Live data from Hacker News

Youth expelled from Montreal college after finding security flaw

news.nationalpost.com

91–100 of 308 posts

Re: Youth expelled from Montreal college after finding security flaw

#91
post #75
post #9

I found something like this at my school. The administration reacted similarly. But fortunately, I was taking djb's Unix Security Holes at the time, and a harshly-worded note from djb to the Computer Center folks ended up getting me a thank you. Next semester, though, I refused to sign the new AUP (which included a clause allowing the computer center staff to seize any computer I was using, even at my off-campus home…

These expulsion stories sound really weird. I mean you pay for all of your studies and still could get axed on a whim? Whereas in my country I get paid to study and have zero chance of being expelled for these kinds of events.

Which country may I ask? Nordic?

Re: Youth expelled from Montreal college after finding security flaw

#92
Most schools have an acceptable use policy for their students which covers unauthorized vulnerability probing and port scanning.

I can understand Ahmed's youthful curiosity about whether the vulnerabilities that he identified had been fixed...But he had handed off the info to the Dawson College IT team and the ball was no longer in his court.

Running Acunetix against the college's/SkyTech's server(s) was a pretty dumb move. But hell, when you are in your early 20s, that's when you are supposed to make dumb mistakes.

I'm all for teaching moments, but this "One Strike And You Are Expelled" issue irks me.

Ultimately, this is about Edward Taza of Skytech Communications being sleazy and manipulative by threatening a scared, inexperienced 20 y/o college student with expensive legal action and implying the possibility of jail time unless he signed a non-disclosure agreement.

The EFF should probably take a look at this.

Re: Youth expelled from Montreal college after finding security flaw

#93
I've already posted my "almost got arrested for using zsh" story, so here's another one:

I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes.

After sniffing the IP address + port of the IRC server and the channel name and password the botnet was using, I joined the channel with a regular IRC client. "/who #channel" listed thousands of compromised clients, including hundreds with .edu hostnames. (One university had a dozen hosts from .hr.[university].edu in the channel. Sleep tight knowing your direct deposit information is in good hands.)

There was no way I could notify everyone, so I concentrated on e-mailing abuse@ the .edu domains. In my e-mails, I explained who I was and where I worked, that one of our computers had been compromised by hackers (yeah yeah terminology), and that in the course of investigating, I found that computers at their university had also been compromised by the same hackers. I also included a list of the compromised hostnames at their university and the IRC server's information so their networking people could look for other compromised hosts connected to the IRC server if they wanted to. Relatively basic IT stuff.

I didn't get replies from the majority of the universities I sent messages to, including the .hr.[university].edu one. I got a few thank yous, but I got just as many replies from IT Security Officers and CIOs (including at big name universities) accusing me of hacking their computers and demanding that I stop immediately or face legal action.

Those people just didn't understand, and they were in charge of (or ultimately responsible for) their universities' IT security efforts... It was completely mind-boggling to me at the time.

Re: Youth expelled from Montreal college after finding security flaw

#94
post #93

I've already posted my "almost got arrested for using zsh" story, so here's another one: I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes. After sniffing the IP address…

link to zsh story:

http://news.ycombinator.com/item?id=3901634

Re: Youth expelled from Montreal college after finding security flaw

#96
post #84

Who in their right mind would think it's a good idea to use a penetration tool against their college?? The title is all wrong. He got expelled for using a penetration, not finding a flaw. He was congratulated for that! I heard someone else from the team even got some kind of prize for it. Sensationalist journalism is what it is. After a little bit of research, I discovered it's written by someone who used to be in Da…

Maybe the right response would be to legally punish - by fine - both parties.

After all, there is private data insufficiently safeguarded. Some poor girl could end up getting stalked if the right kind of sleeze came across this.

Re: Youth expelled from Montreal college after finding security flaw

#97
post #56

Earlier quoted context omitted.

Do you think there is a chance that the university over reacted without the company in loop?

The president of the company is the one who allegedly intimidated the student into signing a NDA by threatening to call the police and have him arrested. If that's how it happened, then it's irrelevant what the school did.

> The president of the company is the one who allegedly intimidated the student into signing a NDA

Missed that part - now it makes me think back on my suggestion. Probably, he should just look around on HN. :-)

Re: Youth expelled from Montreal college after finding security flaw

#98
post #75

Earlier quoted context omitted.

These expulsion stories sound really weird. I mean you pay for all of your studies and still could get axed on a whim? Whereas in my country I get paid to study and have zero chance of being expelled for these kinds of events.

Which country may I ask? Nordic?

Yes, Finland.

Maybe it's because all of our schools are public? For example higher ed. providers are funded based on enrollment and rate of graduation. If someone does not graduate, significant chunk (20-30%) of money won't be paid at all. This creates some incentive for the institution to actually guide and see that people don't fall through all kinds of cracks. I guess it's necessary when there is no ordinary paying customer relationship involved.

Re: Youth expelled from Montreal college after finding security flaw

#99
I think the college administrators are bullying this student because they are embarrassed.

The threats by the Skytech CEO Edouard Taza; the college not allowing the professors to hear the student before voting; his transcripts vandalized with zeroes so he cannot continue his studies elsewhere... What exactly is the relationship between Skytech and this college?

I've signed the petition to reinstate Hamed:

http://www.hamedhelped.com/petition/

Hamed, stick to your guns. You did the right thing.

Re: Youth expelled from Montreal college after finding security flaw

#100
post #93

I've already posted my "almost got arrested for using zsh" story, so here's another one: I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes. After sniffing the IP address…

Evidently the corollary to Arthur C Clarke's famous quote on technology and magic is that those who create it are witches and wizards.

You like the magic and you need a few practitioners but when things start getting weird, it's pitchfork o'clock.

Post reply on HN