Live data from Hacker News

Hacking Oklahoma State University's Student ID

snelling.io

41–50 of 51 posts

Re: Hacking Oklahoma State University's Student ID

#41
post #11

Earlier quoted context omitted.

They were not upset you made a "blank" ID card and tried to borrow a Surface Pro with it then use it at a cafe? I personally think you might have crossed the line on actually using it.

These folks found a gaping security hole that can be exploited to gain physical access to secured areas as well as charge fraudulent financial transactions. I can't imagine the university getting upset with checking out a library book.

You would be astonished at how crazy people can get. Honestly, the author of this study took a huge risk and got lucky. If you're thinking of doing anything like this in similar circumstances, DON'T carry out similar actions without first obtaining written permission for each specific action.

Re: Hacking Oklahoma State University's Student ID

#43

Universities which use the popular and inexpensive Onity (nee TESA) lock systems, despite their overall problems, gain a bit of security from this problem in that the track used by the locks is written at a nonstandard high bitrate that throws off inexpensive reader/writers. This actually helps prevent duplication, although it's only a measure against people without the resources to obtain the Onity equipment. Outsid…

Actually, verifying user photos is pretty common, not just in high-security areas. The residence halls at the university I went to had this setup as far back as the late 90s. --You had a proximity card that was read at the door, and your photo popped up on the computer.

The gym I go to now does the same. --It's an easy way to prevent multiple people from trying to share a card.

Re: Hacking Oklahoma State University's Student ID

#44
post #10

Earlier quoted context omitted.

What do you mean by "school code"? Wouldn't they all be the same for everyone at your university?

There are many schools in a university. School of Engineering, School of Music, etc. In most U.S. universities there is a hierarchy: university contains colleges which contain schools.

And for comparison, my experience of Scottish (and possibly other UK country) universities has been:

University -> Faculty (e.g. Faculty of Technology) -> School (e.g. School of Engineering) -> Department.

But this does vary from institution to institution.

Re: Hacking Oklahoma State University's Student ID

#45
post #44
post #10

Earlier quoted context omitted.

There are many schools in a university. School of Engineering, School of Music, etc. In most U.S. universities there is a hierarchy: university contains colleges which contain schools.

And for comparison, my experience of Scottish (and possibly other UK country) universities has been: University -> Faculty (e.g. Faculty of Technology) -> School (e.g. School of Engineering) -> Department. But this does vary from institution to institution.

Not sure about the rest of the unis down south, but I definitely remember Cambridge and Oxford have some sort of "college" system which had no real relation to your subject (i.e. you could read Philosophy at Foo College, Oxford, or Bar College, Oxford). Maybe someone oxbridge-y can clarify.

Re: Hacking Oklahoma State University's Student ID

#46

Earlier quoted context omitted.

In your judgement how common do you feel this exploit would be across other university IDs in the country, or just IDs in general? Did your research uncover any data in that regard one way or the other? I'm just remembering my ID card...and my sister's...and my brother's. We used those for literally everything.

While my research was specific to OSU, I do know that this is a larger issue than just my alma mater. I collected student IDs from other colleges, but did not publish them as I didn't want to get into hot water. The thing is though, a lot of these magstripe systems have problems. We brought up in the presentation that Walmart at the time was having a large problem with people encoding stolen credit card data onto gif…

> people encoding stolen credit card data onto gift cards. Cashiers at the time did not check driver licenses when paying with a gift card

That is top-quality social engineering.

Re: Hacking Oklahoma State University's Student ID

#49
post #39

Earlier quoted context omitted.

Back in 2005, I was at Rochester Institute of Technology, and our ID cards encoded our student ID... which was also our social security number. The Student Government made you take attendence by student ID number for certain functions, so at one point as officer of one of the campus's major clubs I was sitting with a spreadsheet of the names and socials of >1000 students. They were also low-cap magstripes, and the ch…

Get off my lawn. :) When I was in college, 91-95, your SS# was your identifier. It was the unique code that everyone used when they needed a way to identify people. I gotta dig it out, but I think my SS# was printed right on my school ID (and the state issued card allowing me to buy alcohol with my out of state driver's license -- Vermont).

My university (UT Dallas) once hosted a talk about privacy and security, during which they emphasized that it was important to keep your social security number as secret as possible.

Then they passed out sign-in sheets and asked us to sign in with our student IDs - which were our social security numbers.

The sign-in sheet made it through approximately half the room before someone pointed out what was happening. The organizers looked completely baffled.

Re: Hacking Oklahoma State University's Student ID

#50

Earlier quoted context omitted.

Very interesting. I attended OSU. I bet most of universities have the similar kind of security holes. They probably use the fact that not too many people can exploit those technical security flaws as the single line of defense.

Glad to see another Poke! I agree, you have to be fairly clever to get this far. With that said, the barrier of entry is decreasing every day with things like Coin & loop pay.

I wonder if FERPA, PCI-DSS apply here. We know they are vulnerable about student information, with extra functionality as a payment card, it is getting kinda scary.
Post reply on HN