Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

301–308 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#301

Earlier quoted context omitted.

You're right - the invention you mentioned did not put stores out of business. But there have been inventions and technologies and new business models that have put people out of work before. That's not a controversial fact I think... My point is that if enough of those disruptive technologies get introduced in a small enough time frame to put enough people out of work, then we might see some unexpected pushback.

I wonder whether, instead of the "traditional" software industry feeling the brunt of that push-back, it'll be the robotics industry?

Perhaps; but I think the anger will be directed toward the perceived elitist "intellectual class". I mean, we already see a lot of that rhetoric in politics. (At least in American politics.)

Re: Youth expelled from Montreal college after finding security flaw

#302

Earlier quoted context omitted.

I think what the GP meant was something along the lines of "Unauthorized security testing is indistiguishable from Malicious attack", in the sense that you cannot but expect the administrators of the system in question will react in alignment with their own goals. And you really have no control whether they perceive you as an ally or a threat. Orthogonal to this fact is the question of what happens when an authority…

>"Unauthorized security testing is indistiguishable from Malicious attack" Of course it's distinguishable. Testing comes before attacking, to provide information. The two are otherwise completely unrelated. It'd dead-easy to distinguish between someone poking your fence and someone stealing your jewelery, for example.

You are willingly missing the point here. It is human nature to assume malicious intention, even if it is wrong. And if there's no a strong motive to provide a due process and investigate, malicious intention will will be assumed.

If a random male servant is found to have gained unauthorized access to the princess' chamber, torture comes first and beheading comes last. In-between questioning regarding his intentions and the degree of fulfillment is optional.

Re: Youth expelled from Montreal college after finding security flaw

#303

Earlier quoted context omitted.

>"Unauthorized security testing is indistiguishable from Malicious attack" Of course it's distinguishable. Testing comes before attacking, to provide information. The two are otherwise completely unrelated. It'd dead-easy to distinguish between someone poking your fence and someone stealing your jewelery, for example.

You are willingly missing the point here. It is human nature to assume malicious intention, even if it is wrong. And if there's no a strong motive to provide a due process and investigate, malicious intention will will be assumed. If a random male servant is found to have gained unauthorized access to the princess' chamber, torture comes first and beheading comes last. In-between questioning regarding his intentions…

You don't do that if you have video evidence of him entering, standing there for 15 seconds, and leaving.

There is a huge difference between catching someone in the act of breaking in, where it's reasonable to assume malicious intention, and noticing that someone entered and left, where you can see that they didn't do anything malicious.

Re: Youth expelled from Montreal college after finding security flaw

#304

This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared…

Had a very similar experience at my university. The library worked in the same manner as you described -- the login was a function of your student ID number, and the password was initially the same.

I wondered about the security of that solution, so I checked some random ID numbers to shockingly find out that about 80% of people didn't change their passwords! (I don't remember if you were actually prompted to change it upon first login, or you just had to do it by yourself). I could log in multiple times from the same IP to different accounts.

I hesitated whether to notify someone about it, or to loan a copy of "Mathematical analysis 1" or sth like that for some 100 people in the middle of the holidays within half an hour. That would be hilarious, but they would inevitably throw me out the university if they found out, so I didn't risk the action, neither notifying anyone due to the horror stories here and there.

Re: Youth expelled from Montreal college after finding security flaw

#305
post #94

Earlier quoted context omitted.

link to zsh story: http://news.ycombinator.com/item?id=3901634

In high school I had to write a long apology essay in part because my computer teacher testified to the principal that the Windows command line is "a high-security area of the computer that students have no business accessing." I tried to explain that she was wrong, but you can guess how well that went.

While we're sharing anecdotes...

In high school, I was doing a programming course. I was working on my assignment in the library, when the librarian came in and started yelling at me for hacking. I explained that it was course-work, and she said "Oh, alright then.".

One week later, she came in yelling at me "I've already warned you once about this!", and kicked me out of the library.

* confused-look

Re: Youth expelled from Montreal college after finding security flaw

#306

He treaded on thin water and he fell in. He should have asked for explicit permission to start pentesting instead of putting his academic career in a volatile state.

However, if the article framed things correctly, the college's response is overkill.

I would have given him a second warning.

Re: Youth expelled from Montreal college after finding security flaw

#307

There should really be a Department of Computer Security run by most national governments where people can anonymously report exploits, and that Department takes care of contacting the company or organization. If that group also deals with certain types of personal information that is threatened, there should have 30-60 days to demonstrate that they addressed the vulnerability appropriately, or face penalties. Its re…

There are "Computer Emergency Readiness Teams" in most countries, the United States one is

http://www.us-cert.gov/

The one in my country gets anonymous report exploits for state-run software. Not sure what they do wit them though :)

Re: Youth expelled from Montreal college after finding security flaw

#308

I beleive Skytech should hire this bloke for a "and they lived happily ever after" story. It's essentially a win-win for Skytech.

Apparently, he's been offerred a job from Skytech!

http://news.ycombinator.com/item?id=5090108

Post reply on HN