Even aside from the fact that he was acting in good faith and did not cause any damage to persons or property (as acknowledged by the software vendor), the procedure used to expel him is woefully lacking. I sat on the highest student discipline tribunal at my (Canadian) university and an expulsion for non-academic reasons - which had to receive final approval from both the President and the Governing Council - would…
It was also really crappy cover-up strategy on the school's part. By refusing due process to Al-Khabaz and expelling him with zeroes for his last semester grades, Al-Khabaz now had nothing to lose exposing both the security flaw and the injustice to the press. If they didn't play all their cards at the same time (like putting him on probation or something), he probably wouldn't have gone public.
Youth expelled from Montreal college after finding security flaw
181–190 of 308 posts
Re: Youth expelled from Montreal college after finding security flaw
#182Hackers are the new Sicilians and blacks.
Don't snitch.
Snitches get punished both by:
The person being snitched upon
The person who is being snitched to.
This article and many other comments herein support this view.Re: Youth expelled from Montreal college after finding security flaw
#183Earlier quoted context omitted.
Was MAC spoofing not doable in 1999?
and sadly it won't be in the future. New Intel-wifi cards have them blocked[1], their new drivers even go out of the way to modify/intercept Windows from doing it from the software side. Won't be long until other manufacturers follow suit. [1] http://www.intel.com/support/wireless/wlan/sb/CS-031081.htm
Re: Youth expelled from Montreal college after finding security flaw
#1841. Exploit discovery.
2. Automated service attack.
From the information given, it seems Al-Khabaz did exactly or better than what was expected of him for the first.
But why, if he was simply check for the existing vulnerability after informing of the first, did he launch an automated attack?
I suspect Dawson College has sound reasons to treat him the way they did for both instances.
Re: Youth expelled from Montreal college after finding security flaw
#185Re: Youth expelled from Montreal college after finding security flaw
#186This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…
> more jail time than robbing a bank This meme of "more jail time than robbing a bank" needs to end. The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just havi…
http://www.spiegel.de/international/zeitgeist/berlin-bank-ro...
Re: Youth expelled from Montreal college after finding security flaw
#187I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…
I'd revise that to don't be a hobbyist "white hat". If you want to do white hat hacking either get yourself hired by a serious security outfit or set yourself up as a company doing security consulting. On the whole people are far less likely to go after a genuine security company as opposed to 'just some kid in a basement'.
Re: Youth expelled from Montreal college after finding security flaw
#188Re: Youth expelled from Montreal college after finding security flaw
#189Earlier quoted context omitted.
Yes, Finland. Maybe it's because all of our schools are public? For example higher ed. providers are funded based on enrollment and rate of graduation. If someone does not graduate, significant chunk (20-30%) of money won't be paid at all. This creates some incentive for the institution to actually guide and see that people don't fall through all kinds of cracks. I guess it's necessary when there is no ordinary payin…
How do you prevent the schools from just lowering graduation requirements in order to artificially boost the percent of graduates and get a better payout?
Re: Youth expelled from Montreal college after finding security flaw
#190Earlier quoted context omitted.
This is a C-level position at a publicly-funded institution, that ratio is closer to 95% and 5%. I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA. Engineers aren't in charge, anywhere, other than tech companies.
> I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA IS MBNA a typo for MBA or is this a specialized certification I've never heard of?