Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

141–150 of 399 posts

Re: IoT hacking and rickrolling my high school district

#141
post #116

Earlier quoted context omitted.

I remember back in high school we had this computer lab that was all locked down. Didn't allow opening the CD-ROM drives, only allowed certain educational websites, etc. I put a little remote access app on my share drive as a way to open my own CD drive, mostly just to see if I could do it. The school's computer guy came and found me and was like "hey, a file pinged as malware, what's up with that" and we had a fun d…

Ah, you young whippersnappers with your labs and networks and CDs... my high school just got one Commodore PET, that was "the school computer" in my day. Fortunately, I got on well with the math teacher who had charge of it, and he'd let me take it home over the weekends. Those were the days...

Apple IIe gang over here. Don't bend my floppy!

Re: IoT hacking and rickrolling my high school district

#142

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Wow that's terrifying, I'm from the EU and did 1000x worse stuff than that, never suffered any consequence, which is not right, but teenagers going to prison for hacking pranks it's really fucked up.

Re: IoT hacking and rickrolling my high school district

#143

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

> This kid is very very lucky.

No, he is just smart. He did it anonymously. He knows how to cover his a$$.

> it sends the signal to other young aspiring cybersecurity professionals that this is OK

The post literally has a whole section dedicated to explaining that this is not OK, but whatever.

Re: IoT hacking and rickrolling my high school district

#144

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

GP isn't validating over criminalization. GP is trying to steer people clear of catching charges. The end results for both is, "Don't hack your school district for a prank," but the context of the two are very different. Students' minds are still developing. You can tell them not to respect Draconian laws surrounding hacking, but do the students understand what's at stake?

Yes, students get in trouble all the time, but most of the consequences for their stupidity are slaps on the hand. Lunch in a classroom, a parent-teacher conference, after school detention, in-school suspension, getting grounded - none of these things carry civil or criminal charges that are a matter of record. What should be a harmless prank can turn into a life altering civil and criminal charges. With high school kids, things quickly go from, "I hacked the school network to do a Rick Roll; they laughed and sent me on my way," all the way to, "I gave my friend the exploit to do something similar; I didn't know he was going to change everyone's grades to 69%."

Further, I would not want to teach in a district where students doing digital pranks is the norm. I volunteer at a high school. Unchecked digital pranks would quickly turn into a constant stream of disruptions. Everyone would think that their prank is better than the last.

Re: IoT hacking and rickrolling my high school district

#145
post #66

Earlier quoted context omitted.

It's still a terrible idea to admit to committing a crime under your real name before the statute of limitations has run out

Is there even a statute of limitations for this kind of thing? Seems way better to just never admit to it at all.

The CFAA has a statute of limitations of 2 years.

Re: IoT hacking and rickrolling my high school district

#147

I thought I was cool being able to modify the ready message on printers across the school network. This is really impressive.

In middle school I used Javascript to change Google's button text from "I'm feeling lucky!" to "Andrew is the best!" (javascript:getElementById('').text='blah')

I showed some other students who were so freaked out that I had "hacked Google" that I got the attention of the librarian, who promptly banned me from the library computers for the rest of the year, even after I refreshed the page to show them it wasn't "real". Oof.

Re: IoT hacking and rickrolling my high school district

#148

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Malicious hackers could have shown something unspeakably vile on all those screens. If this kid reduced the likelihood of that... he's a hero. Alas, I totally hear you.

Re: IoT hacking and rickrolling my high school district

#149

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

> a prank

Why do we tolerate pranks? You shouldn't be able to interfere with someone else and say 'just a prank bro'. Leave other people's things alone. Don't create work for other people. Don't bother people just trying to do their jobs. Don't impose your sense of humour on others. These all seem like basics to me?

If you think someone's funny? Great. Just don't bother other people with it. Do it with your own stuff, not other people's.

Re: IoT hacking and rickrolling my high school district

#150

Earlier quoted context omitted.

25 years ago wasn’t any better… I recall several in my circle getting suspended for harmless things. The lesson: don’t explore, don’t be curious, and don’t try to fix anything related to the school and computers. Sigh.

Consent is paramount when doing that type of exploration. Without explicit permission, how would an IT administrator distinguish the difference between a curious student and a malicious attacker?

You would think so, only this is a bit opaque when dealing with a local school and a district bureaucracy with various computer labs, internet and phone systems. As a student, you may think that the right person to ask is the local teacher who has control of the asset. Especially if that teacher has been assigned IT duties.

But to many school administrators consent of teachers is meaningless. Those assets aren't owned by the teachers but by the district, even if they are the apparent authority figures and stewards in the eyes of the students.

Post reply on HN