Slashdot Mirror


Security and School - How Should One Speak Up?

AJ asks: "Well, in the midst of writing 1 of my 3 papers tonight, I realized how insecure my school's network is. It all started because I was upset about them changing from using my SSN to a proprietary number scheme for identifying students. I didn't think that was a bad thing, but I was wondering if they really were securing things. So, I needed a password to access a school resource from the internet. After a little of dabbling around, I found the place where I needed to enter my propriety school ID and password. As it turns out, the login form uses HTTP instead of HTTPS! Also, my school runs a wide-open wireless network that I always had considered a convenience, but now I am changing my passwords over that network! Oh, and that proprietary ID along with a password, lead right to a student summary page where my DOB, age, address and SSN are located. So Slashdot, what is a concerned student to do?" "I have made suggestions before with little results. Should I send an e-mail with an ultimatum. What should my after-ultimatum actions be. I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school. I wouldn't be so concerned, but this wireless problem, combined with a poor web design, has me freaked out. Has anyone dealt with this before?"

137 comments

  1. Job opportunity? by eviljolly · · Score: 5, Interesting

    Maybe you should take a different approach to this situation. You say that the school has security problems, and you seem to be knowledgeable in the matter, so why not explain the problem and ask them if they would be willing to pay you to fix it? If all else they might nag their developers to work a little harder after hearing about it. :)

    1. Re:Job opportunity? by c · · Score: 4, Insightful

      so why not explain the problem and ask them if they would be willing to pay you to fix it?

      Because a lot of institutions will take the offer and twist it so it looks like a blackmail attempt, then involve law enforcement. I've seen way too many headlines reading something like "well meaning security person gets ass-fucked because they offered to help intitution fix security problems in return for money".

      The last thing you want to do is make it look like you're after money.

      c.

      --
      Log in or piss off.
    2. Re:Job opportunity? by torpor · · Score: 5, Informative

      well meaning security person gets ass-fucked because they offered to help intitution fix security problems in return for money"

      Too often the 'well meaning' part of these stories is hype. More often than not, it was a selfish, arrogant little brat-kid type who was trying to 'rule supreme over the stooopid school admins' and got upset when nobody listened to their tantrum and rants.

      Some guidelines for the current situation:

      - Put everything in writing, proof-read it first, then again, and spell check. Produce a professional report, not a whiny rant about why things suck.

      - Send a copy of this report to your schools administrators, registered mail. Hand-deliver a copy to the school administrator, if you can, but always, always, always put everything in writing first. Always. ALWAYS.

      - Be thorough and complete, and make sure you explain why you are being so thorough.

      - Provide examples WHEN ASKED and not before-hand. If you attach a page full of passwords you've sniffed out of the ether, this gives you a definite disadvantage if they decide to put your head on a pike. Remember, as a student, you are just one of many in the eyes of the administrator. It may well be that the problems they try to solve involve decapitating you.

      - Be courteous about this problem. It is not one single persons problem, but is in fact a group problem. Singling out one person for all the problems and mistakes of the group will do nothing but serve to make you enemies, so don't do it.

      - Follow up. If there is a change as a result of your investigation, follow up and ensure it is fixed. Work as closely with the people who are responsible for this problem as you can...

      Always, always, always try to remember, that a whiny rant about things sucking is not going to work as well as a detailed, professional, spell-checked report. If your report about the network problems doesn't look like homework, and doesn't shoot for an "A", then its going to get you into more trouble than you expect ...

      --
      ; -- the corruption of government starts with its secrets. a truly free people keep no secrets. --
    3. Re:Job opportunity? by Glonoinha · · Score: 1

      http://boston.internet.com/news/article.php/211044 1

      Somewhere between 'hacking the data' and 'posting it on the web page' or doing whatever he was going to do with it (expose a massive security flaw, perhaps?) a college kid at UT got caught doing exactly this. He hadn't even done anything with them yet except possess the information.

      Best quote of that article : "If convicted, he could face a maximum term of eight years in a federal prison and up to $500,000 in fines."

      --
      Glonoinha the MebiByte Slayer
    4. Re:Job opportunity? by Anonymous Coward · · Score: 0

      Don't be stupid.
      Any attempt you make to correct this directly yourself will result in punishment.
      Go to an anonymous AP and post the info on Usenet.
      After they are brought to their knees and made an example of, others will have more reason to behave.

  2. Bad idea! by 42forty-two42 · · Score: 4, Interesting
    "I have made suggestions before with little results. Should I send an e-mail with an ultimatum. What should my after-ultimatum actions be. I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school."
    If you're going to blackmail your school (and threaten to break various computer crimes laws), don't post about it on a high-traffic site beforehand! Better would be to talk directly to the network admin and offer to show them a live password-capture session.
    1. Re:Bad idea! by Anonymous Coward · · Score: 0

      Yeah...there are some people on Slashdot, but this guy is one of the dumbest I've seen yet.

    2. Re:Bad idea! by yotaku · · Score: 4, Informative

      I'm not so sure about this. Although I guess now that you've posted here you had better speak up. But if it was me, I'd have just kept my mouth closed. I know someone who reported a security flaw in my highschool's network and was promptly banned from using any school computers except under supervision and suspended from school for a week.

    3. Re:Bad idea! by 42forty-two42 · · Score: 4, Funny
      Yeah...there are some people on Slashdot, but this guy is one of the dumbest I've seen yet.
      You're new here, aren't you?
    4. Re:Bad idea! by Anonymous Coward · · Score: 0

      I know someone who reported a security flaw in my highschool's network and was promptly banned from using any school computers except under supervision and suspended from school for a week.

      Sounds like an argument for home schooling to me (as if the education one gets from a public school wasn't argument enough).

    5. Re:Bad idea! by skinfitz · · Score: 1

      Better would be to talk directly to the network admin and offer to show them a live password-capture session.

      Imagine if all along they have been running HTTP over IPSEC - boy would his face be red.

    6. Re:Bad idea! by schnipschnap · · Score: 1

      Sure, but home schooling is not allowed in every country, and 18,000 students seems to be a university, and no proper high-school, and you can't get a university's degree at home etc.

    7. Re:Bad idea! by bhtooefr · · Score: 1

      What? I can get a university degree from home for a very small fee! I just wonder why this e-mail is in my "Spam" folder...

  3. UM... by ewhenn · · Score: 4, Insightful

    I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school. I wouldn't be so concerned

    If this page really allow you to view all of the above info (SSN, etc.) AND you are upset it would violate your privacy, why are you willing to post a bunch of other peoples passwords online?? Wouldn't taht violate THEIR privacy. I mean if someone found a problem with my banks online checking that would let people exploit and get into my account, I would not appreciate someone posting my account number an pin online. In fact I would sue the poster of htat information if I could. Be careful where you tread.

    1. Re:UM... by Grab · · Score: 3, Insightful

      Dead right.

      By all means, sniff the passwords. But then put them in a document and circulate it to your department supervisors. Make sure the document says *exactly* what you did (every step of the process). It would be good if every step was within the IT policy you subscribed to (then they can't lynch you for that), although as a whistle-blower this may not be necessary. And NEVER use those passwords, otherwise you could be done for hacking into someone else's account.

      Don't even think about asking for money - as someone else said, this makes you look like a blackmailer. Initially you have to act simply as someone bringing in information. What they choose to do with the info is their decision - most likely someone in the IT department *does* have the skills to fix the problem, it's just that they got some incompetent trainee to do it instead. If it turns out that the IT department need your skills then you can negotiate a contract or you can do it for free, but NEVER state that to start with.

      Give out ONLY hard-copies - that way a Word document can't accidentally get put on the web or something dumb like that. This limits circulation - it's more effort to photocopy/scan than to forward an email, so there's less chance of the passwords going where they shouldn't.

      Finally, make sure a hard-copy goes to the school paper, with instructions to hold onto it for 2 weeks (or some arbitrary length of time), and have a good talk with the people running the paper before you tell the school authorities. Make sure when you raise the issue with the school authorities that you tell them you've given the info to the school paper, and tell them the time limit. That way, they know they need to fix things within 2 weeks before things go public. It also covers your ass by ensuring they can't lynch you as a scapegoat, bcos the paper will crucify them.

      Basically, examine every step you take and see how it could be used against you. Getting a couple of your friends to check through what you're doing would also be useful (and having a friend watching at crucial stages like sniffing the passwords gives you the extra backup of a witness).

      Grab.

    2. Re:UM... by Spoing · · Score: 3, Insightful
      1. By all means, sniff the passwords.

      Do *NOT* follow that advice.

      Follow this advice.

      If I have to say why, you're already treading on thin ice.

      When I've run system scans and dumps on systems I do not manage, I've asked first and shown the admins what I do exactly -- and that's in my professional capacity.

      As a student, make no doubts that you will not be treated well if they even think you are able to do this. The admins should get it, though others will not understand -- though if the admins did know WTF they were doing, they'd use HTTPS in the first place...right?

      Instead, I'd point out that you are concerned since HTTP is an unsecure method and that others are likely to abuse your account and you want to know if the school is willing to take responsibility when that happens.

      Scare them into action but do so from the point of view of someone who would not even look themselves.

      In the meantime, use https:// in the URL yourself -- it will probably work -- and suggest friends do the same if it does.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    3. Re:UM... by Glonoinha · · Score: 3, Insightful

      This sounds a lot like that college kid that decided to 'test' airport security a few months ago by sneaking a knife onto a commercial flight. Made it past security, got onto the plane, then announced his amazing feat of stealth and cunning to the crew. Ha Ha your security still sucks - I tested it and I am better than you - hey wait, it was only a test - hey who are these stormtrooper guys - ouch.

      Oddly neither the airport nor the government found his 'test' very enlighting. No, in fact I think he was facing several years in Federal Pound-Me-In-The-Ass Prison.

      Original poster : you are approaching this like a child in an adult world. It is obvious that you desire peer level attention and recognition for your 'accomplishments'. Trust me, as someone that was 'recognized' and 'acknowledged' by the university administration for 'hacking' his college computers (possibly before you were even born) ... recognition is highly overrated. That you even suggested collecting the list of passwords and placing them on a webpage at school shows incredible immaturity. Not because you said it, but because doing so is even a remotely viable consideration in your mind.

      You want to blow the whistle, then blow the whistle. If you see a serious breach of security and you feel the need to get it fixed, go to https://tips.fbi.gov and fill out that form, hit submit. I pretty much 100% guarantee that they will take you serious. You can call them at 202-324-3000 if you want.

      Understand, however, that once you invite the government into any aspect of your life or business it is impossible to put that genie back in the bottle. This goes with any cute little pranks you enumerated like sniffing passwords or listing them on a web page at school.

      There is a fine line between helper and terrorist in today's environment and you really don't want to screw away your lifetime potential because you were being 'gifted and talented' in college. Not only do you not want to cross the line, you don't even want to be under evaulation as to which side of the line you are at - all it takes is one bureaucrat to misinterpret anything you have said and you are royally fscked.

      If you are here because you are genuinely concerned about massive lapses in the security as implemented at your university then consider whether or not you are ready to be a martyr for that security - because once you blow the whistle you can pretty much kiss goodbye any chances at graduation from that college. But the needs of the many outweigh the needs of the few and we are ok with sacrificing you as a pawn in the name of the overall good.

      If you are here to impress us with your 1337 haxor skillz - what you did wasn't 1337, it was merely a rite of passage for every systems guy worth his salt. About like programming a bubble sort in visual basic - everybody is proud the first time they do it, but it really isn't that big a deal.

      You want to impress us, do something none of has done yet :
      Find Osama bin Laden, hell I think there is still a $25M reward for the information leading to his capture.
      Figure out a way to actually get the administration to fix their security. Do that and you will be our hero.
      Find a way to bring back the tech sector jobs that are being outsourced overseas. Do that and you will be our hero and we will rename Linux in your honor.

      --
      Glonoinha the MebiByte Slayer
    4. Re:UM... by NateTech · · Score: 0, Troll

      A bubble sort in VB is a rite of passage to become a sysadmin? Holy shit... I never knew!

      Someone better take my admin privs on my machines away now.

      The last guy I knew who knew how to program a bubble sort in VB also had zero idea how his e-mail got to his machine or his network file systems worked.

      I guess he won't be vying for the prized sysadmin position (ha! Riiiight...) anytime soon...

      Oh yeah, I think he knew one Cisco IOS command too -- "help".

      --
      +++OK ATH
  4. Show the problem to your school leaders... by joelparker · · Score: 4, Informative
    First, contact your school technical staff;
    they are the ones to fix this problem.

    Second, if the technical staff does not fix it,
    contact your school's Deans for intervention.

    Third, if the Deans do not get the problem solved,
    contact your school paper and ask for help.

    This all shows that you're a team player,
    in case you need to escalate it later.

    1. Re:Show the problem to your school leaders... by mar1boro · · Score: 5, Interesting

      Call me paranoid. In a perfect world this would be the ideal situation.
      If you are determined to get this fixed ( as you should be ), and you are
      on friendly terms with both your system admins and your school's administration
      then take the straight forward approach suggested by joelparker.

      If they do not know you, I would attempt to be a little more anonymous.
      If you point out laxaties in their security, you will be the first person
      they think of when there is a problem. The security admin will probably
      also get his ass chewed by his boss. The admin will remember you.

      If you are still determined, do one of two things;
      1. Compose anonymous snail mails. One to the school's admin, and
      if this is a state school - one to the state's security admin at the
      department of education.
      2. If you have money, or can find an activist lawyer willing to do this
      pro-bono - retain council and enter into a priveledged communication.
      Have the lawyer communicate with the admins.

      Just remember - no good deed ever goes unpunished.

      --
      -- "It was as if the paint factories had decided to deal direct with the art galleries." - Thursday Next
    2. Re:Show the problem to your school leaders... by Profane+MuthaFucka · · Score: 1

      Are you crazy? First, the school network is not his responsibility. Therefore he should not report anything at all.

      Second, someone at that university is responsible for that network. That person might have gotten his job through political means, rather than displaying competency. That's likely, given the nature of the security hole. Pointing out the mistakes of politicians from a point of weakness is not a smart thing. He might be technically right, but I doubt that a college student has the financial means to PROVE that he's right in a court of law.

      If we have learned anything here, it's that pointing out that some people in power are idiots is dangerous.

      If he's going to do anything at all, he should do it completely anonymously. Write a letter. When you're done, throw away the pencil, and the pad of paper. Or burn both of them. Seal the envelope with a wet sponge, not your DNA laden saliva. Wear gloves the whole time. Mail the letter from a busy post office box. Keep the addressed side of the envelope out of view of any security cameras. Use a plain letter sized envelope without any distinguishing marks. Paranoid? Sure, why not.

      In the meantime, he should find some other secure way to change his password. Perhaps by logging in from a hardwired subnet that is unlikely to have a dorm full of sniffers on it.

      --
      Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
    3. Re:Show the problem to your school leaders... by Danse · · Score: 1

      Gotta agree here. Anonymous is the way to go. While he certainly has every right, and perhaps even an obligation to complain about the problem since it's his personal info that is at risk here, it's all too common for the messenger to be stabbed, hung, shot, and dragged through the street in situations like this.

      --
      It's not enough to bash in heads, you've got to bash in minds. - Captain Hammer
    4. Re:Show the problem to your school leaders... by Anonymous Coward · · Score: 0

      Another alternative may be to point out the flaw to some reporter, who in many western countries are above the law, at least if the headlines are lurid enough.
      Even if they are not, they know a lawyer, the poster does not, since he is posting on slashdot, instead of asking that lawyer first, so I'll take for granted he doesn't have one(not even an elective law class teacher) to advise him in this case.

    5. Re:Show the problem to your school leaders... by flonker · · Score: 1

      Yes! An anonymous message is the best course of action. If they know who you are, they *will* assume you compromised the system. Then they may take legal action against you. By that point, you're fucked, even if you're in the right. You'll lose a good year or two of your life defending yourself, and paying legal fees.

      Communicating through a lawyer is also good, if expensive. If they're involved from the beginning, then it'll be cheaper than getting them involved later on. Try contacting the EFF, they should be able to help. At the very least, you'll get a lawyer's opinion.

    6. Re:Show the problem to your school leaders... by Anonymous Coward · · Score: 0

      "That person might have gotten his job through political means, rather than displaying competency."

      You know I keep reading the competency thing and as one of these kinds of people that make applications this is just insulting.

      Politics is one reason, having no fucking cash is another.

      For instance, I have a test tool that is used by a good number of profs. Its not the most secure, but thats why its clearly stated it is for low stakes testing. Honestly, I think students should get half the score just for doing this testing because it helps reinforce knowledge.

      For a year or two it didn't have HTTPS to encrypt the data. We *ALWAYS* had snot nosed kids from the technical departments screaming that it wasn't secure. Hell, we'd have snot nosed profs screaming about this.

      The thing was, all of this had to be done either through the universities network, or if at home, logged in through a VPN. The VPN is secured right there. The schools networks were all routed through secured devices that one would need both a physical key and a password to get to the devices as they were in locked rooms. To sniff the networks, you'd have to go through as much trouble as it would have taken to do a man in the middle trick. In fact, it would have been easier to do the man in the middle.

      Costs kept our department from utilizing HTTPS as students didn't want to use the selfsigned certs, and at the time, we didn't have $500 sitting around that anyone was willing to release to buy the certs. We actually have *MORE* problems with the selfsigned even with a page of explanation that we did with no certs.

      Even if we did, we had far more important items that needed to be purchased with this money -- like keeping students employeed so they could do work that was supporting their education and so they didn't have to work at the Taco Bell (which was actually as competitive with the salaries as we were), and figured that a little insecurity is worth the problems we might have.

      Past that and pointing out that folks in power are idiots can be dangerous because the folks that turn out not to be idiots can be pretty fucking vindictive when they know they can make 2x in the 'real world' (as all their friends tell them), but choose to do something where its more rewarding because you hope you are making a difference in people lives (I have 6 students working with me in various capacities a semester -- most if not all learn far more in my environment than they do in their university classes which only exist to give them a head start on understanding the principles -- universities NEVER teach you how anything work, they give you the ability to learn how things work for later life experiences -- hence all the bullshit courses you have to take -- I hope my end of things helps even other shit out). When we get vindictive about this because some snot nosed bastard makes a stink about it, we do all we can in our power to fuck with them.

      Challenge authority all you want, just realize that the tables can be turned around just as easily.

    7. Re:Show the problem to your school leaders... by Profane+MuthaFucka · · Score: 1

      having no fucking cash is another.

      If a university has enough money to automate its systems and pay for a fast internet connection, then it very well can afford $500 to buy a cert.

      You know I keep reading the competency thing and as one of these kinds of people that make applications this is just insulting.

      I suggest that you stop being insulted, and do whatever you can to become competent. Skipping a secure connection because of $500 isn't competent. Hell, even your overly long defense of the bogus reasons why $500 is too much to spend is incompetent; I was completely unconvinced. Bored even. Yawn.

      --
      Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
  5. No no no by FattMattP · · Score: 4, Insightful
    I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school.
    So you're going to point out how insecure their network is by placing 18,000 students accounts in more danger than they're already in? You'll end up in jail for "hacking" if you do that. Seriously.

    What you should do instead is write a letter explaining the situation in terms that a layman can understand. Outline why you believe the current setup is a problem and the risks associated with it. Identity theft is becoming more of a problem these days so maybe they'll understand where you're coming from. Then, and here's the important part, present a solution for them.

    Whatever you do, DO NOT sniff the network and post the results. Don't even show them privatly to the people in charge. Let them handle their own security investigation. All you need to do is point out the problem and suggest a resolution.

    --
    Prevent email address forgery. Publish SPF records for y
    1. Re:No no no by Biochrome · · Score: 5, Informative

      You'll end up in jail for "hacking" if you do that. Seriously. I meerly nmaped our server, and I spent a night in jail, and lost all computer priveleges forever at school. Do NOT even act like you may be comprimising network security... you'll end up in a boatload of trouble.

    2. Re:No no no by shfted! · · Score: 1

      Reminds me of that one time I set off security alarms for port scanning an entire 255.255.0.0 network. Lets just say that was a mistake ;)

      --
      He who laughs last is stuck in a time dilation bubble.
    3. Re:No no no by borius · · Score: 0

      I'm shocked. You went to jail for nmap:ing a server? WTF! They can't do that, it's not illegal. Taking your computer privileges is one thing, jail another... What country do you live in?

    4. Re:No no no by Frisky070802 · · Score: 2, Informative

      I'm with you there. Just think about what happened to Randal Schwartz at Intel a few years ago!

      --
      Mencken had it right. So glad that's old news.
    5. Re:No no no by Anonymous Coward · · Score: 0

      Uhh, it doesn't sound like they shouldn't have overreacted. From your website:
      I got suspended from school for another two days, for stealing shit. Goddamnit, I'm stupid.

    6. Re:No no no by Anonymous Coward · · Score: 0

      Or also this: "I'm a fucking genius. I got caught "hacking" the school server. Hacking as in randomly slecting a bunch of folders and deleting them, because a teacher left her account locked in. A few hours later, the network administrator pressed the "undo" key, and I got banned from the school network. Wow"

    7. Re:No no no by Anonymous Coward · · Score: 1, Informative
      (Copied from his blog): "I'm a fucking genius. I got caught "hacking" the school server. Hacking as in randomly slecting a bunch of folders and deleting them, because a teacher left her account locked in. A few hours later, the network administrator pressed the "undo" key, and I got banned from the school network. Wow"


      The guy obviously has been causing a lot of intentional damage already. His blog also talks about him stealing things from his school. If he went to jail, he probably went for a ton of other things as well.

    8. Re:No no no by pete6677 · · Score: 1

      I do hope you sued for false arrest. No way could you have been legitimately arrested. They did it strictly as a scare tactic, hoping that you would crack and confess everything that you did along with some terrible things that you didn't do.

    9. Re:No no no by Anonymous Coward · · Score: 0

      I call bullshit. You can't get arrested for portscanning a computer. At least not in North America. Not likely in Europe either. I think this is the story you trot out to your high school friends to make them think you're hot shit.

  6. Damned if you, damned if you don't by G4from128k · · Score: 3, Insightful

    IANAL, but I suspect that if you intentionally demonstrate the insecurity of the system, you will be sent to jail. Ask a lawyer, but I suspect that their advice wil be to not do anything that involves you breaking into the system.

    On the otherhand, until somebody at the school gets their identity stolen AND they can prove the school was at fault, nothing will change.

    At most, I would document the problem WITHOUT breaking any laws (again IANAL). Even documenting the problem that might get you in hot water for the terrorist crime of "hacking."

    I feel for you. Be careful.

    --
    Two wrongs don't make a right, but three lefts do.
  7. Inspiration by MegaT · · Score: 3, Interesting

    So Slashdot, what is a concerned student to do?
    this?

    1. Re:Inspiration by 0BoDy · · Score: 1

      Please note that this example of a hacking excersize was santioned, and the school knew about it. Also, IANAL but I don't think this is covered under FERPA, so there's not as much rick to the admins. Moreover, these admins appear to be open to criticism vs. those at a college. think about it.

      --
      Can I be a Luddite too?
  8. Do not! by AresTheImpaler · · Score: 1

    I would recommend you not to get the passwords and user names. I know you are not going to be using them to do anything harmful, but it is ilegal. Instead of doing that get one or two professors to back you up. If those in the IT department don't pay attention to you, you would have a professor that could talk to the dean or someone 'important' that would make ge the attention of the admins.

  9. Sniffing's a bad idea by the_truk_stop · · Score: 3, Insightful

    While sniffing passwords sounds like a great way to get students' awareness up, that's generally an extremely bad idea. While the administration sounds like it's being incompetent, you posting sensitive information online will quickly get you slapped with legal issues.

  10. Re:failure by Anonymous Coward · · Score: 0

    Yeah, that's 'cuz I forgot the 20 second rule. I just hit Submit, got the 20 second warning (I had waited 17 seconds, apparently), hit back, and had to type it in again, then wait 20 seconds. At least 45 seconds total.

  11. No ultimatums... by isaac · · Score: 4, Informative
    Do not make an ultimatum. You WILL be subject to disciplinary procedures, and probably prosecuted. If speaking to the campus technology people responsible (and I mean speaking to the people who are *really* responsible - the managers, not the helpdesk) for these systems and networks about your concerns produces only indifference, you should drop the F-bomb - FERPA, the Family Educational Rights and Privacy Act. Under FERPA, your school may be both liable to you (and theoretically face loss of federal funds) for unauthorized disclosure of your educational records and other personally-identifiable information like SSN. (Directory information, such as your name, and the fact that you're a student, is not automatically protected from discloseure by default, but you may request that such info not be disclosed to third parties.)

    I guarantee the IT managers will have heard of FERPA, and they should snap to attention when you remind them of their responsibilities under the act.

    Consult an attorney licensed to practice in your jurisdiction for more information on your rights. I also recommend judicious use of Google.

    -Isaac

    --
    I am not a lawyer, and this is not legal advice. For Entertainment Purposes Only.
    1. Re:No ultimatums... by GigsVT · · Score: 2, Interesting

      Yeah, but there doesn't seem to be a clear cut line. From what he's said, the data is pretty much secure. As secure as any normal data was 15 years ago.

      Sure, it could (and probably should) be more secure, but does FERPA lay out detailed standards for encryption and data security practices? I personally don't know, but I seriously doubt it.

      (On the other hand, I see no use in putting that data on the web, of course he knows his own SSN and personal info.)

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
    2. Re:No ultimatums... by Anonymous Coward · · Score: 3, Insightful

      Remember also that you catch more flies with honey than with vinegar, and even if you drop the "F" bomb, a pissed-off vice chancellor or IT manager can stonewall like you can't even comprehend while appearing to any outsider to be dealing with an unreasonable student as responsibly as possible

    3. Re:No ultimatums... by Creepy+Crawler · · Score: 1

      Yeah... and when you file suit with FERPA, ALL governmental funds are CUT.

      Fuck the IT manager. This affects EVERYBODY!! that's what you plan when you do this,....

      --
    4. Re:No ultimatums... by Anonymous Coward · · Score: 0

      Exercise: How many schools to date have had government funds cut off for a FERPA violation? It's not as much of a threat as you think it is--just because schools make a good faith effort to comply does not mean they have to take direction on security practices from a rogue student.

    5. Re:No ultimatums... by bcrowell · · Score: 2, Insightful
      Under FERPA, your school may be both liable to you (and theoretically face loss of federal funds) for unauthorized disclosure of your educational records and other personally-identifiable information like SSN.
      IANAL, but I believe there are some big exceptions written into the law. Your information can be given to anybody who has a legitimate educational reason to see it. I also don't think the law spells out any particular level of security that's required. The only kind of stuff that really gets you in trouble as a teacher or administrator is somthing silly like posting people's grades on the door of your office at the end of the semester.

      The OP just needs to get a better grip on reality. His SSN is not a well kept secret. Anybody who really wants to find out his SSN can easily do it. I also think he's confused about the "proprietary" student ID number as opposed to an SSN. Using an SSN for anything but social security is both a security risk and an invasion of your privacy. His school is doing the right thing by switching away from SSNs.

      The basic solution is that he should not use a valuable password on this particular account. Problem solved.

  12. At Northwestern University... by the_truk_stop · · Score: 3, Interesting
    ...the page where you change your password has a Javascript app that will check if your password meets the Northwestern University IT guidelines.

    If it doesn't, a pretty window pops up, displaying your password along with an explanation of the error. Wonderful. A variation of my second most sensitive password suddenly popped up when I missed the shift key while typing in a symbol. So far all my complaint has gotten from IT is "We'll forward this one on to so-and-so."

    Students in-the-know are generally ignored. I wouldn't bet heavily that your school will change its policies anytime soon. It probably took a boatload of work to make the switch in the first place, so more changes will probably take a lot of prodding.

    1. Re:At Northwestern University... by Nasarius · · Score: 1

      How exactly is this a security problem, unless someone happens to be watching over your shoulder?

      --
      LOAD "SIG",8,1
    2. Re:At Northwestern University... by LittleBigLui · · Score: 1
      How exactly is this a security problem, unless someone happens to be watching over your shoulder?


      Well, there IS a reason why password entrance fields usually only give asterisks as feedback.
      --
      Free as in mason.
    3. Re:At Northwestern University... by the_truk_stop · · Score: 1
      Shoulder-surfing is exactly the security risk. The guys around me in my dorm are fairly competent with computers. One in particular likes to gain access to other people's computers and mess around wrecking havoc. Him having my password is a dangerous proposition.

      Having password displayed in plaintext against my will is even more dangerous.

    4. Re:At Northwestern University... by Glonoinha · · Score: 1

      If you have one 'super duper' master password that you use for everything and never change it - you are already screwed. In fact the more 'super duper' it is the more you are screwed because you trust it with everything because you think nobody can guess it or hack it. When someone figures it out (and it happens) you are screwed across the board and the damage isn't sectioned off to just one thing like your college network.

      Work up a scheme of passwords for different layers of security :
      - one set of passwords for web sites like this - message boards under an alias, no financial damage if compromised.
      - a different set for your eBay / Visa web sites
      - a different set for your secure boxes at home with your porn and warez
      - a different set for use on other people's secure boxes / networks (like work or school.)

      Change them from time to time. Use a different password for administrative access to your 'secure' systems than you use as a day to day user.

      It is no longer a question of whether or not someone is going to get your password, it is a question of how much damage will they do when they get it, and how long they can use it without you knowing they have it. Which is worse, to have someone get your password and do something malicious the same day (and thus you find out about it and have to clean up whatever he did) or have someone know your password and silently shadow you for the next three years - reading every email, downloading and archiving every file, and monitoring your every online move?

      --
      Glonoinha the MebiByte Slayer
    5. Re:At Northwestern University... by the_truk_stop · · Score: 1
      one 'super duper' master password...for everything and never change it

      Actually, I have a "super duper" password that's an unspecified-but-very-large number of characters long, was randomly generated, includes alphanumeric and punctuation characters, and I learned by brute force memorization and repetition. I use that for root's password and GPG.

      My lesser password I keep at 10 or more characters. It's got alphanumeric and punctuation characters. I change it yearly.

      Oh yeah, and I have a separate BIOS password. :) I use public key encryption for password-less login over SSH. Heck, I check for keyloggers when using my college's computer labs!

      So here's the punchline: I act paranoid out of principle.

  13. Georgia Tech by Anonymous Coward · · Score: 0, Interesting

    The submitter doesn't mention his school, but this is exactly the situation at Georgia Tech.

  14. obvious by sporty · · Score: 2, Informative
    1. talk to parents. explain to them thuroughly what the situation is.


    2. get a lawyer. you have a right to use their networks, not admin it. you can point things out, and use the system as intended, but that's as far as it goes. i.e. http vs https. changing other's passwords and what not is something for your parents and a lawyer to discuss with the school.

    --

    -
    ping -f 255.255.255.255 # if only

    1. Re:obvious by littlerubberfeet · · Score: 2, Informative

      I agree. Do ALL communication through that lawyer. That alone will probably scare them into making changes.

      DO NOT give up the protection of a lawyer under any circumstance, because they will screw you over. If changes aren't made, have your lawyer send a cease and desist for violating FERPA, the Family Educational Rights and Privacy Act.

      Lawyers are expensive. I bet you could find one to take this on pro-bono. Ask around, email the ACLU and EFF.

      --
      Sig (appended to the end of comments you post, 120 chars)
  15. Suggestion by theantix · · Score: 3, Informative

    Do *not* sniff passwords or publish them, unless you want to face some nasty consequences. What you should to is draw up a list of the tools required to sniff the passwords and give them a recipe as to how someone could crack their security.

    From what you've said there... You should say something along the lines of "A person could sit in the school parking lot with a laptop and a wireless networking card, and run the program 'Ethereal' to watch the network traffic. This person could literally watch the login IDs and passwords, and use that information to get your SSN and other vital and private information."

    Pass that along to IT, your school administrators... if that doesn't get them hopping try passing the story on to your local community newspaper. That would be much safer than risking the legal reprecussions of cracking passwords yourself.

    --
    501 Not Implemented
  16. Suggestions by alienw · · Score: 1

    I have the following suggestions for you:
    - Don't change your password over the wireless network
    - Don't stir shit up too much. Complain to somebody in the IT department, and then complain to someone in a position of authority (the dean, etc).
    - If that doesn't produce the desired results, forget about it. DO NOT threaten anyone with anything, and don't tell anyone you sniffed passwords. Doing that can land you in jail pretty easily, assuming the network administrator is sufficiently incompetent.

    Otherwise, just forget about the whole thing. SSNs and DOBs are not very hard to obtain, you know.

  17. Honestly? No techies. by JabberWokky · · Score: 5, Informative
    Do not go to the IT department. They have screwed up, and will move to cover their asses in the easiest way; making you a scapegoat and likely sending you ass to jail.

    Go to a Dean, the highest level one you can get a good ten minute discussion. Do not discuss this with anybody else. Tell him that you have not discussed this with anybody else, that you have not exploited this vulnerability in any way, and you are coming to him directly as you realize that publically announcing such a discovery can lead to serious consequences.

    In the corporate world, this is known as an "executive sponsor", somebody with the political clout to shield you when the people who screwed up try to discredit you. It is vital that you have a sponsor, since a student has nearly zero political standing. Lay it all on the line and look the Dean directly in the eye and tell him or her that you are concerned about this issue and also about the reprocussions that whistleblowing this issue may have.

    If the Dean is not connected to the technical issues, they won't have any reason to cover their asses and will stand in your corner in the resulting (and there will be one) shitstorm.

    --
    Evan

    --
    "$30 for the One True Ring. $10 each additional ring!" -- JRR "Bob" Tolkien
  18. MOD PARENT DOWN by Fortunato_NC · · Score: 4, Interesting

    Sarbanes-Oxley has nothing to do with your college's wireless network, or private data, or any of that. It's about corporate governance and reporting requirements for large public corporations. Mods, YHBT. YHL. (again!) HAND!

    --
    Blogging Weight Loss, Distance Education, and more at verlin.com
  19. In my job... by davidu · · Score: 1

    I always wonder who the kind of people are who say things like:

    I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school.

    I mean, come on. This has nothing to do with computers -- if you just think about that for one second doesn't it strike you as mildly idiotic?

    Just don't do it. If you are concerned about security, write a letter to the editor of your paper or an op-ed piece and explain what could be done by anyone but make clear that you have not done it. Just get the facts out into the public without implicating yourself or laying down threats. School administrations dislike bad press, even from the annoying school newspaper. Parents call in, kids complain and if you do your research you might find some relevant laws that it breaks by them implementing this so poorly.

    -davidu

    --

    # Hack the planet, it's important.
  20. Re:Legal repercussions for the school by alienw · · Score: 4, Informative

    Actually, it's called FERPA. Sarbanes-Oxley has nothing to do with privacy or colleges.

  21. It depends on who you know. by consolidatedbord · · Score: 4, Interesting

    If you go to the principle, you will probably get suspended/expelled for "hacking" the network. I went to 2 highschools. At Highschool A, if you had anything to do with anything that was not a part of the school's acceptable use policy, even if it was non-malicious and for the better of the school, you were almost guaranteed expulsion. (If they caught you that is. ;-) ) At Highschool B, there was a well established tech community that the assistant principle was a close part of. The on-site LAN admin s were young, former students of the school, so were pretty open to listening to what anyone had to say about "insecurities" on the LAN. I became a part of their student tech program, which offered fairly simple classes in networking, perl, html, and operating system theory. I advanced in the classes, and ended up teaching one of them as a student. Quickly, one of the LAN admins and I become buddies, and a trust was formed with me, him, and the assistant principle. As long as no harm was done when finding some kind of security vulnerability, then no suspension/expulsion was needed. I do recall however, having a history teacher at Highschool A who would periodically pull me and a fellow tech out of class periodically to fix computers. A trust was formed between us, and him. The best advice for reporting this, would be to find a teacher who you are closest to, and explain to them the issues involved. Inform him/her that you aren't trying to harm anyone, you only made a simple ovservasion and would like to report it. A trusting teacher will then put in a good word for you, the student, and you may even get some extra credit.

    --
    while true ; do echo this is my sig; done
    1. Re:It depends on who you know. by Anonymous Coward · · Score: 0

      You graduated high school without knowing how to use "principal" in a sentence?

      Wow. Rock on.

  22. Many players by linuxwrangler · · Score: 3, Informative

    First consider your goal. I presume it is to get them to fix the problem rather than to extort money, humiliate them, etc.

    Given that assumption remember that there are many players. There are the software writers and network admins. They may be afraid of being made to look bad in front of their superiors. They may know the problems and be working on them. They may simply be doing all they can with the resources that have been given them.

    Work your way up from there. IT Department heads may try to claim it isn't a problem (prevent embarassment), indicate the need for more resources or may be in the dark because their people screwed up and hid the problem.

    The legal department and higher administration will be worried about liability and bad press. As such, any "demonstration" you put on can be used against you. Suddenly you will be the bad guy - the evil cracker. They may even try to go after you legally to cover their asses.

    Others have mentioned S-O legislation. There may be a compliance officer on campus who you can contact.

    So what to do?

    I would write a detailed letter describing the problem in layman's terms. Profess ignorance to allow people to save face (phrases such as "perhaps I am unaware of fixes that are already in the works", and "I know running a student network on a tight budget is difficult...") and express your desire that this matter be handled quickly and without the need to involve outside parties but insist that it must be handled.

    The "ignorance" method also allows you to send the letter to a wide recipient list without looking like you are trying to skewer any particular person or department: "I apologize for the wide distribution but I'm not sure who is in charge of such a matter as it involves S-O compliance, student privacy, IT etc..."

    You may want to offer recommendations (perhaps this system should be taken offline to protect the sensitive data until the security problems are repaired) and offer your assistance. If you offer to arrange a demo and they accept, request that they set up a dummy account. This helps isolate you from liability and demonstrates your concern for privacy.

    Other avenues if the "good-guy" method fails: many universities have a student ombudsman, there may be state or federal S-O compliance resources and finally, there is the press.

    --

    ~~~~~~~
    "You are not remembered for doing what is expected of you." - Atul Chitnis
  23. Er, you mean HIPAA... by itwerx · · Score: 1

    Sarbanes Oxley has nothing to do with it.
    HIPAA, on the other hand, has some clout.

  24. Seriously? Here's a list: by np_bernstein · · Score: 1
    By no means is this a complete list, just off the cuff:

    • your parents
    • your teachers
    • other students
    • town paper
    • the school principal/headmaster
    • the super-intendant of schools
    • the PTA
    • the school board
    • your mayor
    • your town selectmen
    • your congressman/woman
    • the EFF
    • the aclu
    • a lawyer
    • Jesus
    • Mary
    • Joseph

    Seriously, though, I'm guessing you have a phone book. There are so many resources that you could use. I'm not meaning this as a knock against you, but you could try google, or ask take a second to think about the resources available to you.
    --
    RandomAndInteresting.comdefending the world from stupidity since 1979
  25. Advice? Be careful what you say. by MBoffin · · Score: 1

    I don't know all the ins and outs, but it seems to be that many people have been burned by the DMCA for trying to let others know about their security problems. I can't remember how many stories on Slashdot I've read that seemed utterly ridiculous because someone was in legal hot water for trying to help some company/institution/organization get their security issues known about.

  26. Any chance it really is encrypted? by itwerx · · Score: 1

    I've seen some apps that ran over plain old HTTP but had a Java applet that was a VPN client so they were essentially just tunneling the encrypted session via port 80.
    (Yeah, I doubt that's the case here too... :)

    1. Re:Any chance it really is encrypted? by yomegaman · · Score: 1

      That's what I was wondering also. I have a faint recollection that that's how Travelocity used to work, all the pages were http but they used some javascript thingy to encrypt and send off the stuff you entered into the form fields. Maybe the school is using something like that?

      --
      ...wearing a skin-tight topless leather jumpsuit, with cutaway buttocks and transparent crotch panel.
  27. Proprietary user id and password? by merdark · · Score: 1, Interesting

    What are you on about with the whole "proprietary user id and password" nonsense. We usually call these things just "username" and "password". Proprietary usually refers to some sort of intellectual property of some value, like source code or wiring diagrams or similar.

    It's not a synonym for "something I don't like". Weirdo.

  28. Can you say lawsuit?? by nes11 · · Score: 1

    Nobody seems to have mentioned this, but if the school is knowledgably posting student data, then they are in open violation of FERPA (Family Educational Rights and Privacy Act). If you notify them of the problems & they still refuse to do something, you have every right (& possibily the responsibility) to sue the hell out of them.

  29. At my secondary school.. by Anonymous Coward · · Score: 3, Interesting

    At my sec school I got in trouble three times. Once because I used megaproxy.com to access Hotmail to send some work home (intrestingly enough, megaproxy.com was stuck on a post-it on the side of the server (yes, the server was just on a desk in a little closet!) - the council, not the school, have authority over what's blocked, so my guess is the teachers used that site to access things which were blocked too....). I got a little ticking off for that. The teachers knew it was silly and had had lots of complaints from students, but done nothing about it.

    The second time I was logged on on somebody else's account and I just did a copy/paste on the common drive. That didn't actually waste much space or slow down performance at all, but it was worth a letter home and a ticking off. Yes, it was stupid using somebody else's account.

    The third time I was pointing out vulnerabilities in the security software they were using (rather, it was a program running over windows and one of the features was that it prevented you from typing "C:\" in a file dialog box. A friend discovered that if you put c:\ in the clipboard and hold paste in the dialog box then eventually the software will be too slow, windows will win and the dialog will open. He screenshotted it and put it on the common drive for people to see. I opened it and put a ring round the "c:\" showing in the dialog box. Of course, my name came up as "last edited" (I never understood why they didn't check created by, but said person had friends right at the top...hmmm.....CORRUPTION..).

    That got a letter home and lots of chats with the Admin and Head of IT (who also happened to be my maths teacher, and knew a) I was brilliant and b) I wasn't harmful) - but still, because of politics from above, she had to take action.

    The funny thing is that there were people in the year below me regularly abusing holes but who didn't get caught because they weren't trying to inform the school. Oh the irony.

    It sucks. The suits don't understand the world of computing - just right, wrong, PR and . They don't understand that sometimes you have to be "cruel to be kind", to nick a lyric.

    The hardest part is that if you do NOT show them the holes they will ignore you, but if you DO, you get letters, action, records, jail time.

    Good luck.

    1. Re:At my secondary school.. by 0BoDy · · Score: 2, Interesting

      It all goes back to this: anytime you make something illegal, then only outlaws can do it, form compiling programs to owning a gun the patriot act and american policy seem to be making being a white hat illegal. They welcome folly by olny allowing black hats who are really dangerous to continue their activities (for lack of a better word) Maybe we need to start a slashdot letter writing campaign???

      --
      Can I be a Luddite too?
  30. Re:failure by eizan · · Score: 1, Troll

    This has nothing to do with the above posting.

    I post here because of the importance of my message:

    DO NOT break security to prove its inefffectiveness. it is ILLEGAL and you will get into major trouble for it.

    Find ways to speak with the local sysadmin, show them how vulnerable they are-- most responsible ones will listen no matter who comes and tries to speak with them.

    But remember this: when dealing with somebody who might consider themselves an "adult" compared to you, approach with an air of maturity and try to reason with them, if anything, for the sole purpose of responsibility. If you believe in your ideals, don't give up, but NEVER resort to irresponsible behavior-- you will be doing more harm than good for both you and your classmates.

  31. First of all, finish your homework and hand it in by Anonymous Coward · · Score: 0

    The security is not your responsibility - you should be studying.

    If you are worried about security, then after you have finished all your studies write a letter on a piece of paper and mail it to the most senior head of department you can think of, and cc it to the head of another department, and keep a copy for yourself, for your records in the years to come. Then you have done your job. Well done.

    Your letter should be polite, friendly, positive, typed, with a handwritten signature and note at the bottom.

    Then get on with your studies and be proud of yourself for doing the right thing. Chill out.

  32. WTF? by Anonymous Coward · · Score: 1, Insightful

    If your post has nothing to do with the one above yours, why did you reply to it?

    If its so important, why don't you start a new thread?

    Idiot.

  33. Release the hounds... by Anonymous Coward · · Score: 0

    Provide a link so that the slashdot masses can slashdot this unsecure server into oblivion!

  34. So tell me, little shaver, by Mordant · · Score: 1

    just where did you say you go to school? ;>

  35. SSN?! by psyconaut · · Score: 4, Insightful

    " I was upset about them changing from using my SSN to a proprietary number scheme for identifying students..."

    Let me see if I understand: you're upset about not being told to use a piece of information that's the root of identity theft issues? Heck, I'd be *glad* the school was moving away from having my SSN plastered all over the place!

    -psy

  36. Re:Legal repercussions for the school by JackAsh · · Score: 3, Informative

    Some of my respondents here are absolutely right - it's HIPAA I'm talking about, not S-O. What can I say, long day at the office, been working so much on compliance for both they're freaking interchangeable in my mind by now, etc. etc. Still no excuse.

    First, IANAL (as evidenced by my previous stupid message naming the wrong act). In any event, my understanding is that although HIPAA was originally enacted/intended as a Health-Care related act, it's effects have been interpreted to apply outside of Health Care and to any industry that stores people's private, personal data. One of the big flags the act applies is storing social security numbers.

    Rule of thumb is that if you see something private stored or transmitted somewhere it needs to be seriously secured. Seriously secured is roughly defined as encryption for every stage of the data lifecycle, from storage to transmission; as well as access control measures and all that jazz.

    So anyway, a whole bunch of industries are running around with their panties in a knot because of these new privacy regs. Then you have happy California's 1386 stuff which I think was meant for online shopping but ended up saying something like that if someone hacked your entity and gained access to customer data you have to notify every single member of that customer population that resides in California or be banned from doing any kind of business in that state. I'm sure that strictly speaking the laws apply only to some very specific instances, but that hasn't stopped people from panicking just in case it could be twisted into applying to them. I'm sure that my explanations are grossly overgeneralized, but they do serve the purposes of this conversation. :)

    The point being, there's cool new regs that protect your privacy. Make sure your school is taking them into account. I wouldn't be hostile about it, but they might just need a pointer in the right directions.

    Good luck,

    -Jack Ash

  37. I think we go to the same University by Phleg · · Score: 1

    Send me an email (ste phe n@t ous et. org) so I can find out if you go to the same University I do--the description matches perfectly. If so, the both of us will probably have better chances of changing something. Especially considering I know most of the Student Government and IT folks there.

    --
    No comment.
    1. Re:I think we go to the same University by EaTiN+cOfFeE+bEaNs · · Score: 0

      I also think that we go to the same University. If my URL matches where you go, please say something.

      --
      No TiVo and no caffeine make me something something...
  38. Platinum cards by aminorex · · Score: 2, Funny

    A few credit applications using the Dean of Students'
    home address and the names/ssns of ten or twenty
    lucky students would get some attention, I reckon!

    --
    -I like my women like I like my tea: green-
  39. Watch out! by Psychor · · Score: 1
    You shouldn't have told me that... you can bet I'm going to sit outside your school sniffing wireless traffic now, so I can find out your date of birth and SSN. I hope you have plenty of car parking for the hacker influx!

    Or perhaps not. In the grand scheme of things, this is a very minor issue, the details aren't that significant, the time taken to procure them would be excessive, and I doubt that a large proportion of students even use the wireless network. You should perhaps consider yourself lucky to have access to such a network at all, not kick up such a fuss posting articles on Slashdot full of hyperbole just because the login form uses HTTP instead of HTTPS, and certainly not advocate sniffing the network yourself and violating other's privacy.

    Lets face it, your school computer account is unlikely to be of interest to most of the world. If you really feel the need to raise the issue (personally I don't think it's even worth the effort), speak to the person in charge of the school network, and if they don't do anything and you still consider it to be a significant issue, schedule a meeting to raise the issue with the principal. Certainly do not direct threats at anyone.

    1. Re:Watch out! by Anonymous Coward · · Score: 0

      SSN and DOB arn't important!?

      those are very important (and very difficult) to keep secret. they are all that is needed to steal your identity, take credit cards out in your name and in general make a mess of things.

  40. Re:Legal repercussions for the school by user+no.+590291 · · Score: 1

    WTF--unless the school is a publicly traded company, Sarbanes-Oxley doesn't even apply. FERPA, yes. GLB (if the school deals in student loans, most do), yes. S-O, no.

  41. bah by Maskirovka · · Score: 2, Funny
    Should I send an e-mail with an ultimatum.

    Nah.
    Just post the name of your school here and let the problem take care of itself.

  42. Good practice in exposing exploits by basking2 · · Score: 1

    OK, I skimmed the topics and didn't see anything that really targetted this idea, so here it is...

    First, go to the school with a nicely written letter explaining the vulnerabilities, the impact and why it must be fixed. Tell them that you intend to publish your findings after a month or so or later if the school needs that time to fix the problem. The idea it to fix a date so that that school fixes the problem.

    Again, our goal is to fix the problem. Not arm the baddies.

    If you fear that you will be sued for some odd reason (and unfortunately, our governing officials in the US do not understand security very well) grass roots is powerful. Word of mouth is devistating. The down side is that this method will almost surely alert the wrong folks to the problems before they are fixed. If it makes you feel any better, the problems you are describiing are so trivial that I'll wager that they are already being exploited.

    On a final note, you as a technical person able to help others have, in my book, an obligation to try and help fix this. I think you already understand this (hense your post to /.) so bravo to you! Fight the good fight.

    --
    Sam
  43. Today's experience with school IT people.... by corpsiclex · · Score: 1

    I was in the library reading slashdot on..shudder..Windows when the impossible happened: IE.EXE crashed. I begin to hold the power down button for a cold boot. [IT Bitch walks over] IT Bitch: What do you think you're doing? Me: IE.EXE Crashed. Big Surprise. IT Bitch: Normally people come and get us when that happens. Me: IT Bitch: What were you doing? Me: Reading /. IT Bitch: What's that? Me: *stare* [IT Bitch informs me that the thing to do is reboot the terminal] IT Bitch: What was all that typing? I heard a bunch of typing... Me: I was typing a URL in the address bar [IT Bitch checks the CD drive. Empty. Looks disappointed] IT Bitch: Show me /. [I show her slashdot] IT Bitch [upon noticing the 'Hardware Hacking Projects for Geeks banner advertisement] kicks me out of the library. And don't get me started on my 2 day suspension for distributing linux...

    --

    eBayDig 1s a typo saerch engien
  44. Above all, tact by Jmstuckman · · Score: 2, Interesting
    There are several ways to deal with this situation. The real question is how the IT staff will react to each of them.

    The most important thing to remember is that they're going to avoid losing face in front of their superiors at all costs. This reclaiming of face might involve lying or throwing you in jail. If you find a way to inform them of the problem *without* causing anyone to look bad in front of someone with influence, they'll be grateful.

    Half of business communication is learning how to tell people things without causing them to lose face in the workplace. The sooner you figure this out, the sooner you'll be successful in the business world.

  45. Walk away.... dont say a word... by Anonymous Coward · · Score: 0

    Walk away.... dont say a word...

    If your school is WTAMU, then just walk away... dont say a word about it... your info WILL be used against you. They will use anything to cover their asses... including you...

    1. Re:Walk away.... dont say a word... by Anonymous Coward · · Score: 0

      Well, what do you expect? They got a friggin link to Texas Homeland Security on their front page.

    2. Re:Walk away.... dont say a word... by Anonymous Coward · · Score: 0

      Yes, isn't it terrible that the school is concerned about security? Not like they have thousands of students to protect or anything...

  46. Your school newspaper by Anonymous Coward · · Score: 1, Insightful

    Take it to them, explain to their most technically savvy reporter (get their web guys to help if they have them), and get them to write a story. They can make the other students aware of the problem, and once a lot of students are aware, the administration won't be able to simply ignore it. They'll be forced to fix it, and it won't look like you were trying to blackmail them.

  47. Drop it by TheLink · · Score: 1

    You said you've already brought it up to them.

    If you're in the US (or France), unless you really like the people in charge of your school AND they like you, forget the whole thing.

    If they're not interested in fixing it, just walk away. There are better things to do. What's in it for you? Jail time?

    You're going to be in that school for how many more years? Just do your time in school and get out. Why risk doing time in jail as well?

    The whole world is not secured properly, but things still work because most people have better things to do than exploit every security weakness they see.

    --
  48. don't come close to threatening by Thu+Anon+Coward · · Score: 2, Interesting

    you want the school to kick your ass out because you threatened them with revealing their network secrets and not following their AUP (surely they have one?)?

    instead, find some sympathetic influential faculty (especially if they have tenure) who can make life hell for those responsible. if they refuse to do anything, just report it to your local newspaper and document _EVERYTHING_ (either immediately write notes while in their presence or tape-record what their comments are while they deny any problems). if they turn purple or get irate, either way you got 'em by the short-n-curlies.

    you shouldn't have to put up with stupid people who endanger your future life because they won't protect your data.

    hmmm, I wonder if this would make them liable for future case of identity theft? potentially big bucks!

    --



    I'm good with numbers - .45, 7.62, 9.....
  49. I've had this same situation by shfted! · · Score: 2, Interesting

    About a year ago, I noticed a fairly significant vulnerability allowing me to get the shadow passwords of any student in the CS program, as well as all faculty and staff at my university. Thankfully, I am on good terms with the CS computers administrator, and told him what I could do, and told him what to type to get it. Being plain old DES, the shadows passwords would have been trivial to crack using a dictionary approach.

    He immediately contacted the university CTS staff (they administer everything else), and it turns out they were aware of the vulnerability. I noticed that later that week the hole was closed in a hacked way, by simply disallowing use by regular users of a certain system binary.

    He also told me it was a smart decision on my part to come forward immediately with the information, because if they had found out that I knew and didn't tell them, I would have been expelled and barred from any post-secondary institution in North America for several years. I guess they keep a watch list somewhere.

    --
    He who laughs last is stuck in a time dilation bubble.
    1. Re:I've had this same situation by polyiguana · · Score: 1

      He also told me it was a smart decision on my part to come forward immediately with the information, because if they had found out that I knew and didn't tell them, I would have been expelled and barred from any post-secondary institution in North America for several years.

      Bullshit. Even if you were expelled, most schools won't say more than the vaguest idea why. It's to prevent them from lawsuits. Besides, you could just omit that institution from your transcript and they would never know, if that was the case (which it isn't).

    2. Re:I've had this same situation by shfted! · · Score: 1

      At a lot of institutions, omitting past attendence from other institutions is grounds for expulsion. They're rather picky about that around here.

      --
      He who laughs last is stuck in a time dilation bubble.
  50. Two suggestions by MobyDisk · · Score: 1

    1) Sniff student passwords, then email the passwords to those students. Nothing is compromised since you are only emailing someone their own password, but that will bring the security flaw to their attention. If you do this enough, then a lot of people will get frustrated with the school.

    2) Go to the CS department. There is probably some grad student who is doing a thesis on network sniffing or honeypots or wireless security or sometihng. Have THEM do the sniffing under the watchful eye of their faculty sponsor. That way, it is protected as research (well, as much as is possible these days) and the school can only blame themselves.

    3) Okay, I said 2. Third is to go to the student government. Students going directly to the administration is seen as a challenge and they commonly to respond by stonewalling. The Student Government is the appropriate organization to lobby on behalf of the students.

    1. Re:Two suggestions by 0BoDy · · Score: 1

      Under no circumstances sniff passwords, let alone send e-mails. As if Getting jailed for hacking weren't bad enough, you'll be imediately reported as hackers by the people you e-mail. Once, I pulled all the AIM screen names out of an extensive forward and put them into my Buddy list, I statered to IM them and tell them that thier e-mail addresses were being distributed, and aspects of their privacy violated, and I was called names, cursed at, reported to AOL TOS (which doesn't do anything), and called a criminal. People whined about being harassed, but boy could I make a lot of money advertising Using that info. . . .hmm

      --
      Can I be a Luddite too?
  51. I'm assuming you're in IT by Gary+Destruction · · Score: 2, Insightful

    I'm assuming that you're in IT to some capacity and not someone who just knows a good deal about networking and security. The reason I'm asking is because if you're not in IT and you approach them, they might talk down to you or attempt to discedit you. I'm sure you know what I'm talking about. The "Well what does he/she know about computers?" If you are in IT, you might want to approach them from the standpoint of an IT professional. You might say something like,"Hello. I was logging in and noticed something...." And make them aware that you are an IT professional/student so that they know you're someone that's speaking on a level playing field. And if you're a student, you could say something like,"Well in security class, I learned https and..." It's a tough situation because you don't want them to get the impression that you're snooping around and looking for something to exploit. At the same time, you don't want to come across as being intrusive or pushy. The other option is to approach them showing concern about your own privacy. The idea of an ultimatum has already been answered by previous comments.

  52. You don't happen by Anonymous Coward · · Score: 0

    to be going to school at IU are you?

  53. Watch your ass by +CipherDemon · · Score: 2, Interesting

    I experienced similar things with my school (except that we're a high school in florida, which means there's almost no education money. bastard politicians.). I found a multitude of insecure things in the workstation setup (including being able to edit file shares between machines from a non-admin account). So, I made a report for them and gave it to my computer teacher. The first IT person that got ahold of my report wanted me suspended and barred from all on-campus computer labs. The second one finally fixed everything that I'd mentioned and now we're running much more securely (although there are still problems that I'm NOT going to bother filing a report about as it won't do any good, I don't plan to exploit them, and I'll just get suspended). But, I haven't gotten any thanks from the IT department. Honestly, I'd rather take it to the deans first as an issue of personal privacy vs. network security. You're probably safer that way as you'll be above the IT people and won't get owned hardcore by them.

  54. Re:Legal repercussions for the school by Anonymous Coward · · Score: 0

    don't you mean LGB (Lesbian-Gay-Bisexual)?

  55. GODDAMN IT! by Anonymous Coward · · Score: 0

    STFU. JUST STFU! Quit being paranoid, you pussy! Nobody gives two shits about your SSN, date of birth, or address. You're nobody special. I'd advise you to quit wasting time with the schools' IT internals and get back to studying. Wasting time dicking around with nonsense like this causes missed classes and low grades. You'll regret it years later, likely after you've dropped out of college and have spent all your unemployed time submitting Ask Slashdot questions. COCKSUCKER!

  56. Please Prosecute me! by bhima · · Score: 1
    Every thing you said is begging to be prosecuted in some way. Do you think that the sysadmin doesn't KNOW what sort of network he is running? Do you think that some of the other students have not pointed this out? The network is set up the way it is because the school administration doesn't care to spend the money / time to do the right thing.

    In this case they will only fix the "squeaky wheel" YOU! And probably with a bludgeon. Shutup, protect yourself, get over it and stop using their network for things you think are important.

    --
    Nothing in the world is more dangerous than sincere ignorance and conscientious stupidity.
  57. Another solution by kill-9-0 · · Score: 1

    Grab userid/password from all 18,000 students, then send emails from ALL of them to the Dean, and head of IT demanding that security holes be fixed. Then, use those email accounts to SPAM the administration until security is fixed. Problem solved, and I'm sure the other students will be fine with you using their accounts for such a noble endeavour.

    --
    Liberalism...the next best thing to thinking.
  58. Send a Letter by 4of12 · · Score: 1

    Certified mail.

    To the principal of the school and cc the office of the superintendent of the district.

    Politely and concisely explain that as a concerned student you believe that the current student database system is needlessly risky as it exposes private information such as name, address and social security number on the computer network.

    Students and parents rely upon the school board and administration not only to provide the best possible education, but also to protect their students' private information from unauthorized disclosure.

    Tell them you think the problem is serious and warrants immediate attention and correction. You'd be happy to work with representatives from the school to demonstrate what you feel are the essential features of the problem.

    Don't be too enthusiastic when it comes time to reveal the problem. (Remember, no one wants to be shown how they fucked up by contracting things out to IT For Less.) They will trust you less if you have any hint of cockiness. Act professional and courteous. Your attitude will critically determine whether you are perceived as a 1337 h4X0r that is dangerous and not to be trusted, or as an intelligent, concerned individual that is willing to your skills for the betterment of the community.

    Don't go tell all your friends so that people find out by the grapevine.

    Hang on to a copy of the dated letter and if nothing happens for a year, then forward a copy to the president of the PTA and to a local newspaper. But there's no good reason to light that fire before it's needed; most school administrators will try their best to fix problems the best they can with the resources they have (admittedly, money and skilled personnel are often drastically limited at many schools).

    --
    "Provided by the management for your protection."
  59. Hire a lawyer by cavemanf16 · · Score: 1

    Get your parents to pay for his/her retainer. If you're in the Columbus, OH area I could refer you to one lawyer at least that would be ethical and fight for you at the same time. (He's not me, but I do know him well enough to know he's a good guy).

    Seriously. If you know that your personal ID info can be VERY easily obtained (as your posting indicated) then it's only different than if you were embroiled in trying to regain your identity through fraud because you're being pre-emptive about it rather than trying to fix the problem after the injustice occurred. I think if you could demonstrate to a lawyer the very serious potential risk your school is taking in not securing the website than you can have the lawyer send them a cease & desist letter that let's them know you're already protected and concerned enough about this issue to go to a lawyer with it.

  60. Re:Honestly? No techies. by 0BoDy · · Score: 1

    I've seen this happen, and heard of it so many times, you definitely need to approach this from a deeply political standpoint, that's how it will pe pproached by everyone else. Obviously thi kind of breach is illegal, but they'll get away with it if you let them nail you instead.

    --
    Can I be a Luddite too?
  61. Community College of Philadelphia by pen · · Score: 1
    (Slightly OT, but I've been meaning to bring this up, and my /. submission was rejected.)

    If you're in the mailing database of CCP, you'll see your SSN right on the envelope, above your name and address. Someone must have realized this would be a problem, but instead of doing something real about it they just shift the numbers around. So if your SSN is 123-45-6789, then the address label looks something like this:

    45 ** 6789 123
    JOHN DOE
    123 FOO STREET
    PHILADELPHIA PA 19111
  62. A controled attack by erik_norgaard · · Score: 1, Interesting

    OK, so you know your own password and you can allow yourself to access your data. So, how about making a controled intrusion attempt?

    Try to see if you can obtain your own password over the wires or wireless. You know what you are looking for but it may be more difficult than you think, and hence you can avoid making a scene of yourself :-)

    Record the whole session, so you can replay it in front of the admin. A demo is often very instructive when people seem reluctant to believe you.

    You cannot be accused of hacking since all you have done is granted yourself access to your own data.

    This way you have not disclosed sensitive information or violated others privacy. Publishing other peoples ids and passwords online is a very bad idea, even if intended as a proof of concept. Respect the privacy of others, even if you find it is not properly protected.

    If it doesn't succeed the objective, go to the press, school paper or other and demonstrate replay the intrusion.

  63. you're not the only one by keyshawn632 · · Score: 1


    I happened to check the online site for my high school grades, too, and noticed it's on a HTTP, not HTTPS for pete's sake !

  64. SSNs by WaterTroll · · Score: 1

    I was upset about them changing from using my SSN to a proprietary number scheme

    What? Are you saying you were content with them using your social security number as an means of unique identification? I am not sure about the specifics, but I know there is legal restriction involving using someone's SSN for anything but social security. Secondly, my university does the same thing, and I don't like the idea at all. Sometimes I have to fill it out on scantrons and other forms that include my full name. By law, I believe the school has a certain deadline before, assuming my SSN is used for, as they sometimes call it, "my student ID number" has to be changed.

  65. Anonymity by AgentOJ · · Score: 2, Interesting

    Back in college, the same thing (more or less) happened to me. My school was using http instead of https for email, and the same password was used to access student information including DOB, SSN, etc. You also had the ability to add or drop classes with the same password. Since the school had "free" wireless access, and no form of network authentication, anyone could sit in the library and sniff passwords. I made the utterly stupid mistake of calling the "help desk," and the lout who answered accused me of hacking when I tried to explain that email wasn't secure.

    Needless to say, the computer services department eventually met with me, and offered me a tech support job. Being the starving college student, I jumped at the chance. Stupidly, I filled out the job application, and waited to hear back from them...and waited....and waited. Over the next two months, I met with the computer services department three times, each time being given some excuse as to why I hadn't started my new job.

    During this time period, I knew a number of people who worked for the computer services department who I was on good terms with. I asked one of them to check for me to see why it was taking so long to start my job, and he did some poking around for me. Eventually he found out that the job application was a front, and they used the information provided in it to do a "background check" on me to see if I had gotten in trouble for "hacking" in the past. They went so far as to call my high school and check there, and then blacklisted me as a "bogey," apparently their term for hackers.

    They never intended to give me a job. They offered me the job to keep me happy until they could do a check on me. As I had done nothing in the past to give me a "hacker record," they decided to just give me the cold shoulder. I passed up two other job offers during that time period, thinking that the higher-paying computer services job was just around the corner, as I was lead to believe. I never got the job.

    I guess the point of my story is that you can try to do the right thing, and explain the situation to your school's IT department, but you might very well end up in my situation. I'd go to an internet cafe, or send a letter, or something, but do it as anonymously as you can. Unfortunately, even though you're in college, some of the people there do not have open minds, and will scorn you for your attempt at helping.

    Funny thing is, about a year after my initial call to the IT department, one of the school newspapers ran a story detailing the problem, and praising the IT department who had "fixed this problem." The story went on to say how this "hole in the network" had been open for over a year, and hadn't been noticed until recently. I laughed out loud when I saw that, as I knew it was complete and utter bullshit.

    Mod me down if you will, but I know that at least one of the people involved in my case reads slashdot, so if this story sounded familiar, maybe you should rethink your method of dealing with those who only wanted to help.

  66. Re:Honestly? No techies. by Spoing · · Score: 3, Interesting
    1. Do not go to the IT department. They have screwed up, and will move to cover their asses in the easiest way; making you a scapegoat and likely sending you ass to jail.

    Agreed on going to the dean. If you use what I call the Columbo method -- after the dumbly and wise detective on TV -- you can also go to the IT department though this is a bit more risky but may silently solve the problem.

    The Columbo method works basically like this;

    "I'm no expert, though shouldn't there ..." (and give a base -- even misworded -- comment on what is wrong)

    Other phrases: "You know, I was wondering..." / "I find it curious that..."

    Now, don't follow through and 'catch the bad guy'...you're only talking after all -- and *you're* not the expert! These things confuse you!

    "If only someone could do something about that. Do you know anyone?"

    Change the subject and leave or if the mood is right, just smile and leave. A "Yep, I find that interesting" as you go might also get it to sink in.

    If anything, be a little funny but do not be condecending.

    Who to talk to? Pick someone who is in the IT department who does not have an ego or a nasty attitude. Be unexcited, and mention your concerns as if you're commenting on the weather.

    Note: If using https:\\ instead of http:\\ works, mention that *you* found a work around, though https should be the default -- after all -- for all those other people who haven't noticed yet. But what do you know?

    --
    A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
  67. I did something similar once... by oneiros27 · · Score: 2, Interesting

    I sent an anonymous packet of informtion to the dean through campus mail, regarding a faculty member's use of equipment purchased for a university project, and his taking that equipment for a company that he started, and giving us instead dated equipment with 'property of NASA' stickers on it. [where he worked part time, it was my understanding]. He also claimed the work of one of the students for whom he was an advisor, as the work of his company.

    Unfortunately, as there were relatively few people who had access to all of the information that I did, it was rather easy for them to track it back to me. I was called into a meeting with the dean, and the faculty member, and they threatened me with expusion. They also weren't happy with something that I posted to the group's web page (which was in fact, a violation of the university's policies regarding use of computer systems)

    I also wasn't aware that the dean had a vested interest in keeping the faculty member, as he had received a multi-million dollar grant for some of the research that he was doing.

    So, my recomendation is -- if you're going to do anything, go straight to the feds. More than likely, whomever you complain to internally knows what's going on, and wants it to continue, for some reason that you don't know about. [It might even just be a cover-your-ass approach].

    Oh -- and after graduating, years later, I needed to get a transcript for a job. It turns out the university had shipped me a diploma, but didn't have my graduation listed in their computer system. It took me over four months to get the issue resolved, and even then, as the last meeting I had with the assistant dean, he had the balls to appologize to me -- not for someone missing to update a flag in the computer system, but for them sending out an incorrect letter informing me of what classes I needed for graduation and sending me the diploma in error.

    [They only flagged me as graduated, as I had taken a number of graduate level classes, and they applied those to make up for the two one credit classes they claimed I needed, 6 years later].

    Unfortunately, I don't think that this is a direct violation of FERPA, but I know there was some new law, that I think is now in effect, that made it so they had to stop using SSNs as tracking numbers. I've been out of higher ed for almost a year now [working as a systems programmer, and speaking up about problems -- which got me fired], so I'm not as current as I used to be.

    If you really want to report this to the school, take it to the student government, or some other body that the school doesn't have direct control over.

    --
    Build it, and they will come^Hplain.
  68. From a guy in the IT Dept: by tverbeek · · Score: 2, Insightful
    Do not under any circumstances use this knowledge of vulnerabilities to actually sniff passwords, gain access to information you're not intended to have, etc. If your college's Acceptable Use policy is anything like ours, doing so will be a violation. Full stop. AU policies never include an "unless you're doing it for a noble reason" or "didn't do any harm by it" exception. And if you were to catch me with my pants down, you can be sure that I'm not going to thank you for it; I'm going to throw the book at you, to make sure that no one else gets the idea of trying something similar. It doesn't matter if I'm negligent or not; that's just the prudent IT fear-mongering to discourage genuinely malicious hacking (of the kind you're worried about).

    Instead if you know people in IT, you can try going to them with your concerns, from a "hey did you know... it worries me...." perspective. If they're good people and well managed (but just didn't stop to think about it), that should help. If you don't have a friend there, or you hear that IT are a bunch of bozos, your best bet is to bypass them and take your concerns (as "I know enough about it to suspect this could happen", not "I know how to do this") directly to one of the offices charged with handling your student data (e.g. registrar, business office, financial aid). They're the ones who ought to be most alarmed over confidentiality problems (because they've had in-services driving the point home), and it'll be their bosses in the administration who'll have the authority to put the pressure on IT to do their job.

    --
    http://alternatives.rzero.com/
  69. My idea by JoeBaldwin · · Score: 1

    Find an admin who knows his shit, and wants to help.

    DO NOT sniff passwords, DO NOT send "ultimatums", just say "Hi, I've found what could be a security hole on the network. I can show you why it's insecure and how it could be exploited. I don't want anything in return, I just want to help you close the hole because it could uncover a hell of a lot of problems."

    Your ass is covered (you said you didn't want anything, can't be blackmail) and you might get a few brownie points out of it. If the admin responds badly to this and you get expelled or in some other kind of shit, my advice (IANAL applies) is to sue, because you have done nothing wrong...so long as you don't try and seem like a l33t h4X0r g0d by sniffing passwords/sending "ultimatums"-just get to the point, tell the admin what the problem is and how to solve it.

    (For the record, I have some great network admins who listen to the students and are very receptive. The way to go :)

  70. Re:Honestly? No techies. by jeffkjo1 · · Score: 1

    You, my friend, are a genius.

    If only I had thought of the 'Columbo method' before, I think it could have saved me much time with my own University's idiot IT department (and other idiots... they seem to populate the earth.)
    The Columbo method will be my new problem solving manifesto.
    Thankyou.

  71. Open University? by Gordonjcp · · Score: 1

    Don't you have something like the Open University in the USA?

  72. "torpor" ratted out some kid to the cops before? by Cryofan · · Score: 1

    Sounds like the parent poster "torpor" speaks from experience. He probably ratted out some white hacker kid to the cops, justifying it to himself because the kid did not spellcheck his report.

    Oh, torpor, BTW, when you wrote "not one single persons problem," you should have written "not one single person's problem." You forgot the apostrophe....

    --
    eat shiat and bark at the moon
  73. Re:"torpor" ratted out some kid to the cops before by torpor · · Score: 1

    Whatever, troll.

    I don't care how 'old' you are, or what 'color your hat is', if you are on my system when you are not supposed to be, then you are going to be punished.

    There is no such thing as a 'good cracker' ... this 'white hat'/'black hat' bullshit is simply narcissism refined ...

    --
    ; -- the corruption of government starts with its secrets. a truly free people keep no secrets. --
  74. Re:Honestly? No techies. by Anonymous Coward · · Score: 0

    Do not go to the IT department. They have screwed up, and will move to cover their asses in the easiest way; making you a scapegoat and likely sending you ass to jail.

    As one of those IT people, I take offense to this charactization. The chances are that they already know about this problem and are working on a fix but haven't implemented it yet. Talk to them, ask if there is any plans to fix it. *THEN* evaluate the situation.

    One thing that most people don't understand about IT at my university-employer is that we have 50,000 people on campus. And the network HAS to work ALL OF THE TIME. So, it takes time to properly evaluate, test, and implement changes. This isn't your home e-mail server.

    So, if you ask the IT people in charge (the helpdesk people are just there to keep the real geeks from going nuts, you will probably be pleasently surprised by their competence and by their plans to address the issues that you're concerned about.

    Every so often, I have a "darn, those guys are GOOD!" moment -- and I've been here several years and know a lot of the IT people on campus.

  75. Turn it into your master's thesis by dooguls · · Score: 1

    I'm assuming your a CS student. Approach one of your CS professors who has a security clue. Make him aware of the problem, see if he'll help you communicate with the School SysAdmins and administrators. I recently did this very thing and once everyone involved understood the problem, they let me turn the solution into my Master's Thesis. which may be better then getting 'paid' to fix the problem.

    --
    Sig 'em boy!
  76. Re:Honestly? No techies. by JabberWokky · · Score: 1
    I've worked in several IT departments over the past 15 years. Add to that general experience with human nature in academia, government and corporate life.

    I have had plenty of "darn, those guys are good"; I wouldn't trade my IT career for any other. What I describe has nothing to do with IT. If the person had found a flaw in accounting or grant or scholarship allocation or any other critical and potentially very embarrassing problem, they would be in the same situation. When you deal with departments with political clout and you raise a very embarrassing problem, you have to realize that it's very easy for you to get squashed if you're a flea. It's harder if you're a flea riding a big dog.

    Even if the department does nothing, the college will move to protect itself. Somebody will come up with the idea of scapegoating the messenger, and if there is zero reason not to, it will happen.

    --
    Evan

    --
    "$30 for the One True Ring. $10 each additional ring!" -- JRR "Bob" Tolkien
  77. As a student by g0bshiTe · · Score: 1

    I myself would hate to learn that my information was made public in that way.
    Does your school have some sort of EULA for the website?
    Most institutions require some kind of security for nonpublic information, such as DOB SSN. It would seem to me that if this information is not secured properly, then perhaps a class action lawsuit would be in order. Identity theft at a university could damage someone for life. It could lead to you losing financial aid, or student loans you never applied for. I would retain a lawyer. Can be done for roughly $100 have said lawyer send a legal letter (certified mail so as to get a return receipt) and have it stated that his client who wishes to remain anonymous will file a lawsuit against the school for wrongfull disclosure of private information if the situation is not remedied.

    --
    I am Bennett Haselton! I am Bennett Haselton!
  78. Now what school? by MATTtheROGUE · · Score: 1

    I'm too lazy to log in;
    but which school did you say you went to?

  79. I work close with my school. by desalien · · Score: 1

    Schools just SUCK when it comes to IT I myself am 16 years old, and live in Belgium. @ my school we use winXP boxes for CAD-programs (robodraw) and NT4 for the typical Wort/Expell lessons.

    Security is good, but not everything. We have 2 save our CAD drawings to the HD wich is not pw protected. Everyone can delete or change the drawings I made, i solved this by saving my drawings on my own comp @ home by using my ftp-server. No1 can get them there :-P
    Other students don't have these tools or such -> their documents and files are insecure.

    Back 2 the topic, in my school no student information is stored on the computers!
    Administrative documents and all of that kind are on a different network (TISK for students TISP for secretary and stuff) and there is no connection between them. We have Wireless also, no protection at all, just drive your car next to the building and your laptop will say: Network Connection Established and you can browse the entire TISK network. BUT there is nothing 2 see over there!

    And indeed, tell the admin over there everything trough a good spelled mail (not like my English). If you come with solutions or possible improvements use the words 'I think it is better ...' or 'It might be better'
    In this way I convinced my school to try Open-Source with OpenOffice as they are always promoting Oxfam (don't know if that's in America) and FAIR trade stuff, this is the right way 2 go! I told them about Open-Source & bla bla bla, and they stepped into the project with me.

    (The admin told me it would take weeks to install it on every computer - - - It took me 1 hour to install OOffice on every computer in 1 classroom, due to slow computing power :-P)

    btw, this is my first Slashdot post, sowrry fo sukcy engglisch

    --
    make install, not war