Live data from Hacker News

Hacking Oklahoma State University's Student ID

snelling.io

11–20 of 51 posts

Re: Hacking Oklahoma State University's Student ID

#11
post #5

Earlier quoted context omitted.

I'm kind of curious - since this was for a class it was kind of allowed but was there any fine lines that you weren't allowed to cross when doing research for the exploit? I assume as long as you didn't hurt the university's reputation (such as getting bad press) or caused massive amounts of monetary damage you would probably not get into trouble.

We had pretty strict guidelines to follow to be apart of the InfoSec class. We basically signed a waiver at the beginning saying that if we did exploit something, we would be subject to expulsion. It was a "theory" based class and all actual research had to be done within a certain IP range in a particular computer lab. With that said, this was the final report that I made in the Winter of 2013. I presented it Spring…

They were not upset you made a "blank" ID card and tried to borrow a Surface Pro with it then use it at a cafe?

I personally think you might have crossed the line on actually using it.

Re: Hacking Oklahoma State University's Student ID

#12
post #5

Earlier quoted context omitted.

I'm kind of curious - since this was for a class it was kind of allowed but was there any fine lines that you weren't allowed to cross when doing research for the exploit? I assume as long as you didn't hurt the university's reputation (such as getting bad press) or caused massive amounts of monetary damage you would probably not get into trouble.

We had pretty strict guidelines to follow to be apart of the InfoSec class. We basically signed a waiver at the beginning saying that if we did exploit something, we would be subject to expulsion. It was a "theory" based class and all actual research had to be done within a certain IP range in a particular computer lab. With that said, this was the final report that I made in the Winter of 2013. I presented it Spring…

[deleted]

Re: Hacking Oklahoma State University's Student ID

#13

Well I'll be honest, didn't expect this post to make it up HN. Happy to answer questions or field comments.

In your judgement how common do you feel this exploit would be across other university IDs in the country, or just IDs in general? Did your research uncover any data in that regard one way or the other?

I'm just remembering my ID card...and my sister's...and my brother's. We used those for literally everything.

Re: Hacking Oklahoma State University's Student ID

#14
post #11

Earlier quoted context omitted.

We had pretty strict guidelines to follow to be apart of the InfoSec class. We basically signed a waiver at the beginning saying that if we did exploit something, we would be subject to expulsion. It was a "theory" based class and all actual research had to be done within a certain IP range in a particular computer lab. With that said, this was the final report that I made in the Winter of 2013. I presented it Spring…

They were not upset you made a "blank" ID card and tried to borrow a Surface Pro with it then use it at a cafe? I personally think you might have crossed the line on actually using it.

These folks found a gaping security hole that can be exploited to gain physical access to secured areas as well as charge fraudulent financial transactions. I can't imagine the university getting upset with checking out a library book.

Re: Hacking Oklahoma State University's Student ID

#15
post #11

Earlier quoted context omitted.

We had pretty strict guidelines to follow to be apart of the InfoSec class. We basically signed a waiver at the beginning saying that if we did exploit something, we would be subject to expulsion. It was a "theory" based class and all actual research had to be done within a certain IP range in a particular computer lab. With that said, this was the final report that I made in the Winter of 2013. I presented it Spring…

They were not upset you made a "blank" ID card and tried to borrow a Surface Pro with it then use it at a cafe? I personally think you might have crossed the line on actually using it.

@greyc

Even though I made a blank card, it was still encoded with my student ID number. That was the only reason it was allowed. The point of trying it was to prove that the name or discretionary data did not affect the card working.

While I definitely toed the line, I tried to be careful not to break any of the rules of the class.

Re: Hacking Oklahoma State University's Student ID

#16

Well I'll be honest, didn't expect this post to make it up HN. Happy to answer questions or field comments.

In your judgement how common do you feel this exploit would be across other university IDs in the country, or just IDs in general? Did your research uncover any data in that regard one way or the other? I'm just remembering my ID card...and my sister's...and my brother's. We used those for literally everything.

While my research was specific to OSU, I do know that this is a larger issue than just my alma mater. I collected student IDs from other colleges, but did not publish them as I didn't want to get into hot water.

The thing is though, a lot of these magstripe systems have problems. We brought up in the presentation that Walmart at the time was having a large problem with people encoding stolen credit card data onto gift cards. Cashiers at the time did not check driver licenses when paying with a gift card.

Re: Hacking Oklahoma State University's Student ID

#17

I went to a University in Virginia and ours, and other surrounding VA universities were equally insecure. We each had a 9 digit code that looked like 10XXXXXXX. These numbers were incremented from one student or faculty to the next. The only track that mattered was track 2. It had your 9 digit code, followed by a the school code (3 digits), followed by a "lost card digit" that was incremented each time a card was los…

if the school lets you take tests without a more secure way of authorizing yourself that speaks for itself

i personally teach a course at a university of applied science and it makes me always wonder how bad the whole online-systems are - and that starts with identification of the student

identity is the base of trust but it is by heart not dependent on technology (which we all think so much about) a modern digital signature cannot be forged easily, a "normal" signature can be done easily - but still we believe the analogue medium is more secure because it is a norm of our society

one of the best examples for use of non-secure technology is usage of two-channel communication for authorization using TEXT Messages via SS7 protocol, one of the most unsecure protocols but considered okay in combination with the first channel running via TLS

Re: Hacking Oklahoma State University's Student ID

#18

I went to a University in Virginia and ours, and other surrounding VA universities were equally insecure. We each had a 9 digit code that looked like 10XXXXXXX. These numbers were incremented from one student or faculty to the next. The only track that mattered was track 2. It had your 9 digit code, followed by a the school code (3 digits), followed by a "lost card digit" that was incremented each time a card was los…

Back in 2005, I was at Rochester Institute of Technology, and our ID cards encoded our student ID... which was also our social security number. The Student Government made you take attendence by student ID number for certain functions, so at one point as officer of one of the campus's major clubs I was sitting with a spreadsheet of the names and socials of >1000 students.

They were also low-cap magstripes, and the checksums were predictable. Inventive students had a database of a few all-access keycards that were used to sneak into the tunnels under the academic buildings at all hours of the night...

Re: Hacking Oklahoma State University's Student ID

#19

Well I'll be honest, didn't expect this post to make it up HN. Happy to answer questions or field comments.

Very interesting. I attended OSU. I bet most of universities have the similar kind of security holes. They probably use the fact that not too many people can exploit those technical security flaws as the single line of defense.

Re: Hacking Oklahoma State University's Student ID

#20
This isn't just a problem with just universities. I have a card reader as well, and any site that issues swipe-able ID cards is more than likely susceptible. You would be surprised how many use an incrementing ID that you can easily impersonate another user.

The equipment needed to create fake cards (not just blanks) that look good is trivial to purchase.

I would be curious if OSU built or bought this system to issue cards. If they built it, shame of them. If they bought it, shame on them as well. Any security audit would have caught this clearly. Cards like any interface require good design for use and security.

Post reply on HN