Live data from Hacker News

The Great Firewall of Yale

162.209.96.128

31–40 of 135 posts

Re: The Great Firewall of Yale

#31

What's the purpose of Yale censoring certain websites? I find it hilarious that people spend so much money to go to Yale, and some of that money goes to inspecting what they're browsing.

Preventing malware outbreaks on the Yale internal network?

Many University networks are intentionally pretty open on the inside. Last I was at Uni, for example, CIFS was not blocked. CIFS is a common vector for malware to spread across a network.

So, blocking access to known malware hotspots works as a form of preventative maintenance. With a student body of 5,000 you are virtually guaranteed to have a cohort of that archetype of user that acquires new malware on a daily basis.

Edit: Obviously that isn't a good reason to block THIS website, just responding to the general question of filtering in the first place.

Re: The Great Firewall of Yale

#32
Something like this happened at the university in the city I live in. There was an apparently awful service for signing up for classes called BearTracks [1] and someone made a scraped version of it that was better called BearScat [2]. Eventually the university basically incorporated the better version into theirs (to, I understand, mixed results).

[1] https://www.beartracks.ualberta.ca/ [2] http://www.bearscat.ca/

Re: The Great Firewall of Yale

#33
post #15

"Universities are a bastion of free speech." LOL.

Having FIRE's[1] RSS feed[2] in my daily reading has dissuaded me from that belief. "Unlearning Liberty" by Greg Lukianoff (FIRE's President) has a chapter of Yale.

1) http://thefire.org

2) http://thefire.org/feeds/news/

Re: The Great Firewall of Yale

#34

This is not news. Most campus have filtering software and the university administration will use it to block websites that make them look bad.

>This is not news.

If you're numb to it, then it's imperative that it is news.

Imagine when the headlines read "Millions killed in Nazi camps" and people said "This is not news."

Re: The Great Firewall of Yale

#35
post #29

Earlier quoted context omitted.

How can they do that without the cooperation of clients? This won't work in a university the way it works in a corporate environment.

Why would it not work in a university as it works in a corporate environment?

in a corporate environment, you usually have control over the workstations themselves, and can inject your own mitm certificate.

Re: The Great Firewall of Yale

#36
post #28
post #20

Earlier quoted context omitted.

That is until Yale than set themselves up to forcefully man in the middle all outgoing https connections.

Really, how?? Wouldn't that require the installation of a custom root certificate on every client?

My university installed a root CA as part of the signup process for WiFi access. Three of them in fact.

Re: The Great Firewall of Yale

#37

Something like this happened at the university in the city I live in. There was an apparently awful service for signing up for classes called BearTracks [1] and someone made a scraped version of it that was better called BearScat [2]. Eventually the university basically incorporated the better version into theirs (to, I understand, mixed results). [1] https://www.beartracks.ualberta.ca/ [2] http://www.bearscat.ca/

I'm glad I was around as BearScat came out and before the killed it.

Re: The Great Firewall of Yale

#38
post #29

Earlier quoted context omitted.

Why would it not work in a university as it works in a corporate environment?

in a corporate environment, you usually have control over the workstations themselves, and can inject your own mitm certificate.

It doesn't matter whether you control the user environment to covertly install the MITM certificate. You simple notify your network users this is happening with instructions on how to install the certificate.

Either the user installs it or not, it's their choice.

I am in no way advocating this abhorrent system of 'security'. Simply noting that it is obviously done in the workplaces and in many workplaces. That it can also be done here under 'security' pretences.

Re: The Great Firewall of Yale

#39
post #28
post #20

Earlier quoted context omitted.

That is until Yale than set themselves up to forcefully man in the middle all outgoing https connections.

Really, how?? Wouldn't that require the installation of a custom root certificate on every client?

Yeah it would. So browers will either get that big red warning or the user can be asked/required to install the certificate to be on the network.

It's not a technical limitation but a moral one.

Re: The Great Firewall of Yale

#40
tl;dr -- the crux of the issue (right or wrong) is making the evaluation information too public. From the news story:

> "[Administrators' primary concern was] making YC [Yale College] course evaluation available to many who are not authorized to view this information,”

> "[Administrators also asked] how they [the site operators] obtained the information, who gave them permission to use it and where the information is hosted."

Edit: Agreed, I don't buy these are the real reasons.

Post reply on HN