Earlier quoted context omitted.
They were not upset you made a "blank" ID card and tried to borrow a Surface Pro with it then use it at a cafe? I personally think you might have crossed the line on actually using it.
These folks found a gaping security hole that can be exploited to gain physical access to secured areas as well as charge fraudulent financial transactions. I can't imagine the university getting upset with checking out a library book.
Hacking Oklahoma State University's Student ID
41–50 of 51 posts
Re: Hacking Oklahoma State University's Student ID
#42Nice write up. Just curious, how many of us are still in or near Stillwater (even in OK)?
Re: Hacking Oklahoma State University's Student ID
#43Universities which use the popular and inexpensive Onity (nee TESA) lock systems, despite their overall problems, gain a bit of security from this problem in that the track used by the locks is written at a nonstandard high bitrate that throws off inexpensive reader/writers. This actually helps prevent duplication, although it's only a measure against people without the resources to obtain the Onity equipment. Outsid…
The gym I go to now does the same. --It's an easy way to prevent multiple people from trying to share a card.
Re: Hacking Oklahoma State University's Student ID
#44Earlier quoted context omitted.
What do you mean by "school code"? Wouldn't they all be the same for everyone at your university?
There are many schools in a university. School of Engineering, School of Music, etc. In most U.S. universities there is a hierarchy: university contains colleges which contain schools.
University -> Faculty (e.g. Faculty of Technology) -> School (e.g. School of Engineering) -> Department.
But this does vary from institution to institution.
Re: Hacking Oklahoma State University's Student ID
#45Earlier quoted context omitted.
There are many schools in a university. School of Engineering, School of Music, etc. In most U.S. universities there is a hierarchy: university contains colleges which contain schools.
And for comparison, my experience of Scottish (and possibly other UK country) universities has been: University -> Faculty (e.g. Faculty of Technology) -> School (e.g. School of Engineering) -> Department. But this does vary from institution to institution.
Re: Hacking Oklahoma State University's Student ID
#46Earlier quoted context omitted.
In your judgement how common do you feel this exploit would be across other university IDs in the country, or just IDs in general? Did your research uncover any data in that regard one way or the other? I'm just remembering my ID card...and my sister's...and my brother's. We used those for literally everything.
While my research was specific to OSU, I do know that this is a larger issue than just my alma mater. I collected student IDs from other colleges, but did not publish them as I didn't want to get into hot water. The thing is though, a lot of these magstripe systems have problems. We brought up in the presentation that Walmart at the time was having a large problem with people encoding stolen credit card data onto gif…
That is top-quality social engineering.
Re: Hacking Oklahoma State University's Student ID
#47Re: Hacking Oklahoma State University's Student ID
#48Well I'll be honest, didn't expect this post to make it up HN. Happy to answer questions or field comments.
Re: Hacking Oklahoma State University's Student ID
#49Earlier quoted context omitted.
Back in 2005, I was at Rochester Institute of Technology, and our ID cards encoded our student ID... which was also our social security number. The Student Government made you take attendence by student ID number for certain functions, so at one point as officer of one of the campus's major clubs I was sitting with a spreadsheet of the names and socials of >1000 students. They were also low-cap magstripes, and the ch…
Get off my lawn. :) When I was in college, 91-95, your SS# was your identifier. It was the unique code that everyone used when they needed a way to identify people. I gotta dig it out, but I think my SS# was printed right on my school ID (and the state issued card allowing me to buy alcohol with my out of state driver's license -- Vermont).
Then they passed out sign-in sheets and asked us to sign in with our student IDs - which were our social security numbers.
The sign-in sheet made it through approximately half the room before someone pointed out what was happening. The organizers looked completely baffled.
Re: Hacking Oklahoma State University's Student ID
#50Earlier quoted context omitted.
Very interesting. I attended OSU. I bet most of universities have the similar kind of security holes. They probably use the fact that not too many people can exploit those technical security flaws as the single line of defense.
Glad to see another Poke! I agree, you have to be fairly clever to get this far. With that said, the barrier of entry is decreasing every day with things like Coin & loop pay.