Live data from Hacker News

Teen Reported to Police After Finding Security Hole in Website

wired.com

91–100 of 123 posts

Re: Teen Reported to Police After Finding Security Hole in Website

#91
post #79

In December I found a glitch in my university's directory that let me have access to personal info of over 60,000 professors, students, and staff. I was thinking of writing an email to the IT, but fuck that. I'm not paying for someone else's mistake.

Send an anonymous email or other notification to them? I agree it's scary to be penalized for "hacking" the system (in their eyes), but I also think these things can't be left alone. It'd be cool if you found a way to let them know.

What's an anonymous email? Even Tor is subject to tracking if the endpoint IPs are monitored [1].

The issue of anonymous disclosure is a real issue if you don't

Why do you think Wikileaks was such a big/new deal?

[1] http://www.forbes.com/sites/runasandvik/2013/12/18/harvard-s...

Re: Teen Reported to Police After Finding Security Hole in Website

#92
post #37

To me this is really weird. If a neighbor knocks on your door to tell you that you forgot the keys in the keyhole outside you thank him, you don't call the police...

This is a bit different and would be like the neighbor opening the door and waking into your bedroom to tell you.

I think it has to do with intentions. Not trying to literally map online site to a house. But in general, when a person has found a vulnerability and is trying to report it in a good will (no matter through what channel), as opposed to using it to try and blackmail, etc., things should not be reversed and used against that person.

Re: Teen Reported to Police After Finding Security Hole in Website

#93
post #79

In December I found a glitch in my university's directory that let me have access to personal info of over 60,000 professors, students, and staff. I was thinking of writing an email to the IT, but fuck that. I'm not paying for someone else's mistake.

Send an anonymous email or other notification to them? I agree it's scary to be penalized for "hacking" the system (in their eyes), but I also think these things can't be left alone. It'd be cool if you found a way to let them know.

Or, similarly, drop a physical, paper note off under their door explaining the problem.

Re: Teen Reported to Police After Finding Security Hole in Website

#94

Earlier quoted context omitted.

Thanks for the friendly correction! I am no native speaker and every friendly correction is helpful, of course! Trouble with spelling correction: It does not understand context and thus lets you run into wrong wording ....

Meta: I've mentioned it before here - why is standard spell-checking so lame. The phrase "It seams that" is only going to be correct about 1 in a few-million times ["if you bend it seams that have high pressure applied will burst", maybe]. If I was clever enough I could probably fix it; I've heard that phrase based analysis is used for translation. Most homophonic spelling errors seem fixable using automated lexical…

One of the Senior Thesis presentations at my college last year was someone working on a context spell-checker. I don't know if his demo could suggest a better word, but it would highlight words that seemed wrong.

It was based off of Google's NGrams, I think he used 3-grams, and checked to see how frequently a word showed up between the two words next to it.

The problem with that was it required a HUGE amount of data. Like several hundred gigabytes worth of space just to store the 3-grams (compressed down to one instance of each 3-gram coupled with the number of times it showed up in the original dataset).

Re: Teen Reported to Police After Finding Security Hole in Website

#95

Earlier quoted context omitted.

And every time that happens a bunch of apologists appear shouting "Why didn't they inform the site operators first? That is really irresponsible" And then some poor teen believes it and thinks "maybe it's wise to inform the site first" and subsequently goes to jail for doing the 'responsible' thing. And so the cycle continues.

Wouldn't combining the two tactics be the actually responsible thing to do? Inform the operators anonymously, and tell them that in four weeks a copy of this e-mail will be publicized.

Because that might seem like blackmail to some people...

Re: Teen Reported to Police After Finding Security Hole in Website

#96

In high school I was blacklisted from an admin position for demonstrating that you could write in Digital Command Language a program that simulated the login environment, stored login attempts, and then after three tries exited to the real login environment to let the user in. In college I was nearly expelled for just mentioning to the IT guys that they didn't have a password on some database, and I could get in with…

Funny enough, I did the exact same thing when I was in high school, only we were running Novell on NT4 and I did it in basic and started it from autorun.bat which loaded before the network login screen. It would let you try one time, tell you you entered the wrong password (saving it to file) and exit, at which point windows would load the novell login screen that looked exactly the same. Good times.

Wasn't that autoexec.bat? I could be wrong here, but I think that's what I used ;) Same methods!

Re: Teen Reported to Police After Finding Security Hole in Website

#97
post #91

Earlier quoted context omitted.

Send an anonymous email or other notification to them? I agree it's scary to be penalized for "hacking" the system (in their eyes), but I also think these things can't be left alone. It'd be cool if you found a way to let them know.

What's an anonymous email? Even Tor is subject to tracking if the endpoint IPs are monitored [1]. The issue of anonymous disclosure is a real issue if you don't Why do you think Wikileaks was such a big/new deal? [1] http://www.forbes.com/sites/runasandvik/2013/12/18/harvard-s...

[deleted]

Re: Teen Reported to Police After Finding Security Hole in Website

#98
post #91

Earlier quoted context omitted.

Send an anonymous email or other notification to them? I agree it's scary to be penalized for "hacking" the system (in their eyes), but I also think these things can't be left alone. It'd be cool if you found a way to let them know.

What's an anonymous email? Even Tor is subject to tracking if the endpoint IPs are monitored [1]. The issue of anonymous disclosure is a real issue if you don't Why do you think Wikileaks was such a big/new deal? [1] http://www.forbes.com/sites/runasandvik/2013/12/18/harvard-s...

Lol, you've never opened a gmail account using fake data and sent from there? Yahoo? Hotmail?

The FBI will help your sys admin investigate a bomb threat, obviously. Reporting a security hole will unlikely draw their interest. Yes, just using a fake gmail account is tracable without more protections (like correctly accessing Tor). Again, I doubt the FBI is going to investigate.

But hey, I'm all for paranoia and extra caution.

Plus, rtfa you linked. It says clearly in the first few paragraphs that Tor did NOT fail this guy, but that he's an idiot in how he accessed it.

Lastly, as mentioned, send an anonymous letter. It's not hard, kids!

Re: Teen Reported to Police After Finding Security Hole in Website

#100
post #79

In December I found a glitch in my university's directory that let me have access to personal info of over 60,000 professors, students, and staff. I was thinking of writing an email to the IT, but fuck that. I'm not paying for someone else's mistake.

Send an anonymous email or other notification to them? I agree it's scary to be penalized for "hacking" the system (in their eyes), but I also think these things can't be left alone. It'd be cool if you found a way to let them know.

Then you have to worry that they might track you down. How will you send an anonymous email? The library will have cameras, so might the coffee shop. The fake email you setup might store information about your location as well. You can never be too careful. It might be better to send a regular old mail.
Post reply on HN