Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

221–230 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#221

Earlier quoted context omitted.

I don't see how a reasonable person would conclude Al-Khabaz's actions were malicious. People with malicious intent do not draw attention to themselves prior to the event, nor do they advertise the exact attack that they will use.

You're still stumbling through systems you are not explicitly invited into. I understand why you might feel that good intentions validate the act, but assuming that all administrators are so gracious would be dangerous :P

No, not "validate", that would be equally black-and-white thinking. But a decision of the legality and morality of the action should take into account the whole circumstances, not just the bare fact of the unauthorized access.

This seems similar in many respects to the Aaron Swartz case. My initial response rejects the idea that all actions regardless of motive should be taken as equally unlawful and unethical.

Re: Youth expelled from Montreal college after finding security flaw

#222
post #104

Unauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college dis…

You are probably correct that what he did is probably unlawful (Canadian law is usually fairly close to US law), I disagree that it was unethical.

In a general sense It's not difficult to find instances of behaviour that, while lawful are far from ethical, so those to things don't necessarily travel together. Some examples: http://en.wikipedia.org/wiki/Sexual_Sterilization_Act_of_Alb... http://en.wikipedia.org/wiki/Canadian_Indian_residential_sch... Obviously this could be a long list...

In this specific instance it seems that his information was exposed by this flaw along with everyone else's. Wanting to verify the safety of your own information feels like a pretty reasonable and ethical thing.

I think I would rephrase your example a little: "Let's suppose you let someone store their stuff at your house you come back home and find them picking on your door lock with a lock picking tool. You ask him "what are you doing?" and he says "I'm just checking is your lock safe. I do it for your security." Would you believe him?"

Re: Youth expelled from Montreal college after finding security flaw

#223

Earlier quoted context omitted.

Evidently the corollary to Arthur C Clarke's famous quote on technology and magic is that those who create it are witches and wizards. You like the magic and you need a few practitioners but when things start getting weird, it's pitchfork o'clock.

I don't know if he was the first, but I assume you got this from Robert Graham's recently proposed corollary "Any sufficiently technical expert is indistinguishable from a witch" http://erratasec.blogspot.com/2013/01/i-conceal-my-identity-...

It actually just occurred to me spontaneously but I'm pleased to find myself in good company

Re: Youth expelled from Montreal college after finding security flaw

#224
Apparently he refused to "cease and desist" his actions. So...he brought on the expulsion!?

Dawson statement on the article: The reasons cited in the National Post article for which the student was expelled are inaccurate. The process which leads to expulsion includes a step in which a student is issued an advisory to cease and desist the activities for which he or she is being sanctioned, particularly in the area of professional code of conduct.

Re: Youth expelled from Montreal college after finding security flaw

#226

I'm going against the general idea here, but the college issued a statement: http://www.dawsoncollege.qc.ca/home Basically, they say Ahmed did more than just what is reported in the article, and they can't publicly say what he did - because that's private info about Ahmed that they're legally obliged to protect. Now I'm not taking a position in favor of the college or in favor of Ahmed. I'm just saying, it's not all…

The site is now 403'ing but I'm really curious what else he could have done and didn't admit to for his story. Personally, this all makes sense right up until the point where the president of Skytech says Ahmed should not have run his tests but that he understands Ahmed was not being malicious. But then Skytech wants him expelled, and the university wants to protect Skytech's interests? Expelling him would get the story out and accomplish literally the opposite of saving face, even with his inability to disclose details.

Based on other stories of bureaucratic ignorance it's easy to jump on the administrative / cover-up blame train, but something about this doesn't quite mesh, and the fact that the story's only alibis are 1) Ahmed and 2) a generic students' rights organization makes it difficult to digest.

Re: Youth expelled from Montreal college after finding security flaw

#227

I'm wondering if that NDA included the clause that urges you to get advice from a lawyer. The conditions under which he signed it sound very suspicious (i.e. coercive language) and I wonder if it would be grounds to nullify the NDA entirely.

I'm curious, how often does this occur? "included the clause that urges you to get advice from a lawyer" I can't recall being offered a NDA with this language.

All the contracts of some form or another in the jurisdiction of California that I've reviewed recently include some language to that effect, usually at the end among the warranties and disclaimers.

Re: Youth expelled from Montreal college after finding security flaw

#228

Earlier quoted context omitted.

What an incredibly succinct way to put it. Props. I have a lurking feeling that in spite of all of the technologist/futurist optimism in our community, we are likely underestimating the pushback from the world at large when enough people at the same time are finally put out of work due to the same technological innovation we strive so furiously for in our own lives.

I've always doubted we would ever encounter this situation to be honest. The invention of vending machines didn't put convenience stores out of business but it did create a new class of technician to service them. What I'm worried about is that as we move towards more ubiquity with computer technology in our lives, the "coder" will become a second string, blue collar job rather then a legitimate, organized profession…

You're right - the invention you mentioned did not put stores out of business. But there have been inventions and technologies and new business models that have put people out of work before. That's not a controversial fact I think...

My point is that if enough of those disruptive technologies get introduced in a small enough time frame to put enough people out of work, then we might see some unexpected pushback.

Re: Youth expelled from Montreal college after finding security flaw

#229

I'm going against the general idea here, but the college issued a statement: http://www.dawsoncollege.qc.ca/home Basically, they say Ahmed did more than just what is reported in the article, and they can't publicly say what he did - because that's private info about Ahmed that they're legally obliged to protect. Now I'm not taking a position in favor of the college or in favor of Ahmed. I'm just saying, it's not all…

It might not be black or white. The kind of people who will abusively kick someone out to cover their ass are the same kind of people who will bend the truth later.

We just don't know.

Re: Youth expelled from Montreal college after finding security flaw

#230
post #66

Back in 1999 when I was a freshman in university, my school had a server for students to host their websites on and use Pine for email. The server did not give shell access... but then there was a security hole in Pine that would allow you to run chsh. So I did that, and got shell access. I think the worst thing I did (other than running ls in a few directories) was use it to connect to IRC. Since I wasn't really try…

Was MAC spoofing not doable in 1999?

It was, and I did use that to verify the new ethernet drop worked, but I would have to spoof it 24/7 for ~6 months. One slip meant losing the internet. So I thought the $10 on a LAN card was a good investment.
Post reply on HN