Live data from Hacker News

Cambridge University refuses to censor student's thesis

boingboing.net

21–30 of 68 posts

Re: Cambridge University refuses to censor student's thesis

#22
post #20
post #16

Earlier quoted context omitted.

I believe the article states they notified the banks before publishing the original work.

No it doesn't? I'm not taking the side of the banks here, just trying to understand why the author took the approach he did. It's a shame that at times the HN community is one of single-mindedness where opposite views are met with immediate down-votes.

> ... because it documented a well-known flaw in the chip-and-PIN system...

The author of the article at least believes that it is a well-known flaw so responsible disclosure isn't really applicable.

Re: Cambridge University refuses to censor student's thesis

#23
post #20
post #16

Earlier quoted context omitted.

I believe the article states they notified the banks before publishing the original work.

No it doesn't? I'm not taking the side of the banks here, just trying to understand why the author took the approach he did. It's a shame that at times the HN community is one of single-mindedness where opposite views are met with immediate down-votes.

"Third, Omar’s thesis does not contain any new information on the No-PIN vulnerability. That was discovered by Steven Murdoch, Saar Drimer and me in 2009, disclosed responsibly to the industry, and published in February this year. It is not expected that an MPhil thesis contain novel scientific work."

http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf

Re: Cambridge University refuses to censor student's thesis

#24
post #18

Earlier quoted context omitted.

Eventually a bully may learn. A true sociopath will continue no matter how many times punished.

Interesting point. But if that's true, then businesses almost never act in a manner we would call sociopathic. And my earlier comment (suitably modified) still stands.

[deleted]

Re: Cambridge University refuses to censor student's thesis

#25
post #22
post #20

Earlier quoted context omitted.

No it doesn't? I'm not taking the side of the banks here, just trying to understand why the author took the approach he did. It's a shame that at times the HN community is one of single-mindedness where opposite views are met with immediate down-votes.

> ... because it documented a well-known flaw in the chip-and-PIN system... The author of the article at least believes that it is a well-known flaw so responsible disclosure isn't really applicable.

Well I think you hit the nail on the head, that the disclosure isn't responsible. I'm all for bringing the flaws in chip-and-pin to the public attention, however I find it distasteful that a leading university publishing the schematics of a device that can be used to commit fraud, receives so much applause for this community.

I get the impression that this has captured the public mood of "sticking it to the bankers", when really Cambridge have gone about this one the wrong way.

Re: Cambridge University refuses to censor student's thesis

#26
post #18

Earlier quoted context omitted.

Eventually a bully may learn. A true sociopath will continue no matter how many times punished.

Interesting point. But if that's true, then businesses almost never act in a manner we would call sociopathic. And my earlier comment (suitably modified) still stands.

Hi ggchapell,

We agree on your point. The company is being a bully. My issue is with the reception of the story. The larger picture is that frivolous takedown notices are issued all the time, and will continue to be issued willfully by companies until there is disincentive to do so.

Prof. Anderson's actions are commendable. I do not wish to detract from them. However, with the candor I hope a security researcher would appreciate, I point out that both parties probably expected this exchange would take place, and both parties understand Prof. Anderson's response is ineffective. (The Internet, however, may not.)

Prof. Anderson has successfully stood up to this organization, but he has only maintained parity. This kind of incident will repeat as long as companies believe they can get something out of it. Someone else will cave or will plain not know any better. The companies' goal is, basically, harassment, and they will continue to do it regardless of anything that's happened so far. So I guess my point is that I would rather see people discussing how to remedy this old situation than remarking on the letter, which while entertaining and well-written, is actually the signifier of a losing battle.

(unfortunately this is the last I can comment on this topic)

Re: Cambridge University refuses to censor student's thesis

#27
post #25
post #22

Earlier quoted context omitted.

> ... because it documented a well-known flaw in the chip-and-PIN system... The author of the article at least believes that it is a well-known flaw so responsible disclosure isn't really applicable.

Well I think you hit the nail on the head, that the disclosure isn't responsible. I'm all for bringing the flaws in chip-and-pin to the public attention, however I find it distasteful that a leading university publishing the schematics of a device that can be used to commit fraud, receives so much applause for this community. I get the impression that this has captured the public mood of "sticking it to the bankers",…

My reading of the whole incident is that the exploit was disclosed (responsibly) to the banks 1 year ago and the banks have done nothing to fix the problem. Since then the professor (along with others) published a paper detailing the exploit. Finally the MPhil student cited the previously published paper in his thesis (it would be a crappy thesis to not reference current similar work)

At no point do I get the indication that the MPhil student was acting in a way that was 'irresponsible' - I don't know how you have come to that conclusion.

Re: Cambridge University refuses to censor student's thesis

#28
Click on our website: === ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

"Priority, my friend!! Christmas is coming, quick to our website shopping, our web site shopping there will be something different, unexpected things to you, let you have different sense, our website wholesale various fashion shoes, such as Nike, Jordan, prada, also includes the jeans, shirt, bags, hats and decoration. All these products are our free transport, prices are competitive, we can also accept paypal j, after the payment within short time, can ship. = New era cap $12;

Air jordan(1-24)shoes $30;

jordan air max oakland raiders $34a€“39;

Ed Hardy AF JUICY POLO Bikini $25;

Christan Audigier BIKINI JACKET $25;

Tshirts (Polo ,ed hardy,lacoste) $15

coogi DG edhardy gucci t-shirts $18;

gstar coogi evisu true jeans $35;

coach chanel gucci LV handbags $36;

Sunglasses(Oakey,coach,gucci,A r m a i n i) $15;

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

=== ( http://www.etradinglife.com ) ===

Re: Cambridge University refuses to censor student's thesis

#29
post #10

Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the public domain?

Wouldn't have worked, in the same way that emailing Facebook and others, instead of releasing Firesheep wouldn't have worked (since they haven't fixed it even after Firesheep has been released, it's unlikely they would have paid much attention to a letter or email).

given the letter says that this is a known vulnerability

Re: Cambridge University refuses to censor student's thesis

#30

Link to original letter - oh boy this is a good read: http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf

Nice last paragraph:

Nonetheless, I am delighted to note your firm statement that the attack will no longer work and pleased that the industry has been finally been able to deal with this security issue, albeit some considerable time after the original disclosure back in 2009.

Post reply on HN