Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

51–60 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#51
This sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him.

That scared the crap out of me though and I realized this was a VERY bad idea. Something as harmless as trying to help someone make their website more secure can get you more jail time than robbing a bank.

I also, completely accidentally, logged into another student's account at my university (a big university too). The school gives you an ID number. Your initial password is the same as this ID, and you're supposed to change it later. I didn't remember my ID correctly, swapped two numbers in it, and ended up in someone else's account. Home address, phone number -- all sorts of information staring me in the face. Will I report this issue? Heck no!

It's weird how many of these I discover by accident. My school also had a hackathon hosted by eBay and PayPal. In fact, one of the programmers from PayPal was there. During the hackathon, I stumbled upon a way to get account information without authentication (security tokens were being seriously misused). The PayPal guy was shocked and asked me to send him all the information on what I had found. Never did get any sort of reward out of that... (and I lost the hackathon too).

Re: Youth expelled from Montreal college after finding security flaw

#53
I've only reported a security issue once and wouldn't do it again. In this case a vendor and IT has agreed to allow several security settings to be disabled temporarily, making all user passwords easily available in the process, but then had apparently forgotten and left things vulnerable for 6 months. IT had to brief some senior people who then started freaking out about hackers. I was lucky to just get off with a few people annoyed with me.

Re: Youth expelled from Montreal college after finding security flaw

#54
post #18

Shame on the faculty! Fire the faculty! I am sure this sort of thing wouldn't fly in France. Looks like Quebec is letting down the Fracophone team. Liberté, Égalité, Fraternité!

Do you mean the dean who ran the judicial hearing? If anyone were to have their heads roll so to speak for this it would be his. The faculty that voted were simply acting on the best information which was presented to them.

People who are supposed to be the shepherds of an environment that fosters free-thinking openness, curiosity, creativity and learning should not lend credence to witch-hunts. If they have a critical-thinking faculty to match their titles, then they should very well have realised that the process they rubber-stamped was one-sided and questionable.

Re: Youth expelled from Montreal college after finding security flaw

#55
post #20
post #16

So why exactly did Tazo (The incompetent president of the company responsible for the security breach) mention "police" and "legal consequences" in his conversation if he wasn't making a threat. If you are going to be a lying asshole and deny something, do yourself a favor and deny it outright. Don't try to imply that you were just having a friendly conversation about "legal consequences" right before you solicit som…

seeing how we don't have the actual logs of the conversation, who knows what was actually said. This is the biggest problem with these stories: we only get information through very partial observers.

That's why I only mentioned what the President admitted to saying.

Re: Youth expelled from Montreal college after finding security flaw

#56
post #15

Earlier quoted context omitted.

After the way this was handled, I'd live in a cardboard box before I worked for this company. You can't have a healthy working environment without trust. I'd give it a shot if they fired their president, but that's an unrealistic expectation.

Do you think there is a chance that the university over reacted without the company in loop?

The president of the company is the one who allegedly intimidated the student into signing a NDA by threatening to call the police and have him arrested. If that's how it happened, then it's irrelevant what the school did.

Re: Youth expelled from Montreal college after finding security flaw

#57
post #50

> The agreement prevented Mr. Al-Kabaz from discussing... No, it didn't, because he was blackmailed into the NDA. It's completely unenforceable. It was signed under duress and only benefited one party.

You misunderstand the purpose of an agreement like that. It's not like it magically binds your tongue. It just makes it easier to sue you if you violate it. The fact that the student could win in a suit is irrelevant. He couldn't afford the time and money to fight. Before he signed the NDA, they would have had a harder time suing him. Perhaps he could have spent merely $10k and gotten it quickly dismissed. After, the…

You're absolutely correct, I hadn't considered that.

Re: Youth expelled from Montreal college after finding security flaw

#58
Maybe the answer is if you find a problem like that don't keep a secret between you and the person in charge.

Just go to the school paper or town paper and let them report it.

He did great up to the point where he tried to pen-test after reporting it. I understand the intellectual curiosity to see if people are doing their jobs and it's too easy to armchair quarterback but if you bring attention to yourself by reporting a problem you can be sure they will watch you and not necessarily the problem.

Re: Youth expelled from Montreal college after finding security flaw

#59
post #31
post #25

I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…

During undergrad I discovered the university's blackboard-like site sent plaintext passwords over http, and the majority of its use was over wireless. I went to the IT office responsible for the site, told them about it, and refused to give my name when they asked. After reading some of the horror stories on this page, I feel really lucky that the IT department didn't go further to figure out who I was and get me in…

The fact that they went https tells us you would probably be okay.

People who go after security bug reporters tend to never fix the bugs in question. They're, like, too righteous for it.

Re: Youth expelled from Montreal college after finding security flaw

#60
While I do not agree with the way this student was being treated, running Acunetix on a system is quite invasive. Regardless of his intent, the consequences might have been data loss and/or denial of service if the system was built poorly enough. Doing extensive vulnerability assessments without consent is really not a good idea.
Post reply on HN