Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

161–170 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#161
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly. Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he…

  > While his intentions were good, I think it was a bit 
  > naive of him to take upon himself the responsibility to 
  > make sure the flaws were fixed and conduct a test.
Given that his own personal information could have been exposed by this exploit, it's just as likely that he was acting out of self-preservation rather than merely due to feelings of personal responsibility. The only naive bit here is that he obliterated his plausible deniability via 1) not allowing more time between submitting the report and attempting the scan, and 2) not masking his IP behind seven proxies.

Re: Youth expelled from Montreal college after finding security flaw

#162
post #41

Earlier quoted context omitted.

> Do computer science professors not understand the concept of white-hat hacking? Unfortunately, if they were at all competent they wouldn't be teaching at a place like that. CS programs at minor universities are notoriously poor and staffed by whoever they could get, and it's not going to be anyone that can make decent pay working on current technology.

Perhaps CS is an exception, but I was under the impression that jobs in academia (in general) were in woefully short supply. While I'm sure they wouldn't get the cream of the crop, there's reportedly an excess of under-employed & under-paid PhD's and post-docs in a number of STEM fields (again, specifically in academia).

CEGEP teachers don't do any research and aren't really considered academics. The hiring requirement for Dawson is a Master's in CS + 2 years experience, and that requirement can be waived down to a college diploma (DEC, that's less than a bachelor's) if one has enough industry experience to justify it.

Re: Youth expelled from Montreal college after finding security flaw

#163
post #154

Earlier quoted context omitted.

This is a C-level position at a publicly-funded institution, that ratio is closer to 95% and 5%. I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA. Engineers aren't in charge, anywhere, other than tech companies.

I still can't wrap my head around this. The CFO damn well understands finance. The COO understands operations. Why aren CIOs held to the same standard?

CFO understands finance because the people who hire CFOs know their organisation will bleed out if money is not controlled - they understand the consequences of mismanaging IT

They understand their organisation will descend into chaos I their Operations are not controlled

But they probably always have lived with crap IT - and so so not understand what competitive advantages come from having IT well controlled. Give it thirty or so years

Re: Youth expelled from Montreal college after finding security flaw

#165
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

Sounds like he was using an automated scanner as well. That's a stupid thing to do and he should be in trouble.

I'm not sure he should be expelled, but definitely reprimanded.

Re: Youth expelled from Montreal college after finding security flaw

#166

Earlier quoted context omitted.

> more jail time than robbing a bank This meme of "more jail time than robbing a bank" needs to end. The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just havi…

> "The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). What's more, you don't even have to have a gun for it to be classed as "armed ro…

Yup, same in the US.

Re: Youth expelled from Montreal college after finding security flaw

#167
post #116

Earlier quoted context omitted.

You can also pastebin it. That's what you should do.

How do new pastebins get discovered? I've never used the service - was assuming someone should post the link to the pastebin on Reddit?

Yes, someone should. You can imagine some fun ways of doing so.

Re: Youth expelled from Montreal college after finding security flaw

#168
There should really be a Department of Computer Security run by most national governments where people can anonymously report exploits, and that Department takes care of contacting the company or organization. If that group also deals with certain types of personal information that is threatened, there should have 30-60 days to demonstrate that they addressed the vulnerability appropriately, or face penalties.

Its really dumb that we're this far into the internet age already and companies and organizations can still play it so fast and loose with security and personal information. It's irresponsible and negligent.

Re: Youth expelled from Montreal college after finding security flaw

#169
post #154
post #137

Earlier quoted context omitted.

I would guess that being a CIO is 80% about management/people skills and 20% about technology. Hopefully that goes some way to explaining why these people did not understand your email.

This is a C-level position at a publicly-funded institution, that ratio is closer to 95% and 5%. I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA. Engineers aren't in charge, anywhere, other than tech companies.

> I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA

IS MBNA a typo for MBA or is this a specialized certification I've never heard of?

Re: Youth expelled from Montreal college after finding security flaw

#170
post #125
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

It's his own data in the system, which makes this completely different. In your lock picking example, it would be a landlord finding one of their tenants picking their flat's locks.

No it's more analogous to him trying to break into a bank vault because it has his money.
Post reply on HN