Live data from Hacker News

Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

bits.blogs.nytimes.com

1–10 of 17 posts

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#3
I spent a summer at one of the universities in this dump. It just looks like wordpress user info - nothing particularly sensitive about the data, and mine wasn't in it.

Edit: Looks like one of the tables has plaintext passwords. If I recall correctly, security practices at this university were horrible - social security numbers could be accessed in plaintext, and resetting a password took only a single security question without email confirmation.

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#6

I spent a summer at one of the universities in this dump. It just looks like wordpress user info - nothing particularly sensitive about the data, and mine wasn't in it. Edit: Looks like one of the tables has plaintext passwords. If I recall correctly, security practices at this university were horrible - social security numbers could be accessed in plaintext, and resetting a password took only a single security quest…

My university had similarly bad security practices. Although not accessible as plain text, the social security number was used when you wanted to change personal information.

For example to reset your university email account you needed the last three digits of the ssn and your date of birth. In my case, the school somehow never got my ssn so my ssn in this case was just "0". So theoretically if anyone wanted to change my password they just needed to use "yyyymmdd0" to access it.

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#7
So, I'm at the University of Maryland right now. All three mirrors seem to be down, so I couldn't check if my information was on the list. The article suggests this was done with SQL injection? God, I really hope my university is better than that. Or at least hashes passwords. I'd check if they did, but again, mirrors seem to be down. Sad thing is, I wouldn't be surprised. Despite the 15th best comp sci program in the nation, and ridiculous policies like "change you password to new unique password with at least 1 number and capital letter every 180 days", OIT seems useless on security. Sigh.

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#8
> If we want change we must be ready for it. the future is technology. physical school will become obsolete.

Cute. There's an odd, and I would say silly, obsession amongst some tech-obsessed people to claim the soon obsolescence of things like libraries and universities.

It's wonderful the recent huge push and availability of online materials and courses from big universities and others, especially for those who otherwise could not attend a university for whatever reasons, but to dismiss universities as a singular blob shows a certain misunderstanding and appreciation of what they are actually for and for teaching in general.

I'd recommend sitting in on various mentoring services, other student services, practicals and other things and also to read Zen and the Art of Motorcycle Maintenance.

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#9

So, I'm at the University of Maryland right now. All three mirrors seem to be down, so I couldn't check if my information was on the list. The article suggests this was done with SQL injection? God, I really hope my university is better than that. Or at least hashes passwords. I'd check if they did, but again, mirrors seem to be down. Sad thing is, I wouldn't be surprised. Despite the 15th best comp sci program in th…

I haven't looked at all the data released, but for the sample I did look I didn't see a breach of a university's central records system - they were breaches of things like the university's diving club's phpbb forum.

Fairly mundane as these things go.

Re: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

#10

So, I'm at the University of Maryland right now. All three mirrors seem to be down, so I couldn't check if my information was on the list. The article suggests this was done with SQL injection? God, I really hope my university is better than that. Or at least hashes passwords. I'd check if they did, but again, mirrors seem to be down. Sad thing is, I wouldn't be surprised. Despite the 15th best comp sci program in th…

There was at least one university where hashed passwords were leaked. I believe it was michigan, though not sure anymore.
Post reply on HN