8 ms·
Hamed Helped. Help Hamed.
- benatkin 14y agoWow. This is much worse than I thought. I'm glad there's no conceivable scenario in which this could lead him to be extradited to the USA, like Marc Emery was. http://en.wikipedia.org/wiki/Marc_Emery http://en.wikipedia.org/wiki/Marc_Emery
- JohnHaugeland 14y agoStop trolling, please. Marc Emery sold illegal goods internationally. The two situations have nothing to do with one another.
- unreal37 14y agoWhat's the truth here? What did Hamed "do"? Exposing a security flaw doesn't get you expelled. He had to have taken it one or more steps too far. I'd like to see the facts.
- namank 14y agohttp://news.ycombinator.com/item?id=5090007 http://news.ycombinator.com/item?id=5090007
- thenicepostr 14y agoHere's his expulsion letter, stating why he was expelled according to the school. http://www.documentcloud.org/documents/560325-al-khabaz-expulsion-revised.html#document/p1 http://www.documentcloud.org/documents/560325-al-khabaz-expu...
- mrtron 14y agoTranslation: On Sept 21st our site was vulnerable to a simple SQL injection attack. On Sept 22nd you documented this information for us. On Oct 26th our site was STILL vulnerable to a simple SQL injection attack. On Oct 29th you again documented this information for us. On Nov 12th we expelled you for our discovering our abysmal security.
- anonymouz 14y agoI advice everyone to read the original expulsion letter. It is just one page, and the parent's post completely (and I must assume intentionally) twists the facts as mentioned in the letter to make the student look better. In particular the letter claims that the student has in fact attempted to exploit the SQL injection to gain unauthorized access, and that both notifications to the IT department were made after they detected him and blocked his account.
- noibl 14y agoActually the letter says nothing about detection and all other sources[1][2] about this matter agree that the 'detection' took the form of a voluntary disclosure, which was rewarded with an NDA demand under threat of arrest. So it seems you are the one twisting the facts for reasons unknown. --- [1] "Al-Khabaz immediately alerted the head of information technology for the school about the breach in the Omnivox software used by the college. At first he was thanked for the discovery." -- http://www.thestar.com/news/article/1318163--montreal-student-expelled-for-finding-security-breach-in-school-portal http://www.thestar.com/news/article/1318163--montreal-studen... [2] "they discovered that by exchanging other student numbers in the encrypted links, they could easily obtain information such as the social insurance numbers, home addresses and phone numbers of more than 250,000 students. Al-Khabaz said he informed the school’s head of information technology immediately after discovering the vulnerability in the school’s Omnivox software and was congratulated for the discovery." -- http://www.cbc.ca/m/rich/canada/story/2013/01/21/montreal-dawson-college-hack-hamed-al-khabaz.html http://www.cbc.ca/m/rich/canada/story/2013/01/21/montreal-da...
- anonymouz 14y agoRead point 2: "On September 21, the IT Policy was applied and your network and portal accesses were suspended." Read point 3: "On September 22, you admitted to these attacks in writing." Compare the dates. According to the letter, his disclosure came after the account was suspended. Implying that they did detect the attack before he admitted to it.
- thefreeman 14y agohttp://news.ycombinator.com/item?id=5090007 http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he didn't break the rules.
- AustinGibbons 14y agoI don't understand how using an external attack tool is grounds for anything. If Hamed could use it to search for exploits an attacker could have used it to search for exploits. Especially if a students' information had been previously exposed and the attacker had access to everyone's personal information / passwords! -- Edit : after reading his expulsion letter, it seems he supposedly injected SQL on both occasions. One imagines they strictly forbid him from doing so again. Sure, he probably should have asked for a sandbox system if he wanted to do ad hoc security research, but it is still quite a logical leap to actually expel him.
- pprd 14y agoEither ways, the solution should be to fix the security system and reward the whistleblower. In a few years, we are going to have millions of teenagers with the competence and ability to pull of what Hamed did. What then?
- loup-vaillant 14y agoObviously those youngsters are all criminals that ought to be put to jail. We shall implement a zero-tolerance policy, just like the copyright industry did. </sarcasm> Nevertheless, I'm afraid they might do just that.
- jrogers65 14y ago> but his explanation doesn't jive with his actions. I think it's perfectly congruent. An entity has your data as well as information on many other people. You come across and report a vunerability. You check that something was done about it. I see no holes in this (aside from the ones in Montreal college's security).
- JohnHaugeland 14y ago> Exposing a security flaw doesn't get you expelled. Unless you're at a minor Canadian trade school which wants to bury that they knew about the security flaw for months and did nothing about it. . > He had to have taken it one or more steps too far. First he told them about it. Then he waited a couple months, and tested to see if it was still there, with some free online security scanner; it was. So he reported it again, and this time contacted the vendor. The school freaked out, decided that he was hacking them without permission, and expelled him over "code of conduct." They absolutely refuse to explain, though they keep pretending that there was a law broken. The student went to the RCMP; the RCMP disagrees. So does the original vendor, who has challenged the school, and given the kid a scholarship. http://www.cbc.ca/homerun/2013/01/21/dawson/ http://www.cbc.ca/homerun/2013/01/21/dawson/ This is just a terrible administrator doing new damage trying to bury his own failure.
- loup-vaillant 14y agoDamage control is often about redirecting the damage.
- jiggy2011 14y agoMoral of the story: Sanitise your query params.
- JanezStupar 14y agoI think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.
- vertis 14y agoI think there can be reward in some cases. From what petition website says, he's received several job offers.
- JanezStupar 14y agoThis is a great comment for ShitHnSays.
- nowarninglabel 14y agoHaving nearly been fired from an university for responsible disclosure, I agree completely, there is substantial risk and no reward for public disclosure of any kind in university environments.
- JohnHaugeland 14y agoAt real universities, this doesn't happen. I've seen scholarships handed out over this. But you never hear about those, because nobody's angry. Hiding responsible disclosure just means you aren't responsible.
- JanezStupar 14y agoWell yes, it can be leveraged. But one needs to be careful about it. You can't just go talking about it or sending official letters to the administration or the IT department. Personally should I want to disclose something like this I would first approach a maverick amongst faculty staff to test the waters. After consultation with a person with good knowledge of the local political landscape I would discretely relay my knowledge. But it is still risky and leaving no evidence is still a safe bet.
- mappum 14y agoWhile Hamed was honorable and didn't try to abuse his exploits, I think it is a stretch to say "Hamed helped". I doubt he tried to get into the data for the purpose of helping make it more secure, it is more likely that he just had the "hacker drive", where he just wanted the challenge of beating a system.
- arcatek 14y agoIf I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators. His troubles began when he checked later if the security hole was still opened.
- mappum 14y agoAh, so that means he wasn't even really "hacking". But I still think it is weird that the site calls it him "helping".
- rurounijones 14y agoBasically he did something he shouldn't have/ He Scanned them again after reporting the bug to "see if they had fixed it" (per his claims). It seems like he had no malicious intent (At least I believe him) but his school and the vendor basically went nuclear on him.
- anonymouz 14y agoAccording to the expulsion letter (linked somewhere in his thread) he only reported the issue after he was detected and his access was blocked. That doesn't prove either sides version but shows why one should get authorization before attempting such a thing. After getting caught anyone can say that they were just trying to help.
- noibl 14y agoThe letter says no such thing. I don't know why you've taken the trouble to post this falsehood twice in a short thread. http://news.ycombinator.com/item?id=5096170 http://news.ycombinator.com/item?id=5096170
- eranation 14y agoI've read the claims from both sides, I think that although he might have handled it more carefully, it was an overreach to expel him this way, I feel we should stand behind him. I signed the petition. Anyone with counter evidence, please step forward.
- JohnHaugeland 14y agoWhere did you find claims on the school's part? The only one I've found so far is an audio interview with Mr. Filion; everything else has had the school refusing to comment. Please provide links.
- anaheim 14y agoLook, this is fairly simple. The names of the top people at Dawson 'College'? Richard Filion, Director General, Dawson College Robert Kavanagh, Academic Dean, Dawson College Diane Gauvin, Dean, Social Science & Business Technology, Dawson College Ken Fogel, Chairperson, Department of Computer Science, Dawson College François Paradis, Director of Information Services and Technology, Dawson College The name of the supposed 'perpetrator'? Hamed Al-Khabaz I'd bet an insane amount of money that if the guy had been named something like Stéfane Latrimou, he'd have gotten off far more lightly.
- ck2 14y agoIf anywhere should be more tolerant of intellectual curiosity, it should be in a college environment. Unless they can prove he had intent to cause damage, which it sounds like they could not do, they should just forgive and forget and stop trying to cover the overpaid butts of the sysadmin who didn't fix the hole in the first place. Hell society forgave all the banks and wallstreet for their actual crimes.
- nowarninglabel 14y agoI have to wonder how much this will help. A colleague and I made a responsible exposure to a vendor that provides the application software for the California State University system. The vulnerability I chanced upon, and that my colleague was able to verify to be fully open, made it possible to obtain the private details of hundreds of thousands of applicants from their system. How were we rewarded for quietly and responsibly disclosing this to the vendor? The vendor threatened a lawsuit against the university, and the university cowtailed and nearly fired my colleague, severely reprimanding him and myself. Little did I know this would become a theme of my stint in working for academia, of the universities not caring at all about students and their private data. I worked for multiple universities and it was the same at each one. They seemed to think the problem was with people not with buggy, overpriced, insecure software.
- JohnHaugeland 14y agoThey got so embarrassed that they challenged the school to change its mind, and offered the kid a full scholarship to wherever he goes next. http://www.cbc.ca/news/canada/montreal/story/2013/01/21/montreal-dawson-college-hack-hamed-al-khabaz.html http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont... In the meantime, their student body is furious that the staff have been knowingly leaving their private information public for months. So I'd say "a lot."
- nowarninglabel 14y agoWell, kind of. I read this was successful in targeting the company to react positively towards Hamed, however, the university is still throwing the book at him. I guess that's a better tactic, going publicly after the company, rather than through university management.
- jasim 14y agoThis goes on to show how out of touch with reality our educational systems currently are. They are incentivized by the wrong things, which reflects in the kind of people and policies that are put in place. Before the web and the free dissemination of information it brought about, the average academician was more 'smarter' than the average student just by the fact that the students hadn't yet had access to the sources of information their teachers had. However, we now live in times when you can expect anybody in the society to grow to their full potential, thanks to the free web. This changes the fundamental role educational institutions has to play. They can't continue to be passive devices of information transmission. Yes, there are an elite bunch of institutions that provide more value than that. But as these events show, the educational sector around the world in general are mediocre and are pretty inefficient. You now have smarter students and they don't need you to tell them what the world is about. That is the changed reality of the market and it is going to affect this sector for the better in the long run.
- JohnHaugeland 14y agoNo, universities internationally are furious and disgusted. This is a trade school, not a college. It's like being angry at DeVry or University of Phoenix. The stupid things that places like that do have nothing to do with real universities.
- JohnHaugeland 14y agoThis wasn't the first time Ahmed (not hamed, ahmed) reported the problem. When they ignored it, left the software running, and notified none of the students, he used some free white-hat web security scanner to generate a report to make it more clear for the business people what was wrong. The business people have decided that the security scanner is "a hacking tool" and that Ahmed needed permission from the school to see if the software that was imposed on him which was leaving his private data exposed after the staff knew was still broken. The way Richard Filion, who runs the school, tries to make excuses around this is appalling. http://www.cbc.ca/homerun/2013/01/21/dawson/ http://www.cbc.ca/homerun/2013/01/21/dawson/ The software vendor gave the poor kid a scholarship and asked the school to change its mind. http://www.cbc.ca/news/canada/montreal/story/2013/01/21/montreal-dawson-college-hack-hamed-al-khabaz.html http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont... The RCMP declined to be involved. The running excuse they're giving is "it was against our code of conduct." And, I mean, most schools don't even kick binge drinkers who got in an accident and nearly killed people out for code of conduct. So clearly this isn't an excuse. The people responsible for the decision are the head of the Computer Science department, Ken Fogel, and Dianne Gauvin, one of the deans. Predictably, they do not respond when contacted. This is a computer science department where a panel of 14 out of 15 "professors" actually chose to stand behind this - though nobody will release their reasoning or names. So don't expect Ken Fogel to get it on grounds that you imagine he's one of us. The school ombudsman, whose job it is to stand up for Ahmed, has been whitewashing its Facebook page of all criticism. The main school Facebook page is just ignoring the criticism instead; they post inbetween literally hundreds of people (including students and alums) to chat with people on posts from before this started getting public. And, a reminder? They did this in November. They've been sitting on this for months. They aren't going to change their minds without a very good reason. Not shockingly, other students have been posting reams of existing security holes on their various servers, and evidence of compromises that are claimed to be years old. Staff is doing just as nothing about those as they did about this the first time Ahmed reported it.