I beleive Skytech should hire this bloke for a "and they lived happily ever after" story. It's essentially a win-win for Skytech.
After the way this was handled, I'd live in a cardboard box before I worked for this company. You can't have a healthy working environment without trust. I'd give it a shot if they fired their president, but that's an unrealistic expectation.
Youth expelled from Montreal college after finding security flaw
21–30 of 308 posts
Re: Youth expelled from Montreal college after finding security flaw
#22I found something like this at my school. The administration reacted similarly. But fortunately, I was taking djb's Unix Security Holes at the time, and a harshly-worded note from djb to the Computer Center folks ended up getting me a thank you. Next semester, though, I refused to sign the new AUP (which included a clause allowing the computer center staff to seize any computer I was using, even at my off-campus home…
Re: Youth expelled from Montreal college after finding security flaw
#23Re: Youth expelled from Montreal college after finding security flaw
#24The CS faculty at Dawson (less one) should be embarrassed. This happened to me twice in college, minus the expulsion part. In the less interesting case the University sent around a form to be used in nominating student speakers for commencement. It included a drop down that was keyed off of student id. Student ids were regarded as private. The school required everyone to either buy health insurance from them, or prov…
Now they are.
Re: Youth expelled from Montreal college after finding security flaw
#25The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institutions, so if you go in that direction might as well make some money.
Re: Youth expelled from Montreal college after finding security flaw
#26I would now never report a security flaw without a iron clad set of laws in place to protect the rights of white-hats, whether we are licensed and approved security researchers or not.
Re: Youth expelled from Montreal college after finding security flaw
#27Like most developers, I've stumbled into lots of security problems over the years. The first few times I attempted responsible disclosure, but that resulted in enough close calls that I simply don't report them anymore. I document them. Sometimes I might mention them to others who have an interest. I would now never report a security flaw without a iron clad set of laws in place to protect the rights of white-hats, w…
Re: Youth expelled from Montreal college after finding security flaw
#28I found something like this at my school. The administration reacted similarly. But fortunately, I was taking djb's Unix Security Holes at the time, and a harshly-worded note from djb to the Computer Center folks ended up getting me a thank you. Next semester, though, I refused to sign the new AUP (which included a clause allowing the computer center staff to seize any computer I was using, even at my off-campus home…
Re: Youth expelled from Montreal college after finding security flaw
#29What's upsetting is the 14/15 professors who voted him to be expelled. Do computer science professors not understand the concept of white-hat hacking? Shame on them. What message does this send to other students at Dawson? Don't be curious; don't go out of your way to do a favour for the safety of your peers; keep your mouth shut and we'll hand you your degree. Someone give him a scholarship to a legit university!
Unfortunately, if they were at all competent they wouldn't be teaching at a place like that. CS programs at minor universities are notoriously poor and staffed by whoever they could get, and it's not going to be anyone that can make decent pay working on current technology.
Re: Youth expelled from Montreal college after finding security flaw
#30I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…