Oxford May Suspend Students Who Pointed Out Network Flaws
from the shoot-the-messenger dept
Stories like these are way too common these days. Two Oxford University students, working for the school newspaper, figured out how easy it was to break into the school's network and access private student data. They wrote up a front page article on the vulnerabilities in the system, and were promptly handed over to the police. The police told the university to handle it internally, but Oxford is now looking at suspending the students and potentially fining them as well. Of course, there's no word whatsoever on whether the university actually patched the holes in their system. Why is it that so many people who point out security vulnerabilities are immediately accused of criminal acts? This only gives good people the incentive not to find and point out these vulnerabilities -- but you can be quite sure that those up to no good are already exploiting them.
12 Comments | Leave a Comment..
- DailyDirt: Autonomous Vehicles
- How Publishers Repeated The Same Mistake As Record Labels: DRM Obsession Gave Amazon Dominant Position
- Park Ranger Tases Guy Walking Dogs Without A Leash
- Brazilian Government Ordering Web Hosting Firms To Kill Domain Names They Don't Like
- Syrian President's Email Hacked... His Password Was 12345





Reader Comments (rss)
(Flattened / Threaded)
...
The point of full disclosure is to get the word out to others whose systems may be vulnerable. Telling the world about local problems before anyone can fix them is downright destructive.
[ reply to this | link to this | view in thread ]
Is it really not clear to you?
Pointing out network or software vulnerabilities to internal administrators who can fix them is GOOD. Shouting them from the rooftops or putting them in print is BAD...it's the equivalent of a bank employee handing out keys to the vault to anyone who passes by on the street. And if you don't want to get handed over to the police, simply avoid breaking into your school's private files and accessing confidential information.
As a network admin with some experience in this area, I'll share a little secret: Well-meaning people don't spend their spare time trying to find vulnerabilities in someone's network. If they do, they're getting paid for it by the network's owner. And for that rare Internet Robin Hood who is the exception, they still wouldn't publicize their findings without notifying the powers-that-be beforehand.
Your moral compass is due for some recalibration, man...
[ reply to this | link to this | view in thread ]
Re: Is it really not clear to you?
An insecure system is insecure period. Obscurity is not a valid security policy. In addition the students were working on the school paper. The lesson they are liable to learn from this incident is that investigative reporting does not pay. Not a lesson any school should be teaching.
[ reply to this | link to this | view in thread ]
To the first two reponders:
[ reply to this | link to this | view in thread ]
It happened to a local school system here
The school shutdown the network, set the access to closed, and now all the parent volunteers can't access it, including the network admins.
No police were called. It must be the type of culture in England to treat whistleblowers differently (they even made a movie about it where the whistleblowers are blown up in the end)
[ reply to this | link to this | view in thread ]
The "Oxford Student" article
University IT network wide open to hackers
[ reply to this | link to this | view in thread ]
Morally wrong
Publishing their way of getting into the network is wrong. Had they gone to the administration & reported it, I highly doubt they would be in the trouble that they are in.
[ reply to this | link to this | view in thread ]
Re: Morally wrong
1. They did tell the administration before publishing the story.
2. They didn't publish *how* they did it, just that they had done it.
[ reply to this | link to this | view in thread ]
No Subject Given
[ reply to this | link to this | view in thread ]
because....
[ reply to this | link to this | view in thread ]
Re: because....
[ reply to this | link to this | view in thread ]
Big Brother loves you ...
Report to the ministry of information for reprogramming.
Big brother loves you ...
[ reply to this | link to this | view in thread ]
Add Your Comment