Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

191–200 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#191
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.

"You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem"

Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.

Re: Youth expelled from Montreal college after finding security flaw

#192
post #188

I don't agree that expulsion is the correct reaction, but when he ran the pen-test software, what he was doing was wrong. It's one thing to stumble upon a bug while you're developing an app, and report it. That's totally respectable. Running pen-testing software without permission is akin to walking up to a stranger's home and testing that all the windows are locked, with a crowbar.

No, that's a terrible analogy unless this stranger is not a stranger, and is known to be trusted holding tons of personally identifiable information of yourself and your peers, and has already been alerted they left a window wide open (in this example, minimal tech know how is required).

And saying crowbar is intentionally misleading people into thinking that damage is somehow being done during the check.

Re: Youth expelled from Montreal college after finding security flaw

#193

Earlier quoted context omitted.

I still can't wrap my head around this. The CFO damn well understands finance. The COO understands operations. Why aren CIOs held to the same standard?

CFO understands finance because the people who hire CFOs know their organisation will bleed out if money is not controlled - they understand the consequences of mismanaging IT They understand their organisation will descend into chaos I their Operations are not controlled But they probably always have lived with crap IT - and so so not understand what competitive advantages come from having IT well controlled. Give i…

Highly doubtful. My day job is at big IT company. Possibly the most well-known in history. You can guess. I'm the lead guy on my team for running our quality control. 6-sigma style stuff. The guy in charge of international training for this quality program said, "The fact is, IT is now a commodity."

The whole meme started with Nick Carr's infamous Does IT Matter? editorial in the Harvard Business Review. He argued that while IT provided a competitive advantage in the past, it doesn't anymore. It's important for keeping up with the competition, but it will never put you ahead of the competition because it has been commoditized. All of his arguments made perfect sense at the time. And most IT organizations to date still take them to heart.

His arguments just assumed one thing incorrectly: they assumed that enterprise IT would never change in terms of the end user functionality it delivered. He assumed there was no more innovation to be had, that everything ever needed to be invented had been invented, and so we had reached the peak of functionality, like how you can't improve much upon the hammer and nail beyond perhaps the screw and electric power screwdriver.

Unfortunately, IT is treated like a commodity for most organizations, and commodities never get special attention.

Re: Youth expelled from Montreal college after finding security flaw

#194
post #125
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

It's his own data in the system, which makes this completely different. In your lock picking example, it would be a landlord finding one of their tenants picking their flat's locks.

"It's his own data in the system, which makes this completely different. In your lock picking example, it would be a landlord finding one of their tenants picking their flat's locks"

More accurate would be catching your tenant picking every single apartment's lock to prove that their personal lock is vulnerable.

Re: Youth expelled from Montreal college after finding security flaw

#195
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly. Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he…

It sounds like he may have been trying to find more flaws.

Re: Youth expelled from Montreal college after finding security flaw

#196
post #93

I've already posted my "almost got arrested for using zsh" story, so here's another one: I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes. After sniffing the IP address…

Evidently the corollary to Arthur C Clarke's famous quote on technology and magic is that those who create it are witches and wizards. You like the magic and you need a few practitioners but when things start getting weird, it's pitchfork o'clock.

What an incredibly succinct way to put it. Props.

I have a lurking feeling that in spite of all of the technologist/futurist optimism in our community, we are likely underestimating the pushback from the world at large when enough people at the same time are finally put out of work due to the same technological innovation we strive so furiously for in our own lives.

Re: Youth expelled from Montreal college after finding security flaw

#197

Earlier quoted context omitted.

You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.

"You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem" Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.

True, but it makes the case quite different in legal and moral scope from one in which the system owner is not warned.

Re: Youth expelled from Montreal college after finding security flaw

#198
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly. Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he…

Agreed. While he may say he was trying to verify the flaw was fixed, that just doesn't coincide with running a general purpose vulnerability scanner against their network.

While I doubt his intentions were malicious, it certainly seems like he got curious / excited from his first find and went looking for more.

With that being said, I definitely feel for the guy. I can certainly understand the intrigue and curiosity that would lead him to continue his exploration. It sucks that they decided to bring the hammer down so hard.

Re: Youth expelled from Montreal college after finding security flaw

#199

Earlier quoted context omitted.

You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.

"You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem" Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.

"True, but it makes the case quite different in legal and moral scope from one in which the system owner is not warned"

I would believe that it would really only make a difference if the systems administrator replied to your warning with acceptance and an invitation to do so.

Morals being subjective, how do you feel it would change the legal conditions?

Re: Youth expelled from Montreal college after finding security flaw

#200
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem. Thus, you can not claim the actions of Mr. Al-Khabaz were definitely unlawful and unethical, that remains to be seen. This is not a black and white issue.

[deleted]
Post reply on HN