Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

111–120 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#111
post #38

Found a bug like this at my school and reported it a few months ago. The guy who responded to me said he'd fix it but it's still live :(

I've had similar encounters with privately disclosed vulnerabilities that are still live years after the fact. What is the right course of action here? If you just wait out and the vulnerability eventually gets exploited they could blame whoever reported it "because he was the only one who knew". You can't really anonymously disclose it after privately reporting it either, because they'll quickly link it to who reported it before.

Re: Youth expelled from Montreal college after finding security flaw

#112
post #109

"This type of software should never be used without prior permission of the system administrator, because it can cause a system to crash." Remind me to never, ever use Omnivox, or any Skytech software, ever.

You probably won't have to, but as a student, you don't have the choices ;) Your courses information, schedule, homework, etc. is all on it.

In Australia, I'm happy to say all I need to do is report a data leak to the privacy commissioner and they'll basically investigate what's happening and force changes.

Re: Youth expelled from Montreal college after finding security flaw

#113

I love the part of the story where the guy naively assumed that it would take his school less than two days to fix the vulnerability. In reality, would probably take them months. How long did it take sony to fix their issues? Oh, right, it took someone to explose it publicly. Heh. It's unfortunate how broken some IT organizations are and that they would rather kill the messenger than fix things.

It involves more or less humongous amounts of pre-meetings, meetings, post-meeting, legal documents, reviews of meeting, implementation strategy, review of implementation, certificating/accepting, post-...

You got the picture. In big companies it might take some time.

Essentially is is very broken system that destroys itself.

It is like you need a manager to watch over a manager that watches over a manager.

It is funny to work at such companies, I got fired from one when I said everything I think about them.

Re: Youth expelled from Montreal college after finding security flaw

#114
This is a perfect example of 'No good deed goes unpunished'.

The best action to take while you find a security flaw is to do nothing. Let some one evil abuse the flaw and make the guys miserable enough to realize the importance of a responsible disclosure.

Without this the guys ego is going to take this as- 'How dare he point a problem in my/our work' and not 'Thanks for saving my life before some body could screw me'.

Re: Youth expelled from Montreal college after finding security flaw

#115
post #22

Earlier quoted context omitted.

Did you pass that course?

I got a B. The homework was to find and write an exploit for 10 security holes in deployed software, but I only found 2. (3 including the one above, which I must have found the week or so after exams. The holes I found were in nasm and in some amateur open-source smtpd.) FWIW, the exams are quite thought-provoking nearly 10 years later, here's a link to them: http://cr.yp.to/2004-494.html

Sounds like a very cool course.

Re: Youth expelled from Montreal college after finding security flaw

#116
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

You can also pastebin it. That's what you should do.

How do new pastebins get discovered? I've never used the service - was assuming someone should post the link to the pastebin on Reddit?

Re: Youth expelled from Montreal college after finding security flaw

#117
post #22

Earlier quoted context omitted.

Did you pass that course?

I got a B. The homework was to find and write an exploit for 10 security holes in deployed software, but I only found 2. (3 including the one above, which I must have found the week or so after exams. The holes I found were in nasm and in some amateur open-source smtpd.) FWIW, the exams are quite thought-provoking nearly 10 years later, here's a link to them: http://cr.yp.to/2004-494.html

What did you think of the course textbook ("Exploiting Software", Hoglund & McGraw)? Is there a more modern alternative that you (or anyone) can recommend?

Re: Youth expelled from Montreal college after finding security flaw

#118

This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…

> more jail time than robbing a bank

This meme of "more jail time than robbing a bank" needs to end.

The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). To make it worse, each 5-year gun sentence must run _consecutive_ with each other sentence (ie., be added on after you serve the other sentences). [1] If you brandish the gun, it becomes a mandatory minimum of 7 years, and if you fire it you get a mandatory minimum of 10 years [1].

Contrast that to all of the hacking charges we've discussed recently where the mandatory minimum is zero (a judge could sentence a convicted defendant to no penalty, or to probation).

To go further, the US Sentencing Guidelines [2], which are all-but-mandatory for federal judges (there's a constitutional out, but in effect most defendants are sentenced according to the Guidelines) gives "wire fraud" a base offense level of 7 (of 42+), which gives a sentencing range of either 0-6 months or 4-10 months, depending on how much economic harm is caused. Compare that to robbing a bank, which is a base offense level of 22, brandishing a firearm adds +5 for an offense level of 27, and if you actually make off with any cash add another +2 for an offense level of 29 (of 42+). The sentencing guidelines call for a sentence of 87-108 months (7-9 years) for a first-time bank robber, per bank, assuming that nobody gets hurt---plus the mandatory additional 5+ years for having a gun.

Realistically, bank robbers face a lot more time than even malicious computer criminals.

[1] See section (c) of 18 USC 924 http://www.law.cornell.edu/uscode/text/18/924

[2] http://www.ussc.gov/guidelines/index.cfm

Re: Youth expelled from Montreal college after finding security flaw

#119

There really needs to be legal protection for acts of white-hat hacking like this. Both protection from prosecution, and protection from reprisal. This kind of stuff isn't going to stop happening unless the act of finding and reporting a security vulnerability becomes legally protected behaviour.

The problem is the that would provide a legitimate cover story for black hats. "Oh I was just doing a white hat scan".

Re: Youth expelled from Montreal college after finding security flaw

#120
it seems like there's more to this story, and the more to this story is around his actions two days after the report.

I've seen things like this happen before. You find a bug, you report it, they tell you "oh we're getting on it immediately". Some time goes by and you think, hey, did they fix it? You look, discover "nope", think "man I bet those guys would fix it if I lit a fire under their ass" and try and use the bug to deface the site, or something.

this is logic that makes sense to a 20 year old (speaking as a former 20 year old..). I've seen that happen before. the article doesn't say this, but perhaps reading between the lines the second attempt did not have a pure motivation behind it...

Post reply on HN