Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

141–150 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#141
When it comes to software and security flaws, finding them is like an exercise in witchcraft.

Throw the person who found the software bug into the lake, if they float, then they were a witch, and deserve to die.

And people wonder why security is so poor and Chinese hackers find it so easy to hack into all our stuff. Because America Punishes people who focus on bulletproof secure code.

I guess we'll need to hire some special interests to pay-off the news networks cnn/fox/msnbc/etc to add the "Hackers are not witches" to their narratives. We would probably need bribes on the order of billions.

Re: Youth expelled from Montreal college after finding security flaw

#142

This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…

We need a Good Hacker law.

https://en.wikipedia.org/wiki/Good_Samaritan_law

Re: Youth expelled from Montreal college after finding security flaw

#143

I love the part of the story where the guy naively assumed that it would take his school less than two days to fix the vulnerability. In reality, would probably take them months. How long did it take sony to fix their issues? Oh, right, it took someone to explose it publicly. Heh. It's unfortunate how broken some IT organizations are and that they would rather kill the messenger than fix things.

And meanwhile, the student data is at risk on the Internet. Every org needs a better plan then that, especially when change management takes weeks/months and this requires immediate action.

Re: Youth expelled from Montreal college after finding security flaw

#144
post #66

Back in 1999 when I was a freshman in university, my school had a server for students to host their websites on and use Pine for email. The server did not give shell access... but then there was a security hole in Pine that would allow you to run chsh. So I did that, and got shell access. I think the worst thing I did (other than running ls in a few directories) was use it to connect to IRC. Since I wasn't really try…

Was MAC spoofing not doable in 1999?

and sadly it won't be in the future. New Intel-wifi cards have them blocked[1], their new drivers even go out of the way to modify/intercept Windows from doing it from the software side. Won't be long until other manufacturers follow suit.

[1] http://www.intel.com/support/wireless/wlan/sb/CS-031081.htm

Re: Youth expelled from Montreal college after finding security flaw

#145
post #98

Earlier quoted context omitted.

Which country may I ask? Nordic?

Yes, Finland. Maybe it's because all of our schools are public? For example higher ed. providers are funded based on enrollment and rate of graduation. If someone does not graduate, significant chunk (20-30%) of money won't be paid at all. This creates some incentive for the institution to actually guide and see that people don't fall through all kinds of cracks. I guess it's necessary when there is no ordinary payin…

My experience in the U.S. is that public universities aren't much different from private universities (at least the nonprofit ones) on these kinds of policies. They might be better in other respects, such as lower tuition, but they're run by similar kinds of administrators. Often literally the same administrators: there's a lot of churn as people hop between institutions.

The main problem, in my view, is the professionalization of this institution-hopping class of university administrators. It used to be made up of senior faculty who got promoted to Dean, but now it's made up of an entirely separate group of people, often people who come from business management backgrounds, and who have little grounding in a particular institution's traditions or culture. They tend to think rather differently, in a more locked-down, policy-driven way, and apply broad "best practices" without much regard for how things are done in a particular place. Universities end up getting managed like a corporation, with similar kinds of policies.

Things are a bit better at small colleges (Rose-Hulman, Olin, Harvey Mudd, Wesleyan, Pomona, Colgate, etc.), which typically have much lighter-weight administration and a more pro-student, pro-experimentation attitude, as well as more success in en-culturating their administrators so they "get" the local culture and work with it. But they don't scale very well (I say this despite having gone to one and being a big fan of the undergraduate-college model).

Re: Youth expelled from Montreal college after finding security flaw

#146
This headline is somewhat misleading. The student was expelled, not for finding and disclosing a security flaw (he was actually congratulated and thanked for this), but for later running a pentest software suite without permission to "verify" if the bug had been fixed.

That's not to say that the expulsion still doesn't reek of BS, but Ahmed's hands are not completely clean here.

Re: Youth expelled from Montreal college after finding security flaw

#147
Ahmed, I am assuming that you are following this discussion.

Based on the article, your life probably doesn't feel so good right now. Sorry to see a bright person in such a situation.

Give me a ring if you are looking for an internship, job or start-up experience in Montreal. We are in town (walking distance from Dawson actually). By the nature of our business, we also have good connections with academia if that can help (www.tandemlaunch.com).

My login is my name so you can reach me at [firstname].[lastname]@tandemlaunch.com

Re: Youth expelled from Montreal college after finding security flaw

#149
post #98

Earlier quoted context omitted.

Which country may I ask? Nordic?

Yes, Finland. Maybe it's because all of our schools are public? For example higher ed. providers are funded based on enrollment and rate of graduation. If someone does not graduate, significant chunk (20-30%) of money won't be paid at all. This creates some incentive for the institution to actually guide and see that people don't fall through all kinds of cracks. I guess it's necessary when there is no ordinary payin…

How do you prevent the schools from just lowering graduation requirements in order to artificially boost the percent of graduates and get a better payout?

Re: Youth expelled from Montreal college after finding security flaw

#150
post #31
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

During undergrad I discovered the university's blackboard-like site sent plaintext passwords over http, and the majority of its use was over wireless. I went to the IT office responsible for the site, told them about it, and refused to give my name when they asked. After reading some of the horror stories on this page, I feel really lucky that the IT department didn't go further to figure out who I was and get me in…

Man. I found an XSS bug in the University of Washington's web portal several years ago. It would allow a hacker to impersonate any user if they clicked on a crafted hyperlink.

After testing this on my own account, I reported it right away to the university. They thanked me and fixed the problem within days.

But after reading these horror stories, I feel extremely lucky that they didn't do something much stupider. My entire academic career could have been destroyed, as well as my professional one if they'd decided to press frivolous charges.

Post reply on HN