though the security of this system was poor, he still (probably) broke the law. There are plenty of opportunities for people with some knowledge of IT to abuse their power, but it's our responsibility not to do so.

He looked in the window of a car and saw tons of users' personal information -- visible through the window! Any criminal could walk by and copy the info, privately, without anyone knowing. Maybe some criminals already have.

I think the important thing we miss with car/physical crime analogies is that cybercrime can be so invisible. Nothing is missing, nothing is taken... but users private data is lost. So if an organization is doing something terribly naive like publishing passwords to userdata in plaintext... it's disgusting for our society to punish the wrong people, the people pointing out the flaws rather than the ones who cause them. All the really malicious entities came and went and will never be caught.

They put private information into a JSON file accessible by an HTTPS GET, the only password being one that they put in plaintext onto everyone's phones.

My analogy: They put the private information onto a billboard, but you can only see the billboard from a particular vantage point in a public park.

Re: I “found” the database of a college app (2018)

#82

Earlier quoted context omitted.

They might just not be from the US. Here in Germany, tracking or forcing student attendance is subject of large discussions and generally often frowned upon (or forbidden by regulation) in the University setting these days.

This is mind boggling. Failing someone for missing one or two classes is ludicrous, but giving someone a certificate who didn't engage with the course is equally so. University education isn't about the destination/exam it's about the journey.

University education isn't about the destination/exam it's about the journey.

There are more paths to the final destination than just turning up to all of your lectures, particularly if a lecturer is not doing a good job of presenting the material.

One of the controversial issues here in the UK at the moment is how much students are now paying for their university fees compared to how much value the university offers in return. Governments over the past generation or so have turned undergraduate degrees into a much more commercial proposition: you're taking on a lot of debt, but you're leaving with (in theory, according to the marketing brochure) much better career prospects.

At the same time, advances in technology and communications are rendering obsolete the old school lectures where you turn up and transfer the lecturer's notes from their paper to yours without passing through either brain along the way. You can find some of the best presentations of subjects ever given in freely available videos online today. Manually transcribing notes (or typing them on your laptop, or whatever) is largely a waste of time when you can just download well-written notes and spend your time in a lecture actually concentrating on understanding the material. For many courses, you really need to look at multiple sources anyway, to avoid getting tied up with a single view of the subject or a single expert's personal style of presentation and notation.

So if you said to a typical UK undergraduate today that the most important thing about their university journey was to attend all of their lectures, even when they're being phoned in by some researcher who is simultaneously daydreaming about their latest funding application, I don't think many people would agree with you.

Re: I “found” the database of a college app (2018)

#83
post #78

Earlier quoted context omitted.

This is more like walking up to the bank at night and jiggling the door handle then telling everyone it’s unlocked and the alarm isn’t on.

The author straight up admits to scraping the database! That's clearly a point at which "Hm... I think this is insecure, can I actually pull this?" turns into criminal behavior.

I think this is where analogies between physical theft/trespass and digital access break down.

Pressing the handle down, maybe even opening a door, but not walking in and not taking anything. No theft, no trespass. AFAIK in my local laws trespass requires entry and theft requires carrying-off. Indeed -- apparently -- you're legally allowed to enter abandoned properties if you don't break-in.

That to me is equivalent to access, maybe even duplication (proving access with no 'alarms'), of digital data. When it becomes immoral is when you use that data, or make it available for use by others.

Of course the CMA(UK)/CFAA(USA) don't see things this way they both seem to make the equivalent of 'looking in the direction of a door and noticing it's open' into an illegal act.

Re: I “found” the database of a college app (2018)

#84

Earlier quoted context omitted.

You never had a friend bring your iClicker in for you????

Unfortunately, my friends in the class have annoyingly moralistic views on academic honesty, and the professor made it quite clear what the consequences of doing this would be :(

> Unfortunately, my friends in the class have annoyingly moralistic views on academic honesty

Their is nothing wrong by adhering to the rules of a school, and I think it is not that good that subverting the rules is such common practice that actually following the rules is considered annoying. If the rule is so egregious that it can not be followed then sure, but showing up is literally the easiest part and statistically has strong correlation to better performance.

Re: I “found” the database of a college app (2018)

#85

Earlier quoted context omitted.

They might just not be from the US. Here in Germany, tracking or forcing student attendance is subject of large discussions and generally often frowned upon (or forbidden by regulation) in the University setting these days.

This is mind boggling. Failing someone for missing one or two classes is ludicrous, but giving someone a certificate who didn't engage with the course is equally so. University education isn't about the destination/exam it's about the journey.

You can get much more out of Uni but IMO a degree certificate is, and should only be, a measure of ability to complete the stated academic requirements.

Re: I “found” the database of a college app (2018)

#86

Earlier quoted context omitted.

They might just not be from the US. Here in Germany, tracking or forcing student attendance is subject of large discussions and generally often frowned upon (or forbidden by regulation) in the University setting these days.

This is mind boggling. Failing someone for missing one or two classes is ludicrous, but giving someone a certificate who didn't engage with the course is equally so. University education isn't about the destination/exam it's about the journey.

> University education isn't about the destination/exam it's about the journey.

Showing up for lectures is by far the least important part of the journey. It's a passive activity that usually adds zero value versus watching lessons on YouTube or reading the textbook.

The real learning (IMO) is in doing the assignments, networking with people in your residence, social activities, internships, etc.

Re: I “found” the database of a college app (2018)

#87

Earlier quoted context omitted.

And having a full day class on Saturday when a weekday was lost due to bad weather or strikes.

What sort of bad weather are we talking about here? Also, is this due to the commute becoming difficult/impossible in the weather, or because the facilities/lecture theatres are leaky/poorly constructed, or something else?

For Kerala, its heavy rains. Flooded roads with open drains and deep potholes, bad electricity poles and transformers, lines touching trees etc. Engineering and business college norms require sturdy buildings and a few AC rooms.

Re: I “found” the database of a college app (2018)

#88
post #78

Earlier quoted context omitted.

The author straight up admits to scraping the database! That's clearly a point at which "Hm... I think this is insecure, can I actually pull this?" turns into criminal behavior.

I think this is where analogies between physical theft/trespass and digital access break down. Pressing the handle down, maybe even opening a door, but not walking in and not taking anything. No theft, no trespass. AFAIK in my local laws trespass requires entry and theft requires carrying-off. Indeed -- apparently -- you're legally allowed to enter abandoned properties if you don't break-in. That to me is equivalent…

> When it becomes immoral is when you use that data, or make it available for use by others.

That's logically consistent but shockingly permissive. And to be frank, I don't believe for a second this is really a principled opinion on your part, it's an excuse.

You'll get behind the hacker linked on HN out of solidarity or for some other personal reason (maybe you hate schools, or java). You'd never forgive someone for walking in and lifting your photo history due to a security lapse by Facebook, even if they never "used" the data nor "made it available for use by others". And that is why this behavior is criminal.

Be real.

Re: I “found” the database of a college app (2018)

#89
post #62

Earlier quoted context omitted.

Hey, that is too old and I have done it without knowledge, it's my mistake and I apologized for all of them personally and publicly! Here this app belongs to my college, it's my attendance and work is mine!

The first linked tweeter thread is from July 2018, the second is from November 2018. I don't classify that as "too old". And your article is dated October 25, 1028, so it's approximately the same period of time. Also, your article is extremely similar to https://medium.com/@fs0c131y/how-i-found-the-database-of-the... (Oct 16, 2018)

Yeah, the wording in this article is very very similar to OP's article. Calling bullshit on the OP

Re: I “found” the database of a college app (2018)

#90
post #80
post #55

Earlier quoted context omitted.

> he didn't do anything special to hack... Someone who snatched a purse out the hand of someone else isn’t “doing anything special” either. The illegality doesn’t hinge on the difficulty of the action. Why is that so hard to grasp for technical crowds? If you find a car with the keys in the ignition and the door unlocked, you won’t get away with driving it a block down the road by telling the judge: “Oh, but it was o…

The data that's available isn't the school, it's student data! The school left the students "cars unlocked" and no one holds them accountable. They just say that people shouldn't steal cars.

They left the car unlocked in the same sense that your home is unlocked. With the right tools, it’ll take me 5 minutes to gain entry. I could then claim that it’s your own fault I gained entry because you don’t have a metal enforced door, steel bars across windows, and a lock that can’t be easily or Hardily picked...

Yes, someone technically minded with the right tools and access can break in. But that’s less than 5% of the population, very similar to the percentage who could easily pick even a complicated lock, but Of cause near 90% will be able to take an ax to a door or kick in a window.

Post reply on HN