Live data from Hacker News

I “found” the database of a college app (2018)

yoginth.com

101–107 of 107 posts

Re: I “found” the database of a college app (2018)

#101
post #55
post #33

The media would have a field day and say that he hacked his school database. It's crazy how so many institutions are doing the digital equivalent of leaving an unlocked car in a bad neighbourhood and no one holds them accountable. Most people understand the concept of an unlocked car, not many understand that he didn't do anything special to hack his school db. He just strolled right in.

> he didn't do anything special to hack... Someone who snatched a purse out the hand of someone else isn’t “doing anything special” either. The illegality doesn’t hinge on the difficulty of the action. Why is that so hard to grasp for technical crowds? If you find a car with the keys in the ignition and the door unlocked, you won’t get away with driving it a block down the road by telling the judge: “Oh, but it was o…

> Why is that so hard to grasp for technical crowds?

Because laws concerning actual theft are objectively defined, and are logically consistent with themselves and other laws.

Laws about 'hacking', where the crime is simply a message, not a physical action, are extremely subjective. It revolves around intent more than the action.

For example: If a user goes to the website of theirbank.com and the root page is a list with all the credit card numbers of all the clients. Is he committing a crime? He used computers to get information that he shouldn't be allowed to see. Most people would say: no, he only wanted to visit the website.

If I see that the bank's API has no security, am I committing a crime?

If I use SQL injection to see all the users data, am I committing a crime?

Most people would say that it depends on intent, but intent is extremely subjective, and IMO a pretty bad way to define laws.

Re: I “found” the database of a college app (2018)

#102

Earlier quoted context omitted.

Pretty sure it’s the same person from what I could find out from archive.org snapshots. I followed this trail: - From the tweet you linked, it’s clear that they owned yoginth.ml - Archive of the homepage links to a gitlab profile [1] which uses the same profile picture and style of writing as their current gitlab profile. - The page linked to yoginth.ml, and subsequent snapshots of page show it changed to yoginth.com…

Yeah, Docspen was a copy of BookStack. Was a really awkward and difficult thing to handle as maintainer with BookStack being my first popular OS project. It was done very purposeful in an odd way. I remember that issues, filed by BookStack users, were being re-created on the docs pen repo by (potentially fake?) docspen maintainers with pretty much the same text. Yoginth would then commonly create issues on the BookSt…

Interesting. I have a hunch that this all is an attempt to game Google Summer of Code to win sponsorship. I think the sponsors look for open source contributions, and they created all the copies, organisations etc. to make it seem like significant profile. It’s crazy that people would go to such lengths. Like you said, it’s very odd, and sloppy.

Re: I “found” the database of a college app (2018)

#103
post #90
post #80

Earlier quoted context omitted.

The data that's available isn't the school, it's student data! The school left the students "cars unlocked" and no one holds them accountable. They just say that people shouldn't steal cars.

They left the car unlocked in the same sense that your home is unlocked. With the right tools, it’ll take me 5 minutes to gain entry. I could then claim that it’s your own fault I gained entry because you don’t have a metal enforced door, steel bars across windows, and a lock that can’t be easily or Hardily picked... Yes, someone technically minded with the right tools and access can break in. But that’s less than 5%…

Even with that house analogy, I'd argue that you shouldn't store large volumes of other people's sensitive personal data in a house that has the bare minimum security.

The issue is organisations being reckless with our data and then blaming hackers when they lose it. It should be common sense that if you have sensitive information then it needs an appropriate level of security but someone companies have convinced everyone it's not their fault

Re: I “found” the database of a college app (2018)

#104
post #88

Earlier quoted context omitted.

I think this is where analogies between physical theft/trespass and digital access break down. Pressing the handle down, maybe even opening a door, but not walking in and not taking anything. No theft, no trespass. AFAIK in my local laws trespass requires entry and theft requires carrying-off. Indeed -- apparently -- you're legally allowed to enter abandoned properties if you don't break-in. That to me is equivalent…

> When it becomes immoral is when you use that data, or make it available for use by others. That's logically consistent but shockingly permissive. And to be frank, I don't believe for a second this is really a principled opinion on your part, it's an excuse. You'll get behind the hacker linked on HN out of solidarity or for some other personal reason (maybe you hate schools, or java). You'd never forgive someone for…

Meh.

Your post to me is a bit like how people said "you feel violated, don't you" when we had burglars. I didn't feel violated, nor particularly care I'd had unknown people in my house -- what I cared about was the nuisance of making insurance claims.

>You'd never forgive someone for walking in and lifting your photo history //

Someone who looked at one of my photos to prove they could, or downloaded one - never shared it, never re-published it?? I wouldn't ever know, for one thing.

If they downloaded all my photos and never used them? Am I supposed to be angry?

>it's an excuse //

What do you think I'm excusing?

You mention school, so say someone hacks the school network, they don't share any of the info ever with anyone, don't use it in any way -- except perhaps the only result is they anonymously inform the school they have a breach -- what's immoral there? (Yes, practically you move the legality toward the easily measurable act of making access assuming immoral intent, I understand that.)

Re: I “found” the database of a college app (2018)

#105
post #84

Earlier quoted context omitted.

Unfortunately, my friends in the class have annoyingly moralistic views on academic honesty, and the professor made it quite clear what the consequences of doing this would be :(

> Unfortunately, my friends in the class have annoyingly moralistic views on academic honesty Their is nothing wrong by adhering to the rules of a school, and I think it is not that good that subverting the rules is such common practice that actually following the rules is considered annoying. If the rule is so egregious that it can not be followed then sure, but showing up is literally the easiest part and statistic…

> statistically has strong correlation to better performance

Not this class.

Re: I “found” the database of a college app (2018)

#106
post #88

Earlier quoted context omitted.

> When it becomes immoral is when you use that data, or make it available for use by others. That's logically consistent but shockingly permissive. And to be frank, I don't believe for a second this is really a principled opinion on your part, it's an excuse. You'll get behind the hacker linked on HN out of solidarity or for some other personal reason (maybe you hate schools, or java). You'd never forgive someone for…

Meh. Your post to me is a bit like how people said "you feel violated, don't you" when we had burglars. I didn't feel violated, nor particularly care I'd had unknown people in my house -- what I cared about was the nuisance of making insurance claims. >You'd never forgive someone for walking in and lifting your photo history // Someone who looked at one of my photos to prove they could, or downloaded one - never shar…

> If they downloaded all my photos and never used them? Am I supposed to be angry?

Send them to me then. I promise I'll never look at them.

Re: I “found” the database of a college app (2018)

#107
post #93
post #81

Earlier quoted context omitted.

He looked in the window of a car and saw tons of users' personal information -- visible through the window! Any criminal could walk by and copy the info, privately, without anyone knowing. Maybe some criminals already have. I think the important thing we miss with car/physical crime analogies is that cybercrime can be so invisible. Nothing is missing, nothing is taken... but users private data is lost. So if an organ…

>He looked in the window of a car and saw tons of users' personal information -- visible through the window! The information was still behind a door that you had to unlock. They just unwittingly sent keys to everyone.

If everyone has a key, it’s not really locked.

I guess a key is a legal metaphor and not an actual physical device. Huh.

Post reply on HN