Earlier quoted context omitted.
While I was expecting downvotes for this comment, I was also looking forward to the discussion that should arguably accompany such downvotes. But that, of course, is a privilege exercised by the downvoter and rarely ever happens!
If you know why you got downvoted then you don't need someone to explain it to you. There are less-irritating ways to start a conversation than trying to be 'loud and wrong'.
Youth expelled from Montreal college after finding security flaw
251–260 of 308 posts
Re: Youth expelled from Montreal college after finding security flaw
#252Earlier quoted context omitted.
My suspicion is that yes, that would be a robbery if you ask in such a way that the teller actually gives you money. You could ask in such a way that it comes across as a joke ( "Anything more I can do for you today sir?" "A million bucks and a winning lottery ticket would be nice" ), but if it comes across as a joke then the teller isn't going to give you any money.. because they think it is a joke.
I think that is a reasonable interpretation, but sets a scary precedent. If you are selling something and I, the buyer, say "I'd really like to get this for free" and you respond, "okay, it's yours!" Can you come back and call on me being a thief later? > if it comes across as a joke then the teller isn't going to give you any money.. because they think it is a joke. I'd also add that vast majority of malformed reque…
For example, there is a world of difference between a panhandler asking you "Hey, can I have a couple dollars" in a populated touristy area during the day, and the same panhandler following you for several blocks at night before asking you that in an ally. One is just panhandling, but the other is effectively a mugging.
Computers don't really have those sort of cues, so it becomes difficult to make reasonable comparisons between the two.
Re: Youth expelled from Montreal college after finding security flaw
#253Earlier quoted context omitted.
Try walking into the safe deposit box area at the bank absent escort or previous notification and see how that works out for you. Again, the school is on record as giving him kudos for reporting the error - it's perfectly reasonable to assume that someone will not launch offensive penetration testing tools at your site, without notice or permission , just because they have reported the bug in the past. He could have…
The webserver did escort him into the room with the safe deposit boxes. He has a key, they let him in, that's their job. The problem is that he could open his box, or any other box, without actually using the key.
Again, the problem isn't that he found and disclosed a bug, the problem is that he attempted to exploit that bug after the fact.
You do not have the right to do that. Pure and simple.
Finding and disclosing a bug is one thing, utilizing it is something else entirely.
Re: Youth expelled from Montreal college after finding security flaw
#254its all a flow chart if you make a mistake in school no matter if its tech stuff like this, or anything really. we live in a world of corporations, lawsuits and lawyers, insurance & liability - no room for grey area anywhere in there. wheres the incentive for the school to care? they already got your money.
the worst part for the students is - they can have all sorts of good feelings built up towards their professors & classes. then the administration comes in and manages to sour all those feelings. those same professors, who may think the world of you, cant do a thing because at the end of the day its c.y.a. - and youre all alone.
college kids need to get educated about how college justice works if you screw up - its always too late when they do learn.....lets spend money on athletic complexes instead right?
Re: Youth expelled from Montreal college after finding security flaw
#255I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…
Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly. Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he…
Re: Youth expelled from Montreal college after finding security flaw
#256Earlier quoted context omitted.
The webserver did escort him into the room with the safe deposit boxes. He has a key, they let him in, that's their job. The problem is that he could open his box, or any other box, without actually using the key.
We're laboring a physical analogy quite hard, here. Again, the problem isn't that he found and disclosed a bug, the problem is that he attempted to exploit that bug after the fact. You do not have the right to do that. Pure and simple. Finding and disclosing a bug is one thing, utilizing it is something else entirely.
Re: Youth expelled from Montreal college after finding security flaw
#257Earlier quoted context omitted.
I think what the GP meant was something along the lines of "Unauthorized security testing is indistiguishable from Malicious attack", in the sense that you cannot but expect the administrators of the system in question will react in alignment with their own goals. And you really have no control whether they perceive you as an ally or a threat. Orthogonal to this fact is the question of what happens when an authority…
>"Unauthorized security testing is indistiguishable from Malicious attack" Of course it's distinguishable. Testing comes before attacking, to provide information. The two are otherwise completely unrelated. It'd dead-easy to distinguish between someone poking your fence and someone stealing your jewelery, for example.
Re: Youth expelled from Montreal college after finding security flaw
#258Re: Youth expelled from Montreal college after finding security flaw
#259I'm going against the general idea here, but the college issued a statement: http://www.dawsoncollege.qc.ca/home Basically, they say Ahmed did more than just what is reported in the article, and they can't publicly say what he did - because that's private info about Ahmed that they're legally obliged to protect. Now I'm not taking a position in favor of the college or in favor of Ahmed. I'm just saying, it's not all…
Re: Youth expelled from Montreal college after finding security flaw
#260Earlier quoted context omitted.
How do you prevent the schools from just lowering graduation requirements in order to artificially boost the percent of graduates and get a better payout?
Since they are either fully government funded or jointly funded with municipalities, there are no incentives to search short term profits by running diploma mills. Ministry of Education controls the money and conducts yearly performance target negotiations bilaterally with each higher education institution. You actually need a permit from the ministry to run any kind of school. Even our few "private" primary and seco…