Slashdot Mirror


Blackboard Campus IDs: Security Thru Cease & Desist

On Saturday night, Virgil and Acidus, two young security researchers, were scheduled to give a talk at Interz0ne II on security flaws they'd found in a popular ID card system for universities. It's run by Blackboard, formerly by AT&T, and you may know it as OneCard, CampusWide, or BuzzCard. On Saturday, instead of the talk, attendees got to hear an Interz0ne official read the Cease and Desist letter sent by corporate lawyers. The DMCA, among other federal laws including the Economic Espionage Act, were given as the reasons for shutting down the talk (but -- update -- see the P.P.S below). I spoke with Virgil this morning.

Virgil was there two years ago when Dmitri Sklyarov was arrested and led away in handcuffs at Def Con 9. He's not in handcuffs now, but in speaking to me, he had to stop and think about everything he said, and every third answer was "I really shouldn't talk about that."

The DMCA is largely to thank for that. Section 1201 states that no one "shall circumvent a technological measure that effectively controls access to a work," and that no one "shall... offer to the public... any technology" to do so. Blackboard Inc., whose card system is called the Blackboard Transaction System and known to end users under various names, uses a network of card readers and a central server, and they communicate over RS-485 and Internet Protocol -- using, or so they apparently claim, measures that effectively control access.

For the record, none of what I learned about the Blackboard technology was from him or Acidus after the restraining order was sent. I spoke to other people, who have not been served with a restraining order. Google has a less enlightening mirror of the slide titles from this weekend's PowerPoint presentation and a more enlightening mirror of Acidus's "CampusWide FAQ" from last July. And, most enlightening of all, this mirror has an updated version with details on what they figured out how to do and what their talk was going to be about (click "CampusWide" for the text description, the PowerPoint slides, and Acidus's timeline of the last year).

At many schools, Blackboard's system is the ID: you swipe your card for your meal plan at the cafeteria, to get into your dorm, maybe even to get your final exam.

A swipe at a vending machine will get you a soda -- a money transaction from your campus debit account. When you use a swipe to do laundry and make copies, money has to be involved. Blackboard even notes that they can set up a merchant network on- and off-campus: "a cashless, safe, and secure way to transact on and around campus while offering parents the assurance that their funds will be spent within a university-approved network." (Emphasis added. Maybe readers who go to schools that use such a system can expand on how that system is used.)

The kicker, of course, is that this network is not very secure, or at least Blackboard doesn't think it's as secure as... well, as lawyers. One anonymous Slashdot submitter wrote that: "The authentication system is so weak that [Virgil and Acidus] have been able to create a drop in replacement for the CampusWide network debit card readers used on coke machines on campus."

Virgil couldn't provide me any details about what he had learned about the system. Based on the mirrors, it looks like a man-in-the-middle replay attack -- which is a pretty simple attack, repeating messages sniffed over the RS-485 protocol, or even over IP -- can have effects like convincing a Coke machine to dispense free product. Or, it's claimed, the attacker can create a temporary card, with no name attached, and free money in its account. Hmmmmm.

Or, more ominously, someone else's identification might be sniffed, and then replayed from a security terminal. If a thief gained entrance to a building by sending the message "open the door, my name is John Doe," the real John Doe might be sorely inconvenienced the next morning.

So, if you're a student at a school that uses Blackboard, do you feel more secure now that the DMCA has tried to stop you from learning about its security flaws?

If you're a parent putting money into a Blackboard-based debit account, do you feel more confident of its safety now that this information is ostensibly hidden?

This card system has been installed on many campuses and its roots go back almost twenty years. My guess is that replacing the card-reading hardware would be necessary to improve the security of these devices. Obviously, Blackboard would be hard-pressed to replace thousands of hardware devices at all its locations, even if they'd started in late 2001 when Acidus claims he called to tell them of the flaws he'd found (and "was blown off").

So, assuming that's not possible -- is the DMCA a viable tool to ensure security?

P.S. Virgil tells me that he has a good lawyer. They are scheduled to argue on Thursday that the restraining order not be made permanent. Slashdot will keep you apprised of what happens in our Slashback stories... stay tuned.

P.P.S. Update: 04/15 02:30 GMT by J : Now online are the restraining order, which just lists the six things that Acidus and Virgil are not to do, and the more detailed Complaint. Now that these are available, as Declan McCullagh points out, it turns out the DMCA was only in the lawyers' threatening letter and not considered as part of the Complaint itself. I'm not sure why it would be included in the letter -- some of the language of the Georgia Computer Systems Protection Act is similar, and who knows, Section 1201 might be mentioned later on, as this case progresses. Maybe the lawyers are just keeping their options open. Meanwhile, I love this part of the Complaint:

"Mr. Hoffman openly acknowledges on his website that 'I am a hacker.' His website then defends the process of hacking. See Exhibit B."

28 of 653 comments (clear)

  1. Remember, Citizens by RLiegh · · Score: 5, Funny

    This in NO WAY implies we live in a police state.

  2. Duh... by c0dedude · · Score: 5, Insightful

    Well, if you aren't even able to TALK about security flaws *Cough*First Amendment*Cough* they'll never get fixed. The DMCA again makes the net less secure instead of more.

    --
    Since when has this country used intellectual elite as a pejorative term?
    1. Re:Duh... by BattleTroll · · Score: 5, Insightful

      Ummm, no. If Neo-nazis can parade down the street, hate-mongers can publish their diatribes, crosses can be burnt, and flags defecated on then by God the first amendment should protect academic discussion on security holes and their implications. Teaching someone how to pick a lock is not the same as breaking into Ft. Knox.

  3. Re:I say publish all the details overseas by Jeffrey+Baker · · Score: 5, Insightful

    It is trivial to leak this kind of information. Walk into an internet cafe (or walk by any of millions of open 802.11b network) and upload the information to USENET. Problem solved.

  4. Re:I say publish all the details overseas by Marx_Mrvelous · · Score: 5, Insightful

    Now of course, I wouldn't have had this reaction if the company had taken steps working with the discoverers of the security flaw. If anything, they should hire/pay these researchers for their work, fix the problem, implement it, and then publish what went wrong. And who knows, maybe they even tried. I doubt it though, when a cease-and-desist can have the same effect.

    --

    Moderation: Put your hand inside the puppet head!
  5. I know a little about this... by Probius · · Score: 5, Interesting

    Our school uses blackboard, and last year the machines were shut down for a long time because students used methods to get free stuff out of the snack machines. And I'm not talking cracking a case or making a fake card either. It was really simple too, like swiping really fast after the transaction, if I remember right, and you could get a second item for free. Kinda scary.

    1. Re:I know a little about this... by JahToasted · · Score: 5, Informative

      The sentence "swiping really fast after the transaction" is a violation of the DMCA. Seriously.

  6. obviously not by ih8apple · · Score: 5, Informative

    To answer the question "is the DMCA a viable tool to ensure security?"

    Here's an article from the BBC.

    and here's a good presentation from toorcon.

    and lastly, this is a good article from ITWorld.

  7. Re:I say publish all the details overseas by Anonymous Coward · · Score: 5, Funny

    I wish there were a way to accidentally leak the exacty details overseas. There, it would be very difficult to get shut down, and every college using this system would have to deal with it. While this may be an inconvenience to students, they can get by without buying coke with a swipe of a card for a while.

    Yeah, I wish we had some sort of global communication network where you could instantly and anonymously post a piece of information, and people anywhere in the world could see it. Wouldn't that totally rock?

  8. Re:*cough* Clueless *cough* by intermodal · · Score: 5, Insightful

    actually, it does. Thats the point of a free press. An informed public is necessary to maintain ones freedoms, but i guess we already missed the "informed public" boat too early to avoid draconian laws like the DMCA anyhow.

    --
    In SOVIET RUSSIA... erm...NSA AMERICA, the Internet logs onto YOU!
  9. it's over by HBI · · Score: 5, Interesting

    Time to stop being a geek. I'm getting my pencils and paper back out, doing RPGs that way, and selling off my 7 or 8 computers.

    I can see the writing on the wall just as easily as anyone else. The joy that I got out of these marvelous toys just isn't worth it anymore. It used to be liberating, now it's just torturous. I can think of dozens of ways to get thrown in prison just by playing around with my system at night after work. Tinkering and exploring are forbidden. I'd rather be an insurance guy or something similarly boring then spending part of my life in a 4x6 cell, or even living in fear of same.

    Just proof once again that anytime government gets involved with anything, it sucks all the fun out of it. All in the name of equity and greater corporate profits.

    --
    HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
  10. Is this the most correct channel? by sabinm · · Score: 5, Interesting

    Surely Acidus and his colleagues informed the Universities about this before they went public with this information. That is of course the most effective way to get the system to change. . . Imagine inviting the Dean of Purchasing and Procurement to a Coke and a Apple pie on campus and using a facsimile of his id and account to pay for it. Or even more fun - - getting a sweet new laptop at the bookstore with a hyper-inflated account balance. Most certainly then Blackboard would think about upgrading their machines. Announcing that you are going to circumvent their digitally encrypted system in public, no less, simply gave Blackboard a way to facilitate their illegitimate hardware and polices and making it legitimate under the cover of an unjust law.

    As my good old Uncle Scrooge always said: Work Smarrrrrterrrr not harrrrrderrrrr

    --
    http://cincyboys.blogspot.com/ Everything Cincinnati. Including the word 'Finnih'
  11. Stupid. Typical. by jasenj1 · · Score: 5, Insightful

    If guns are outlawed, only outlaws will have guns.

    If hacking is outlawed (and talking about it), only outlaws will know how to hack.

    So who do you get to sue if someone makes a dupe of your ID card and raids your campus debit account, or breaks into your dorm room? The school? The hacker? The company that sold the school the lame ID system they claim is secure but is not?

    I would think the schools would like to know why sodas, meals, etc. are disappearing from their supplies. Hmmm.... This Coke machine is empty, but only 5 Cokes were recorded to be bought from it. Hmmm...

    This is the worst kind of security through obscurity.

    - Jasen.

  12. Re:Another way to go about this? by Anonymous Coward · · Score: 5, Informative

    This is a snippet from Acidus' old website. It relates the timeline of events. I hope you enjoy.

    Sorry for posting AC but since this does come from Acidus' website ....

    Spring 2001 - I got interested in the Buzzcard network on Campus. Based on the AT&T logo, I went to the Internet and soon found out about the system. Lots of Web research done, and fieldwork on the connection between the device and the reader. Locked Cabinet with Multiplexes was opened and photo was taken of insides. Determined which wires to cross to make doors open, laundry machines get credited, etc.

    Summer 2001 - Continued exploring the system, called the company (now Blackboard), and interviewed Jim Resing.

    Fall 2001 - With Publishing of my Fortres article, increased last minute field research, and finalized my notes. Called Blackboard again to tell them all the flaws I found, was blown off.

    Spring 2002 - Wrote Article, and was published in Spring 2002 issue of 2600.

    6/2002 - Blackboard learned of my article. The Blackboard Usergroup tried to track me down; finally figuring out I went to Tech, saw my web page and was very upset. Concerns about how accurate my article was are posted by schools around the country to the list-serve. GT tells the list-serve that they are looking into it and they would reply again soon.

    GT Police asks to speak to me to determine if crime was committed. GT Police never file charges and indeed I am told there is no long an investigation. Buzzcard Office conducts internal audit of their systems. I go to Buzzcard office unsolicited to try and assist them in securing their system. They were not happy to see me. Office of Information Technology (OIT) on campus starts a test of the Buzzcard system to see if any of the attacks described in article are valid.

    Buzzcard office asks that I remove picture of inside of the locked cabinet from my web page (since its hosted on GT machines), which I did. Buzzcard center asks me to remove AT&T cached pages, which I refuse to do. (Its not theirs, if AT&T wants it down, they can ask me).

    Buzzcard office reluctant to talk with my about my article, since they don't want to confirm or deny how accurate I was. They do confirm the VTS could be hacked and money can be added to any accounts as I describe. However parts of my article (namely how to clone a card through the VTS), are, they claim incorrect. They ask if I would write a letter for the list-serve that explains what parts were incorrect. I agree as long as my letter will be unedited, and I get to also stress what parts are accurate to let colleges learn what they need to secure. Buzzcard office agrees but continues to cancel my meetings with them and not return phone calls. I am contacted by several colleges that are on the list-serve. They tell me that Tech has all along been posting that they have interviewed me, that my article is totally false. Tech uses such loaded statements as "As any experienced administrator should know, these security holes are not possible." These colleges are concerned Tech is not being truthful, and want to talk to me. I see that the Buzzcard center was stringing me along, and cease my attempts to contact them, or help them fix their pathetic security.

    OIT concludes their investigation, and confirm that everything in my article is correct, except about how to clone a card. Tech does not post these results to the list-serv.

    Dean of Students is involved, and is checking to see if, while no laws were broken, if I broke institute policy.

  13. Re:I say publish all the details overseas by gl4ss · · Score: 5, Insightful

    chances are that they knew _exactly_ how bad the system was, and maybe just hadn't care when they first made the system, maybe thinking that it would be such niche system or so it wouldn't need to be secure, or maybe it was some other system adapted to use where security would have paid off..

    --
    world was created 5 seconds before this post as it is.
  14. my experience with it... by JimBobJoe · · Score: 5, Interesting

    After I left the Ohio State dorms in 1998 (I'm still a student) the university started to put card readers on the dorm entrances (up to that time either you had a key that opened both your dorm room and the main entrance, or you had two separate keys if you lived in a really big dorm.)

    It does offer some advantages, for instance, all people could be allowed into the dorms at some parts of the day, but other times of the day only people who live in that dorm could gain entry.

    Though there are some interesting caveats

    *the first one, which I didn't really know well at the time, is the fact that making a copy of the card is far easier than making a copy of the key. Remagnetizing magnetic stripes is not the hardest thing in the world.

    *the campuswide system runs off of ethernet to the AT&T9000 computer which administers everything. If a particular door gets disconnected with the central computer, it's default setting is to pretend like everything is normal, and let everyone in, and it has a cache of swipes which it would then transmit back to the central computer when the connection was restored. That seems like a sensible kludge given the circumstances, given a network failure it would be more sensible to allow all in as opposed to all out, especially at a dorm. (Higher security places would have their door failure mode set to allow no one.) On the other hand, as a security concept, it just bugged me. (this is explained in the powerpoint presentations.)

    *my big concern at the time was the tracking and auditing abilities, and it still is. the key system had no tracking and auditing. The swipe system allowed the university to keep a record of when students come into the building (and implicitly, when they go.) I pointed out that Ohio law prohibited a government institution from collecting information which were not authorized by law, nor required to achieve a particular purpose...and that the system need not perform the tracking, it only needed to perform the authorization.

    The response I got was that the system was not designed with a zero tracking/auditing setting, it needed to perform tracking and auditing as part of its authentication mechanism. I pointed out that I can't help that the university bought a dumbass product, and I threatened to sue them, but I was young, and I threatened to sue everyone. :-)

    I got a letter from the university lawyers saying "While we ourselves certainly hope never to need the archived data -- and, fortunately, rarely do -- it can be of unquestionable value in
    investigating incidents in the residence halls. It is for this very reason that similar systems are in use at numerous colleges and universities
    around the country."

    I've however pointed out that any idiot who was gonna do something in the dorms would do what everyone else does, and that is follow someone who swiped before you, and not swipe themselves.

    I still hope to work on this issue at some point. :-)

  15. Re:No, it doesn't. by nehumanuscrede · · Score: 5, Insightful

    Think of America as the 'politically correct' police state. While the jackbooted-gestapo isn't kicking the door down and beating you. . . (yet) . . . they are instead getting law degrees, dressing in nice suits and suing you. It's much more profitable. It ultimately achieves the same goal. You tend to keep your opinions / comments to yourself.

  16. Re:I say publish all the details overseas by archeopterix · · Score: 5, Interesting
    Now of course, I wouldn't have had this reaction if the company had taken steps working with the discoverers of the security flaw. If anything, they should hire/pay these researchers for their work, fix the problem, implement it, and then publish what went wrong. And who knows, maybe they even tried. I doubt it though, when a cease-and-desist can have the same effect.
    Sadly, the reaction of Blackboard is a big hint to the future discoverers of security flaws: don't even try to contact the company - wear gloves, attach a fake beard, go to an internet cafe, publish your exploits on Freenet, Usenet, foreign haxx0r sites and whatever else comes to your mind, grin evilly (this part is optional).
  17. Re:I say publish all the details overseas by skillet-thief · · Score: 5, Interesting
    The same kind of thing happened in France. (Maybe it was on /., it was a few years ago...)

    A guy figured out how to manipulate the chip on the smart cards used for credit cards. He contacted whatever company makes the cards to try to get them to hire him. They didn't believe him, so to prove his point he bought about $7.00 worth of metro tickets from an automatic distributor.

    And then what?

    They busted his ass big time. I think it totally destroyed the guy's career, life, etc. Then the company upgraded their encryption...

    --

    Congratulations! Now we are the Evil Empire

  18. Patent your exploits by scrotch · · Score: 5, Funny

    The only sane thing to do is to patent your exploits before you announce them. :)

    Then you have precedence for publishing them, or you just point to the online patent info.

    As a bonus, you can sue the companies that fix the holes you're supporting because they've broken that "shall circumvent a technological measure that effectively controls access to a work" line. After all, your exploit controls access, right? Opening a door is controlling access as much as locking it is.

  19. Re:What a strange filename by Acidic_Diarrhea · · Score: 5, Interesting
    Purely for marketing purposes chief. If the suits realize the kids are ripping off the system, the system will get fixed really quickly. On the other hand, how many college kids are going to download security_analysis_of_collegecard_system.pdf? Come on now, it's MARKETING.

    --
    I hate liberals. If you are a liberal, do not reply.
  20. Re:*cough* Clueless *cough* by masq · · Score: 5, Insightful

    So which one of your examples is this? He's not yelling fire in a crowded theater... He originally tried to tell the company their theater was on fire, and when they refused to give a damn, he decided to tell the people inside the theater about the fire.

    That's when they Cease and Desisted him, and told him that the burning theater was their little secret.

    Personally, I'd wanna know, but hey, I'm obviously not normal. Stay asleep if you want, everybody. It's still a free country - but you better check back with me tomorrow just in case.

    ----
    www.whatreallyhappened.com is interesting.

  21. Re:I say publish all the details overseas by Anonymous Coward · · Score: 5, Funny

    Ah, I've often shouted "POST IT ON USENET!" at the television screen whenever there's a movie or x-files/whatever episode where the hero is running away with the evidence/HotInfo trying to keep it from the Evil Conspirators.

    They almost never do.

  22. free printing by strider3700 · · Score: 5, Interesting

    We had the Onecard system at my school. Best hack we found was with the printing system. Insert a card with $30 on it in the machine toy print for $0.10 say this is my print job, wait for it to read amount on card. take out the card and put in a card with $0 on it. hit yes to print. $29.90 will be wrote to the card. Everyone I knew had $100 on the card in no time once we "borrowed" a profs card. We also got to print at half price by taking a copy of his card.

    People also spent time sniffing the one card network, but as far as I know no one had found anything interesting yet. this was 4 years ago, so I'd assume the entire thing is solved by now.

  23. Re:No, it doesn't. by Anonymous Coward · · Score: 5, Insightful

    Hello. Stupid. The corporation is using the law to prevent speech. The law is stopping someone from speaking. A prior restraint, stupid. This is the hallmark of a police state -- laws being used to silence the voice of individuals. Armed thugs will beat the shit out of him if he speaks -- they will attempt to kidnap him, imprison him, and extort money from him for this sin in the guise of arrest, detention, and fines by the police and court system. You have no idea what you are talking about, AC.

  24. Re:I say publish all the details overseas by Kilbasar · · Score: 5, Insightful

    The problem is that uploading the information to usenet is exactly what's going to happen. Corporate-types don't read usenet, but hacker-types do. What does that lead to? Some bored kid stealing all of my money, and only THEN is there a reaction from the company. I attend Cornell University, and I have to say, Blackboard is EVERYWHERE. We call it CornellCard. It controls all of the vending machines and meal plans. At least one door on each academic building and all the doors on the newer dorms are controlled by it. Not only can it be used to charge money out of our debit account (called Big Red Bucks), but it can be used to charge however much you want to your parents' bursar bill. The card isn't the only product Blackboard provides to schools. They also sell Cornell a web service called MyBlackboard. It allows teachers to set up websites for their classes. In addition to trivial stuff like assignments and lecture notes, the teachers use this interface to post test scores. Imagine all the havoc that could be brought upon this huge system simply because some exec decided it was more "cost-effective" to send out the attack lawyers than to fix their shoddy product.

  25. Re:I say publish all the details overseas by jonadab · · Score: 5, Insightful

    Indeed. If they'd just thrown the information onto usenet in the
    first place, no lawyer action would have had any effect at all.
    The problem is, people[1] who find security flaws don't generally
    *want* to post them to usenet: they want to work with the vendor
    and the security community to get the problems _fixed_.

    So here's the question: will these sorts of responses from vendors
    force the security community into just giving up on all pretenses
    of working with the vendor and just leaking everything to the
    general public immediately upon discovery? That would be bad for
    all concerned, but it might be better than being lawyered to death.
    It's pretty easy to arrange to get something posted to usenet
    with a reasonable degree of anonymity, and there's absolutely no
    way to suppress anything that has been posted to a big-8 or alt
    group, short of destroying the whole planet. But I don't think
    I trust the security of a product whose vendor is sufficiently
    uncooperative as to motivate a discoverer[1] of a vulnerability
    to do things that way.

    Maybe people who discover such vulnerabilities should discreetly
    communicate everything they know to some third party overseas
    first before doing anything else...? But you still have the
    problem that if you try to work with the vendor they know who
    you are and can laywer you, and you can be held responsible for
    communicating the information to the third party.

    Ah... but what if the original discoverer remained anonymous
    and communicated to someone _else_ who would try to work with
    the vendor, and if that failed the original discoverer or some
    third party he communicates with could release the information
    to the security community (and, in the process, the general
    public)? This would be harder for the discoverer, who would
    have to anonymously contact a trusted third party in the first
    place whom he would have to trust to make a good-faith attempt
    to work with the vendor. But if the vendor tried to laywer
    the non-anonymous person, they'd run into "I just found out
    from this here anonymous email and was trying to work with
    you; this leak must have been perpetrated by the evil person
    who circumvented your effective measure in the first place,
    probably the same dude who sent this email, which seems to
    have come to me from an evil open relay in southeast Asia,
    one of the same ones the spammers use to send me special
    offers for reduced-price copies of your products, which they're
    probably pirating. Gosh, you should really go after those
    open relays, they're all kinds of trouble."

    [1] Security people, I mean. I'm not talking about blackhats.

    --
    Cut that out, or I will ship you to Norilsk in a box.
  26. you don't know police states by g4dget · · Score: 5, Insightful
    If we lived in a police state, armed thugs would not tell you, [...]They'd just beat the living crap out of you and then go home,

    Maybe that's how police states work in your native, ignorant, Hollywood view of the world. In real life, police states don't usually bother with beating people up--it's way too much effort--and it's not necessary. They control people through implicit and subtle threats to their liberty, livelihood, and privileges, as well as similar threats to their families. They only resort to force when people absolutely don't comply--but so does law enforcement everywhere.

    You don't agree with the party line? Sorry, you or your kids can't go to college. You don't return from your trip abroad? Well, to compensate the state for your misdeeds, your home will be confiscated; too bad about your family. In some areas of US law enforcement, it's getting frighteningly close to that (drug seizures, computer seizures, etc.).

    Police states aren't anarchies. They operate orderly and according to laws, they just happen to be laws that limit freedoms excessively. And it's very easy to move from the rule of law in a free society to the rule of law in a police state.