Live data from Hacker News

Hamed Helped. Help Hamed.

hamedhelped.com

41–50 of 52 posts

Re: Hamed Helped. Help Hamed.

#41

I've read the claims from both sides, I think that although he might have handled it more carefully, it was an overreach to expel him this way, I feel we should stand behind him. I signed the petition. Anyone with counter evidence, please step forward.

Where did you find claims on the school's part?

The only one I've found so far is an audio interview with Mr. Filion; everything else has had the school refusing to comment.

Please provide links.

Re: Hamed Helped. Help Hamed.

#42
post #36

This goes on to show how out of touch with reality our educational systems currently are. They are incentivized by the wrong things, which reflects in the kind of people and policies that are put in place. Before the web and the free dissemination of information it brought about, the average academician was more 'smarter' than the average student just by the fact that the students hadn't yet had access to the sources…

No, universities internationally are furious and disgusted.

This is a trade school, not a college. It's like being angry at DeVry or University of Phoenix. The stupid things that places like that do have nothing to do with real universities.

Re: Hamed Helped. Help Hamed.

#43
post #2

Wow. This is much worse than I thought. I'm glad there's no conceivable scenario in which this could lead him to be extradited to the USA, like Marc Emery was. http://en.wikipedia.org/wiki/Marc_Emery

Stop trolling, please.

Marc Emery sold illegal goods internationally. The two situations have nothing to do with one another.

Re: Hamed Helped. Help Hamed.

#44
post #3

What's the truth here? What did Hamed "do"? Exposing a security flaw doesn't get you expelled. He had to have taken it one or more steps too far. I'd like to see the facts.

> Exposing a security flaw doesn't get you expelled.

Unless you're at a minor Canadian trade school which wants to bury that they knew about the security flaw for months and did nothing about it.

.

> He had to have taken it one or more steps too far.

First he told them about it.

Then he waited a couple months, and tested to see if it was still there, with some free online security scanner; it was.

So he reported it again, and this time contacted the vendor.

The school freaked out, decided that he was hacking them without permission, and expelled him over "code of conduct."

They absolutely refuse to explain, though they keep pretending that there was a law broken. The student went to the RCMP; the RCMP disagrees. So does the original vendor, who has challenged the school, and given the kid a scholarship.

http://www.cbc.ca/homerun/2013/01/21/dawson/

This is just a terrible administrator doing new damage trying to bury his own failure.

Re: Hamed Helped. Help Hamed.

#45

Moral of the story: Sanitise your query params.

I think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.

At real universities, this doesn't happen.

I've seen scholarships handed out over this. But you never hear about those, because nobody's angry.

Hiding responsible disclosure just means you aren't responsible.

Re: Hamed Helped. Help Hamed.

#46

Earlier quoted context omitted.

I think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.

At real universities, this doesn't happen. I've seen scholarships handed out over this. But you never hear about those, because nobody's angry. Hiding responsible disclosure just means you aren't responsible.

Well yes, it can be leveraged. But one needs to be careful about it.

You can't just go talking about it or sending official letters to the administration or the IT department. Personally should I want to disclose something like this I would first approach a maverick amongst faculty staff to test the waters. After consultation with a person with good knowledge of the local political landscape I would discretely relay my knowledge.

But it is still risky and leaving no evidence is still a safe bet.

Re: Hamed Helped. Help Hamed.

#47
post #12

Earlier quoted context omitted.

I don't understand how using an external attack tool is grounds for anything. If Hamed could use it to search for exploits an attacker could have used it to search for exploits. Especially if a students' information had been previously exposed and the attacker had access to everyone's personal information / passwords! -- Edit : after reading his expulsion letter, it seems he supposedly injected SQL on both occasions.…

Either ways, the solution should be to fix the security system and reward the whistleblower. In a few years, we are going to have millions of teenagers with the competence and ability to pull of what Hamed did. What then?

Obviously those youngsters are all criminals that ought to be put to jail. We shall implement a zero-tolerance policy, just like the copyright industry did.

Nevertheless, I'm afraid they might do just that.

Re: Hamed Helped. Help Hamed.

#48
post #3

What's the truth here? What did Hamed "do"? Exposing a security flaw doesn't get you expelled. He had to have taken it one or more steps too far. I'd like to see the facts.

> Exposing a security flaw doesn't get you expelled. Unless you're at a minor Canadian trade school which wants to bury that they knew about the security flaw for months and did nothing about it. . > He had to have taken it one or more steps too far. First he told them about it. Then he waited a couple months, and tested to see if it was still there, with some free online security scanner; it was. So he reported it a…

Damage control is often about redirecting the damage.

Re: Hamed Helped. Help Hamed.

#49
post #29

Earlier quoted context omitted.

Sorry but that's bullshit. What you've said is that the guy simply got caught and therefore this was not a case of responsible disclosure. The letter doesn't say that. No other sources say that. You're the only one saying that.

I did read the blocking of his account to mean that he was detected in some form. You may not agree with my reading of that letter, and I certainly don't agree with mrtron's reading of the letter, but that's why I asked people to read the original letter anyway. I never said that it was not a case of responsible disclosure. I simply don't know, the evidence at this point seems insufficient to support either conclusio…

What I'm surprised about is the alleged suspension of Ahmed's account. Also, if Ahmed "admitted" something in writing, I'd like to have a copy.

Re: Hamed Helped. Help Hamed.

#50

I have to wonder how much this will help. A colleague and I made a responsible exposure to a vendor that provides the application software for the California State University system. The vulnerability I chanced upon, and that my colleague was able to verify to be fully open, made it possible to obtain the private details of hundreds of thousands of applicants from their system. How were we rewarded for quietly and re…

They got so embarrassed that they challenged the school to change its mind, and offered the kid a full scholarship to wherever he goes next. http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont... In the meantime, their student body is furious that the staff have been knowingly leaving their private information public for months. So I'd say "a lot."

Well, kind of. I read this was successful in targeting the company to react positively towards Hamed, however, the university is still throwing the book at him. I guess that's a better tactic, going publicly after the company, rather than through university management.
Post reply on HN