Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

261–270 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#261

Earlier quoted context omitted.

30% of MBA's are engineers, and the most common degree for CEO's is engineering. 1/3 of S&P 500 CEO's have an engineering degree, even though only a small fraction of the S&P 500 is tech companies.

A lot of people get engineering degrees as a signalling mechanism to prove they can do hard work, not because they have any interest in becoming engineers. Formal training in a subject combined with a lack of intrinsic curiosity about the subject makes the worst engineering managers you will ever meet.

I think this is probably true.

Empirically speaking, a lot of the guys who graduated with their B.Sc. in computer science with me saw their career paths as joining a big consulting company, working on the front lines for a couple of years and then getting into management and leaving the code behind for good.

In my PhD program, most guys in the lab saw the actual engineering side of things as a stepping stone to higher-paid positions in acadaemia.

Clearly a significant number of people with engineering degrees are engineers only by title.

Re: Youth expelled from Montreal college after finding security flaw

#262

The title is misleading. He wasn't actually expelled for finding the flaw; he was expelled because, after reporting the flaw, he ran an exploit program on the school's server without permission, allegedly to see if it had been fixed. Had he only reported it, he would not have been subject to any disciplinary action.

So the fact that the submission title is misleading makes the university's heavy-handedness easier to swallow?

I didn't say anything about whether the decision was justified. I only elaborated on the reason behind it.

Re: Youth expelled from Montreal college after finding security flaw

#263

Earlier quoted context omitted.

> "The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). What's more, you don't even have to have a gun for it to be classed as "armed ro…

This seems more like walking up to a teller and asking nicely in a clever way if you could have all the money. Is it even a crime if the teller responds positively to your request?

There's no nice way of saying you have a gun.

Also handling stolen goods is a crime. So even if you didn't personally rob the bank, if you know the money is dodgy then you shouldn't accept it.

Re: Youth expelled from Montreal college after finding security flaw

#264

Earlier quoted context omitted.

The site is now 403'ing but I'm really curious what else he could have done and didn't admit to for his story. Personally, this all makes sense right up until the point where the president of Skytech says Ahmed should not have run his tests but that he understands Ahmed was not being malicious. But then Skytech wants him expelled, and the university wants to protect Skytech's interests? Expelling him would get the st…

I graduated from CS at Dawson and know the faculty quite well. I had the same exact reaction as most people when reading the article up until the point where I saw that 14/15 of the faculty members voted in favour of expelling the student. That right there makes me wonder what else he did. The faculty told me that there are other things that caused this and they are unable to discuss them with me. I wish it were poss…

I also graduated from CS at Dawson. I've been told that Taz and François Paradis know each other quite well and this is probably the result of said friendship. But this is all heresay.

Re: Youth expelled from Montreal college after finding security flaw

#265
This story is somewhat complex, and lacks information on many aspects. I've made a kind of TLDR of what happened and added my thoughts. I've also cross compared the informations given in the article with those available on dawson's college web page and Skytech's omnivox.

[he was] working on a mobile app to allow students easier access to their college account [.] -> Did he have authorisation? -> From who did he have authorisation? -> Omnivox does not seem to have a public API.

“I saw a flaw which left the personal information of thousands of students, including myself, vulnerable,” "I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong.” -> Did he try to fix it, or only bring it to the attention of the college? -> Did he inform the college he tried/would try to fix the flaw? -> Did he try to fix the flaw after or before meeting with the college?

"Mr. Paradis congratulated Mr. Al-Khabaz and colleague Ovidiu Mija for their work and promised that he and Skytech, the makers of Omnivox, would fix the problem immediately" -> Mr. Paradis is Dawson's Director of Information Services and Technology -> I precise only because it is not clear from the article if he works at the college or at Skytech

"Mr. Al-Khabaz decided to run a software program called Acunetix" "to ensure that the issues he and Mija had identified had been corrected" -> Did they use acunetix the first time? -> If yes, did the college know? Did skytech noticed? -> Otherwise, why? They found the flaw without acunetix

"Taza explained that he was quite pleased with the work the two students did identifying problems, but the testing software Mr. Al-Khabaz ran to verify the system was fixed crossed a line."

The administration of Dawson College clearly saw things differently, proceeding to expel Mr. Al-Khabaz for a “serious professional conduct issue.

Following this meeting, the fifteen professors in the computer science department were asked to vote on whether to expel Mr. Al-Khabaz, and fourteen voted in favour. Mr. Al-Khabaz argues that the process was flawed because he was never given a chance to explain his side of the story to the faculty -> Was there other incidents that could have influenced the judgment? -> College rarely want to expel students who ace all their courses. Especially in CS with the high rate of failure.

-> According to the college : The process which leads to expulsion includes a step in which a student is issued an advisory to cease and desist the activities for which he or she is being sanctioned

-> This, along with the "He said that this was the second time they had seen me in their logs" tend to indicate he probably ran the test multiple times. Or, the first time he foud the flaw, skytech took him for an attacked and the college warned him to stop developpement on his application. This would indicate that he had no authorisation in doing so.

Re: Youth expelled from Montreal college after finding security flaw

#266

Shame on the faculty! Fire the faculty! I am sure this sort of thing wouldn't fly in France. Looks like Quebec is letting down the Fracophone team. Liberté, Égalité, Fraternité!

This is superficial and I probably shouldn't answer to this but anyways : Dawson is, in fact, an english college.

Re: Youth expelled from Montreal college after finding security flaw

#267

Earlier quoted context omitted.

I've always doubted we would ever encounter this situation to be honest. The invention of vending machines didn't put convenience stores out of business but it did create a new class of technician to service them. What I'm worried about is that as we move towards more ubiquity with computer technology in our lives, the "coder" will become a second string, blue collar job rather then a legitimate, organized profession…

You're right - the invention you mentioned did not put stores out of business. But there have been inventions and technologies and new business models that have put people out of work before. That's not a controversial fact I think... My point is that if enough of those disruptive technologies get introduced in a small enough time frame to put enough people out of work, then we might see some unexpected pushback.

I wonder whether, instead of the "traditional" software industry feeling the brunt of that push-back, it'll be the robotics industry?

Re: Youth expelled from Montreal college after finding security flaw

#268
post #45

Ahmed, if you're reading this, sorry about your college acting like idiots. If finishing college is important to you, I'm sorry they've made it so difficult. That said, please don't think this is going to end your career. There are a lot of companies and startups that would love to have you for your kind of initiative. Not having a degree that you don't seem to need anyway will not be a sticking point with them. And…

He's technically still in Québec's equivalent of a US high-school 12th grade. Since he's 20, he can wait a year and be accepted to a University.

Re: Youth expelled from Montreal college after finding security flaw

#269

Earlier quoted context omitted.

No they are not bugs, in any way, shape or form. I think you are missing the technology and ethos of website design here. Web scanners do massive offensive attacks. They basically DOS attack your site in many ways, trying millions of attack vectors. Mitigating against vandalism is very hard. It hurts users the more you do. Generally you leave it as open as possible and it is ok, since it's not a security issue per se…

> No they are not bugs, in any way, shape or form. Maybe not all, but some of them are. I think you mentioned different issue here, puerto called unauthorized check 'unethical' and you talk about performance. If Mr. Al-Khabaz used some noninvasive scanner, which didn't bring any serious technical overhead, is it ok by you? > Someone could write a script to cause thousands of $ damage to wikipedia without much trouble…

As per my link to a direct article by the makers of the scanner he used, it is invasive. What more do you want?

Yes, passive scanning is fine with me, it's probably legal in most countries, but this is not certain (See Google and wifi). But I don't see the relevance to the conversation.

Passive automated scanning is fairly useless so it's not really used.

Fact is he broke the law at a criminal level and caused damage, if you can't see this, you really have no idea of the reality of the technology he was using.

But what should happen to him for it is a discussion for a different thread.

Re: Youth expelled from Montreal college after finding security flaw

#270

Earlier quoted context omitted.

I graduated from CS at Dawson and know the faculty quite well. I had the same exact reaction as most people when reading the article up until the point where I saw that 14/15 of the faculty members voted in favour of expelling the student. That right there makes me wonder what else he did. The faculty told me that there are other things that caused this and they are unable to discuss them with me. I wish it were poss…

I also graduated from CS at Dawson. I've been told that Taz and François Paradis know each other quite well and this is probably the result of said friendship. But this is all heresay.

That's interesting. I went to see them today and it didn't seem like they were coerced into expelling him. They seem to really have something that makes them strongly believe it was necessary. Gah, I'd love to know.
Post reply on HN