Earlier quoted context omitted.
"You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem" Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.
"True, but it makes the case quite different in legal and moral scope from one in which the system owner is not warned" I would believe that it would really only make a difference if the systems administrator replied to your warning with acceptance and an invitation to do so. Morals being subjective, how do you feel it would change the legal conditions?
Youth expelled from Montreal college after finding security flaw
201–210 of 308 posts
Re: Youth expelled from Montreal college after finding security flaw
#202Earlier quoted context omitted.
You missed my point. Like I said, I'm not commenting the penalty. In my opinion, it's too hard. But this is only my opinion after hearing (just like you said) just one side of the story. The main problem with unauthorized testing (putting aside technical problems) is that person who performs it is in _very_ difficult position explaining her intentions. She already did what is considered the _second_ stage in hacker a…
> She already did what is considered the _second_ stage in hacker attack Considered by who? There's companies which pay you money if you can find bug in their software. And that's open offer, they don't say 'wait, we'll get ready at 8 p.m. friday and then you can check'. What do you think would Google do, if this student used scanner(or something else) on gmail and found bug and then told Google about it? I still thi…
Re: Youth expelled from Montreal college after finding security flaw
#203Earlier quoted context omitted.
"You are overlooking the fact that Al-Khabaz informed the system owner 2 days prior of the problem" Warning the system owner doesn't give you the ability to run pen tests if they do not wish you to do so.
"True, but it makes the case quite different in legal and moral scope from one in which the system owner is not warned" I would believe that it would really only make a difference if the systems administrator replied to your warning with acceptance and an invitation to do so. Morals being subjective, how do you feel it would change the legal conditions?
The trespassing, using a system in nonstandard ways could still be considered "malicious", even if the user's intent was not. (I'm not making judgments on the guy so much as imagining that prior warning is not sufficient.)
Re: Youth expelled from Montreal college after finding security flaw
#204Re: Youth expelled from Montreal college after finding security flaw
#205Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…
Malicious definition: "motivated by wrongful, vicious, or mischievous purposes", so it doesn't look that what he did was malicious. Also, unlawful? please quote the Canadian law that he broke, even in the US IANAL but the law mentions a vague "unauthorized access", has anyone ever been charged or convicted for running a vulnerability scanner like Nessus? Not that I disagree with you: always ask for permission in writ…
Orthogonal to this fact is the question of what happens when an authority is brought in to solve the conflict. And something young hackers need to learn as early as possible is that you are not entitled to a due process in every possible context. It would be unlawful if you were not given the chance of a just trial in the context of a criminal or civil lawsuit, but this does not translate well into private institutions.
In particular case of a student unauthorized access within a university, this problem is compounded by the fact that such University and its representatives play the rules of prosecution, judge, jury and (sometimes) defense. You also have to consider that the people doing this are not professionals of law procurement but are pulled out of their real jobs to sort out some random mess, thus the only constrain is their common sense. I've even heard the first hand report of a case in my university where the faculty member supposedly playing "defense" was the most gung-ho about giving the boot to the guy in question (who ended up getting a one term suspension, but got to keep his scholarship, so it could have gone much worse).
This is probably not "fair", but it is the way it is and nobody seems interested enough to make it change. Education has a number of stakeholders with sometimes conflicting preferences and goals, so this is not a trivial problem.
But the point is that once your actions put you in the harms way, the abstract concepts of "fairness" and "proportionality of the punishment" are academic at best. My opinion is that legality is the bare minimum standard society imposes to keep barbarism at bay, but it is pretty rough itself. So it is in your best interest to conduct yourself in such a way that appeals to "the rules" happen as little as possible.
Re: Youth expelled from Montreal college after finding security flaw
#206Earlier quoted context omitted.
"True, but it makes the case quite different in legal and moral scope from one in which the system owner is not warned" I would believe that it would really only make a difference if the systems administrator replied to your warning with acceptance and an invitation to do so. Morals being subjective, how do you feel it would change the legal conditions?
"A warning removes malicious intent. Lack of warning leaves malicious intent in place." The trespassing, using a system in nonstandard ways could still be considered "malicious", even if the user's intent was not. (I'm not making judgments on the guy so much as imagining that prior warning is not sufficient.)
Re: Youth expelled from Montreal college after finding security flaw
#207Earlier quoted context omitted.
This is a C-level position at a publicly-funded institution, that ratio is closer to 95% and 5%. I would even go so far as to say that these individuals very likely have a background in law or simply have an MBNA. Engineers aren't in charge, anywhere, other than tech companies.
30% of MBA's are engineers, and the most common degree for CEO's is engineering. 1/3 of S&P 500 CEO's have an engineering degree, even though only a small fraction of the S&P 500 is tech companies.
Re: Youth expelled from Montreal college after finding security flaw
#208Earlier quoted context omitted.
"A warning removes malicious intent. Lack of warning leaves malicious intent in place." The trespassing, using a system in nonstandard ways could still be considered "malicious", even if the user's intent was not. (I'm not making judgments on the guy so much as imagining that prior warning is not sufficient.)
I don't see how a reasonable person would conclude Al-Khabaz's actions were malicious. People with malicious intent do not draw attention to themselves prior to the event, nor do they advertise the exact attack that they will use.
Re: Youth expelled from Montreal college after finding security flaw
#209I've already posted my "almost got arrested for using zsh" story, so here's another one: I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes. After sniffing the IP address…
Had you known about it, you could've got in touch with the "watch desk" and passed this information along. The watch desk has contacts for security folks at the majority of .edu's (in the US, anyway). I'd guess that about half of these "zombies" would have been offline in less than 24 hours.
I know this doesn't do you any good now, but in the event that someone else reading this discovers a security issue at a .edu in the future, I'd recommend contacting the watch desk before anyone else (either via phone or PGP-encrypted e-mail). They will, depending on severity, for example, call the .edu's security people's cell phones at 3 a.m. and wake them up, if it is warranted.
I was a member of REN-ISAC when I worked at a .edu. It is a vetted and very trusted community. Breaches of trust are dealt with quickly and severely. Any information you pass off to REN-ISAC will remain in good hands.
Re: Youth expelled from Montreal college after finding security flaw
#210Earlier quoted context omitted.
CFO understands finance because the people who hire CFOs know their organisation will bleed out if money is not controlled - they understand the consequences of mismanaging IT They understand their organisation will descend into chaos I their Operations are not controlled But they probably always have lived with crap IT - and so so not understand what competitive advantages come from having IT well controlled. Give i…
Highly doubtful. My day job is at big IT company. Possibly the most well-known in history. You can guess. I'm the lead guy on my team for running our quality control. 6-sigma style stuff. The guy in charge of international training for this quality program said, "The fact is, IT is now a commodity." The whole meme started with Nick Carr's infamous Does IT Matter? editorial in the Harvard Business Review. He argued th…
Most CEOs think IT is a commodity like electricity - you cannot buy "better" electricity. But this is crap - way back when you could buy better electricity - the debate ranged from power smoothing to DC/AC - and your smelter or your lights could depend on the Chief Electrical Officer
...
oh hell I don't care anymore - anyone dumb enough not to think that an IT literate workforce working on IT-enabled processes cannot out perform an illiterate company (just as we now know a reading and writing literate workforce can) deserves to get Schumpeter-ed