Live data from Hacker News

Cambridge University refuses to censor student's thesis

boingboing.net

11–20 of 68 posts

Re: Cambridge University refuses to censor student's thesis

#11
post #10

Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the public domain?

Based on their response it wouldn't be effective - they would just try to cover it up.

Plus it's likely it's already being used secretly by those with nefarious purposes, publishing just means the average person knowns about it - it's not likely to change how many actually use it.

Re: Cambridge University refuses to censor student's thesis

#13
Prof. Anderson shows good character.

Let's talk about the other side. Businesses have always acted this way when it comes to computer security (for at least the last 15 years, feel free to cite earlier examples). By now they probably understand that what they're doing is wrong, from a security perspective. They may even understand that issuing takedowns increases publicity. Still, business are sociopathic, they don't care about the legitimacy of their actions. They have a staff of lawyers they're already paying for, and a responsibility to defend trade secrets and protect their product base. So they marshal their lawyers, essentially for free, and maybe they get something out of the effort as a result. If they don't, nothing much was lost, and they generally don't care about their perception in the security community. Same old story. This incident is less about someone standing up to a bully and more about someone weathering another wave coming out of the ocean.

Re: Cambridge University refuses to censor student's thesis

#14
post #9

He's a good lecturer too. Funny how being a good lecturer and being a badass correlate.

"Security! Security! Security!"

Although there were some fantastic lecturers at Cambridge who were somehow very terrible at getting the material across, but whose content/personalities were so enjoyable it was worth turning up anyway. I dare say it's the same everywhere.

Re: Cambridge University refuses to censor student's thesis

#15
post #13

Prof. Anderson shows good character. Let's talk about the other side. Businesses have always acted this way when it comes to computer security (for at least the last 15 years, feel free to cite earlier examples). By now they probably understand that what they're doing is wrong, from a security perspective. They may even understand that issuing takedowns increases publicity. Still, business are sociopathic, they don't…

I think I see what you are saying, but I don't agree with the contrast you mention in your last sentence.

Consider: being sociopathic, not caring about the legitimacy of their actions, harassing someone when the risk to them is small -- how does this differ from being a bully?

Re: Cambridge University refuses to censor student's thesis

#16
post #10

Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the public domain?

I believe the article states they notified the banks before publishing the original work.

Re: Cambridge University refuses to censor student's thesis

#17
post #6

To be fair I didn't read this the first time it was on HN - I'm inclined to think that the title of the post is more descriptive than the original, and its deserving front page material, even if it is a duplicate.

Agreed, but it is useful/insightful to have the comments/discussion on hand.

Re: Cambridge University refuses to censor student's thesis

#18
post #13

Prof. Anderson shows good character. Let's talk about the other side. Businesses have always acted this way when it comes to computer security (for at least the last 15 years, feel free to cite earlier examples). By now they probably understand that what they're doing is wrong, from a security perspective. They may even understand that issuing takedowns increases publicity. Still, business are sociopathic, they don't…

I think I see what you are saying, but I don't agree with the contrast you mention in your last sentence. Consider: being sociopathic, not caring about the legitimacy of their actions, harassing someone when the risk to them is small -- how does this differ from being a bully?

Eventually a bully may learn. A true sociopath will continue no matter how many times punished.

Re: Cambridge University refuses to censor student's thesis

#19
post #18

Earlier quoted context omitted.

I think I see what you are saying, but I don't agree with the contrast you mention in your last sentence. Consider: being sociopathic, not caring about the legitimacy of their actions, harassing someone when the risk to them is small -- how does this differ from being a bully?

Eventually a bully may learn. A true sociopath will continue no matter how many times punished.

Interesting point.

But if that's true, then businesses almost never act in a manner we would call sociopathic. And my earlier comment (suitably modified) still stands.

Re: Cambridge University refuses to censor student's thesis

#20
post #16
post #10

Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the public domain?

I believe the article states they notified the banks before publishing the original work.

No it doesn't? I'm not taking the side of the banks here, just trying to understand why the author took the approach he did. It's a shame that at times the HN community is one of single-mindedness where opposite views are met with immediate down-votes.
Post reply on HN