Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

171–180 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#171
post #158
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

Malicious definition: "motivated by wrongful, vicious, or mischievous purposes", so it doesn't look that what he did was malicious. Also, unlawful? please quote the Canadian law that he broke, even in the US IANAL but the law mentions a vague "unauthorized access", has anyone ever been charged or convicted for running a vulnerability scanner like Nessus? Not that I disagree with you: always ask for permission in writ…

I explained my point below in more detail regarding the equation and why I think it should be remembered.

When someone is scanning your system and you haven't authorized it, you will definitively treat it as malicious. In a given moment, you don't care about attacker's inside motives, because your system is under attack and you better act accordingly.

I know a story about a guy who lost his job because of the unauthorized Nessus scanning in his company. Every story with a convicted hacker has some kind of a scanning tool (at least nmap) that was used in scanning phase, you can bet on it. Every scanning tool is an attack tool. In fact, scanners are most useful tools for any kind of attack, because they minimize amount of manual effort needed.

I don't know much about Canadian law, but most current laws forbid unauthorized access and _atempts_ of doing it.

Re: Youth expelled from Montreal college after finding security flaw

#172
post #22

Earlier quoted context omitted.

Did you pass that course?

I got a B. The homework was to find and write an exploit for 10 security holes in deployed software, but I only found 2. (3 including the one above, which I must have found the week or so after exams. The holes I found were in nasm and in some amateur open-source smtpd.) FWIW, the exams are quite thought-provoking nearly 10 years later, here's a link to them: http://cr.yp.to/2004-494.html

Didn't he famously fail the whole class one of the times he gave it?

Re: Youth expelled from Montreal college after finding security flaw

#173
post #154
post #137

Earlier quoted context omitted.

I would guess that being a CIO is 80% about management/people skills and 20% about technology. Hopefully that goes some way to explaining why these people did not understand your email.

This is a C-level position at a publicly-funded institution, that ratio is closer to 95% and 5%. I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA. Engineers aren't in charge, anywhere, other than tech companies.

30% of MBA's are engineers, and the most common degree for CEO's is engineering. 1/3 of S&P 500 CEO's have an engineering degree, even though only a small fraction of the S&P 500 is tech companies.

Re: Youth expelled from Montreal college after finding security flaw

#175

I'm wondering if that NDA included the clause that urges you to get advice from a lawyer. The conditions under which he signed it sound very suspicious (i.e. coercive language) and I wonder if it would be grounds to nullify the NDA entirely.

I'm curious, how often does this occur?

"included the clause that urges you to get advice from a lawyer"

I can't recall being offered a NDA with this language.

Re: Youth expelled from Montreal college after finding security flaw

#176

This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…

This phenomenon isn't unique to computer crime. The other day my iPhone was stolen from my car in my apartments parking garage. I forgot to lock the door. I noticed that the guy who parks next to me (we have assigned spaces) also left his door unlocked. I was going to leave a note suggesting he remember to lock his doors because something was stolen from my car, but I thought better of it. If something was stolen from his car, do you want your note to be the only piece of evidence of what happened?

Re: Youth expelled from Montreal college after finding security flaw

#177
A fellow student and I discovered a similar flaw in my college's system a few years back, but not as serious as this (no social insurance numbers, but emails, full names, phone numbers and addresses).

We brought it to the attention of the head of the IT Department by email. Later that week, the head visited our morning class to discuss this with us.

He discussed the issue to the class and actually acknowledged his appreciation for students like us for reacting promptly and responsibly over the issue.

Re: Youth expelled from Montreal college after finding security flaw

#178

This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…

> more jail time than robbing a bank This meme of "more jail time than robbing a bank" needs to end. The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just havi…

People have successfully robbed banks with just notes. The penalty for witch can be less than 5 years depending on the note.

Not that robbing a bank is all that profitable vs. the risk and penalty's.

Re: Youth expelled from Montreal college after finding security flaw

#179
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

Agreed, when SQL Injections in ASP were all the rage some 10 years ago I contacted a couple dozen companies to inform of their full credit card visible customer admin pages and asked for nothing in return (at that time someone was offered money to help fix a security breach and was arrested for blackmail -- the employee that offered the money for services was actually the police speaking to him, so that saved my ass too) and I got a ton of threats, only one company actually gave me a number to call and thanked me but when I asked for a postcard of their city he got really pissed. Good times.

Re: Youth expelled from Montreal college after finding security flaw

#180
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.
Post reply on HN