Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

241–250 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#241
post #188

I don't agree that expulsion is the correct reaction, but when he ran the pen-test software, what he was doing was wrong. It's one thing to stumble upon a bug while you're developing an app, and report it. That's totally respectable. Running pen-testing software without permission is akin to walking up to a stranger's home and testing that all the windows are locked, with a crowbar.

I can't help but feel a better analogy is finding a rip in the seat of a bus, reporting it, and then poking at the rip a few days later to see if it has been repaired. Going at someone's windows with a crowbar doesn't seem to fit the situation at all, in my opinion.

Re: Youth expelled from Montreal college after finding security flaw

#242
post #98

Earlier quoted context omitted.

Yes, Finland. Maybe it's because all of our schools are public? For example higher ed. providers are funded based on enrollment and rate of graduation. If someone does not graduate, significant chunk (20-30%) of money won't be paid at all. This creates some incentive for the institution to actually guide and see that people don't fall through all kinds of cracks. I guess it's necessary when there is no ordinary payin…

How do you prevent the schools from just lowering graduation requirements in order to artificially boost the percent of graduates and get a better payout?

Well, that is a problem. But universities also doesn't want to be known for poor quality. And then there is pretty strong government oversight. In Sweden the National Agency for Higher Education do regular audits and have the right to remove a schools privilege to award degrees.

Re: Youth expelled from Montreal college after finding security flaw

#243

Earlier quoted context omitted.

> "The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). What's more, you don't even have to have a gun for it to be classed as "armed ro…

This seems more like walking up to a teller and asking nicely in a clever way if you could have all the money. Is it even a crime if the teller responds positively to your request?

My suspicion is that yes, that would be a robbery if you ask in such a way that the teller actually gives you money.

You could ask in such a way that it comes across as a joke ("Anything more I can do for you today sir?" "A million bucks and a winning lottery ticket would be nice"), but if it comes across as a joke then the teller isn't going to give you any money.. because they think it is a joke.

Re: Youth expelled from Montreal college after finding security flaw

#244

I'm going against the general idea here, but the college issued a statement: http://www.dawsoncollege.qc.ca/home Basically, they say Ahmed did more than just what is reported in the article, and they can't publicly say what he did - because that's private info about Ahmed that they're legally obliged to protect. Now I'm not taking a position in favor of the college or in favor of Ahmed. I'm just saying, it's not all…

The site is now 403'ing but I'm really curious what else he could have done and didn't admit to for his story. Personally, this all makes sense right up until the point where the president of Skytech says Ahmed should not have run his tests but that he understands Ahmed was not being malicious. But then Skytech wants him expelled, and the university wants to protect Skytech's interests? Expelling him would get the st…

I graduated from CS at Dawson and know the faculty quite well. I had the same exact reaction as most people when reading the article up until the point where I saw that 14/15 of the faculty members voted in favour of expelling the student. That right there makes me wonder what else he did.

The faculty told me that there are other things that caused this and they are unable to discuss them with me.

I wish it were possible to get that information but I know them and I trust them.

Re: Youth expelled from Montreal college after finding security flaw

#245

Earlier quoted context omitted.

> "The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). What's more, you don't even have to have a gun for it to be classed as "armed ro…

This seems more like walking up to a teller and asking nicely in a clever way if you could have all the money. Is it even a crime if the teller responds positively to your request?

[deleted]

Re: Youth expelled from Montreal college after finding security flaw

#247
post #31

Earlier quoted context omitted.

During undergrad I discovered the university's blackboard-like site sent plaintext passwords over http, and the majority of its use was over wireless. I went to the IT office responsible for the site, told them about it, and refused to give my name when they asked. After reading some of the horror stories on this page, I feel really lucky that the IT department didn't go further to figure out who I was and get me in…

The fact that they went https tells us you would probably be okay. People who go after security bug reporters tend to never fix the bugs in question. They're, like, too righteous for it.

Probably, but not necessarily. They could easily harass you saying that the cost of such an upgrade (probably actually measurable only in the effort of some salaried employee..) are damages that you caused.

edit: see the $800k 'damages' Gary McKinnon allegedly caused. It's not like he smashed their equipment with a sledgehammer or something.

Re: Youth expelled from Montreal college after finding security flaw

#248
People are always afraid of what they don't understand, but to think that prosecuting or punishing people for helping prevent malicious people from finding these types of bugs is just ignorant. No ones code is perfect, and it often takes dozens of eyes before issues like this are found.

The longer people are punished for helping, the worse our "cyber security" will digress moving forward.

Re: Youth expelled from Montreal college after finding security flaw

#249

Earlier quoted context omitted.

This seems more like walking up to a teller and asking nicely in a clever way if you could have all the money. Is it even a crime if the teller responds positively to your request?

My suspicion is that yes, that would be a robbery if you ask in such a way that the teller actually gives you money. You could ask in such a way that it comes across as a joke ( "Anything more I can do for you today sir?" "A million bucks and a winning lottery ticket would be nice" ), but if it comes across as a joke then the teller isn't going to give you any money.. because they think it is a joke.

I think that is a reasonable interpretation, but sets a scary precedent. If you are selling something and I, the buyer, say "I'd really like to get this for free" and you respond, "okay, it's yours!" Can you come back and call on me being a thief later?

> if it comes across as a joke then the teller isn't going to give you any money.. because they think it is a joke.

I'd also add that vast majority of malformed requests are denied. Only computers who have a sense of humour, so to speak, comply to the abnormal requests. Computer security is much closer to this scenario than carrying a gun, I feel.

Re: Youth expelled from Montreal college after finding security flaw

#250
post #116

Earlier quoted context omitted.

You can also pastebin it. That's what you should do.

How do new pastebins get discovered? I've never used the service - was assuming someone should post the link to the pastebin on Reddit?

Yeah, Tor->Reddit should work. Alternatively you could fire off some emails to a couple high-ish profile twitter accounts of people/groups that would be interested in taking credit for it.
Post reply on HN