Slashdot Mirror


Security and School - How Should One Speak Up?

AJ asks: "Well, in the midst of writing 1 of my 3 papers tonight, I realized how insecure my school's network is. It all started because I was upset about them changing from using my SSN to a proprietary number scheme for identifying students. I didn't think that was a bad thing, but I was wondering if they really were securing things. So, I needed a password to access a school resource from the internet. After a little of dabbling around, I found the place where I needed to enter my propriety school ID and password. As it turns out, the login form uses HTTP instead of HTTPS! Also, my school runs a wide-open wireless network that I always had considered a convenience, but now I am changing my passwords over that network! Oh, and that proprietary ID along with a password, lead right to a student summary page where my DOB, age, address and SSN are located. So Slashdot, what is a concerned student to do?" "I have made suggestions before with little results. Should I send an e-mail with an ultimatum. What should my after-ultimatum actions be. I was thinking that I could simply start to sniff passwords (18,000 students and quite a few use wireless) and then place them on my webpage at school. I wouldn't be so concerned, but this wireless problem, combined with a poor web design, has me freaked out. Has anyone dealt with this before?"

3 of 137 comments (clear)

  1. Re:Bad idea! by 42forty-two42 · · Score: 4, Funny
    Yeah...there are some people on Slashdot, but this guy is one of the dumbest I've seen yet.
    You're new here, aren't you?
  2. Platinum cards by aminorex · · Score: 2, Funny

    A few credit applications using the Dean of Students'
    home address and the names/ssns of ten or twenty
    lucky students would get some attention, I reckon!

    --
    -I like my women like I like my tea: green-
  3. bah by Maskirovka · · Score: 2, Funny
    Should I send an e-mail with an ultimatum.

    Nah.
    Just post the name of your school here and let the problem take care of itself.