9 ms·
Teen Hacker Finds Bugs in School Software That Exposed Millions of Records
- deleted 7y ago[deleted]
- andybak 7y ago> But Gatsis also claimed that even with the security flaws he exploited, Demirkapi could never have accessed Follett data other than his own. Demirkapi counters that he "100 percent had access to other people’s data," and says he even showed Follett's engineers the password of the friend who had let him access his information. So - someone is lying. Isn't lying about the extent of a security breach a fairly serious matter? Blackboard operates in the EU. Is the disclosure portion of the GDPR retroactive? Of course - I'm not making any presumptions about which of the two parties is a liar!
- radicalbyte 7y agoHave you ever seen or used Blackboard? It's probably the worst "large" software system I've used outside of something built within an enterprise.
- nicoburns 7y agoBlackboard is awful. When I was at uni, I actually wrote a scraper to auto-download my course content so I didn't have to use the Blackboard UI. It's upwards of £100k/year too. Definitely a market ripe for a competitor!
- Insanity 7y agoAnd honestly, blackboard got worse over the years! They got a UI overhaul a couple of years ago and I hardly recognize it. But it seems like everything is harder to find than it used to be. Back when I was a SE student, we wrote an application for our university that students could use to access their examination schedules without having to look through the Blackboard calendar. Which was so much better, because you did not have to log in and it was faster than going through Blackboard's UI...
- jakejarvis 7y agoMy university switched to something called Canvas (right after I graduated, of course) and it's incredibly slick, on top of it being fully OSS. Sakai is out there too — the quality isn't much better than Blackboard but at least it's free! https://www.instructure.com/canvas/ https://www.instructure.com/canvas/ https://www.sakailms.org/ https://www.sakailms.org/
- veridies 7y agoI think most of the universities in California have been switching to Canvas. I also use Moodle, which is also FLOSS; personally I strongly prefer the UX to Canvas, but it may be less enterprise-y.
- moftz 7y agoMy school transitioned to Canvas from Sakai, it was like night and day in usability. I used Blackboard in highschool so even Sakai offered a major increase in usability. Sakai and Canvas seem easy enough to setup that I can't imagine Blackboard can continue making money for much longer. There's another system called LON-CAPA (written in Perl) that seems ancient compared the other competing systems. It was very easy to use and "just worked" but it felt like it was straight out of the Web 1.0 era.
- snarfy 7y agoExcept they have patents on 'e-learning'.
- LeifCarrotson 7y agoThe awful UI and pervasive install base shows that Blackboard's fitness in the market is not tied to their UI or other tech decisions. Building a successful competitor to Blackboard is not predicated on your ability to design a prettier, faster, more usable interface or a simpler, more powerful feature set. It's 100% based on your ability to do enterprise sales to universities.
- pbhjpbhj 7y agoJust because the incumbent lacks finesse doesn't mean you can 'eat their lunch' without having better features or a better UI. People need a reason to change the software they use; when it means retraining a district full of teachers then the reason needs to be good.
- LeifCarrotson 7y agoA better product may be necessary, but it's definitely not sufficient.
- pbhjpbhj 7y agoAbsolutely. Sometimes, unfortunately, you can get away with a worse product and better marketing!
- radicalbyte 7y agoIt's not just a bad UI, it's also extremely buggy. The problem is that the market is next to impossible to get into. They're like Photoshop - they've got an army of people trained in using their super complex UI. It's the de facto standard in the market; they've built a massive moat which will be extremely hard to get past.
- tracker1 7y agoIn the early 00's I developed a test LMS (SCORM) for courseware the company I was working for at the time was building... only because all the LMS software was a convoluted mess. That test LMS became the LMS for a few major airlines and a large fortune 50 company (uplifted through a few software shifts). It lasted for more than a decade before being replaced by an "Enterprise" solution, I think it was Blackboard (took 2 years to get it setup right, and people in the know still don't like it.
- skinnymuch 7y agoI think Rutgers in NJ used Sakai. As well as some other schools. It’s not much better but it’s far cheaper. Canvas is the new kid on the block. Even Canvas has issues though so it’s great as a replacement for Blackboard, but there’s still plenty more that can be disrupted and improved.
- gempir 7y agoWhen I was at school they were using Moodle. And I gotta say Moodle was very solid. The UI wasn't terrible and everything worked. But the big plus: Open Source and completely free to self-host
- Aeolun 7y agoSo it’s the worst software system short of 90% of the other stuff you’ve seen?
- albertsondev 7y agoI'd assume they meant "built within an enterprise" in terms of internal tooling.
- Izkata 7y agoIt's possible he got read-only access while they're saying he wouldn't have gotten read/write access. My highschool's records were similarly unsecured - I got a surprising amount of read-only access (including how much money was on students' IDs for lunch), but couldn't change anything.
- thrownaway954 7y agoI know SecLists Full Disclosure exists, but it is a shell of it's former self: https://seclists.org/fulldisclosure/ https://seclists.org/fulldisclosure/ What are other places can someone report a vulnerability that will get companies to actually listen and fix the issues reported? Is there a Google Project Zero for the rest of us?
- appleflaxen 7y agoWow! those numbers have really fallen. It's a bit off-topic for the larger discussion of this bug, but how come?
- wolf550e 7y agoI guess managed bug bounty programs
- Chris2048 7y agoPerhaps the dark-web should set up shop and bid with foreign/bad actors for these disclosure. Then these companies might care to put in a bid, and long for the days they could have gotten them for free.
- Aeolun 7y agoIsn’t it sad that the software we’re paying millions for has such elementary mistakes? Is this just a case of ‘Nobody ever got fired for choosing Blackboard’?
- burk96 7y ago"Is this just a case of ‘Nobody ever got fired for choosing Blackboard’?" Sadly I believe it is. My school recently moved off Blackboard for Canvas after at least ten years. While some teachers were relieved to move to a more modern system that supposedly offers them a better experience (it certainly offers students a better experience), many teachers rejected it as they did not want to learn a new system. My older instructors hardly ever post to Canvas besides updating grades saying they just don't want to learn it. Luckily for whoever setup Canvas at our school I don't think they will get fired over it, but the resistance from staff makes me understand why other schools would feel hesitant to switch off Blackboard.
- pard68 7y agoWe are moving to MOOC. We (sysops) are very pleased. Everyone else not so much.
- mieseratte 7y ago> Is this just a case of ‘Nobody ever got fired for choosing Blackboard’? I would say it's more a case of "Nobody ever got fired" As a former high-school hacker, I routinely reported major holes to District IT. No one gave a damn. Only once I started poking around private financial data did they raise hell, and even then it was "Show us what you have, tell us how you did it, and we'll let you walk. Otherwise we'll get the police involved." Handed over my laptop, the IT guy managed to play some Rammstein accidentally but otherwise found nothing of note. I was banned from bringing, touching, or even being near a computer, my assigned seating was moved in all classes directly to the front, and that was that. Kept in touch with a few of the tech-interested Freshman I knew during my Senior year, nothing was ever patched, nothing changed over the ensuing years. The exact same exploits I informed them of were not touched. There is simply no culture of accountability.
- sersi 7y agoWired should be more careful when saying "He did, in a separate incident, exploit flaws in a college admission software to change his admission status to "accepted" " when in fact he found that security vulnerability and immediately reported it.
- userbinator 7y ago10-15 years ago you would keep things like this quiet and maybe share it with your closest friends. Now it's like everyone is scrambling to show how "good" they are. Something has changed, and I'm not so sure if it's for the better...
- kossae 7y agoHow is disclosing critical security vulnerabilities responsibly a bad thing, again?
- flowersjeff 7y agoWould also like someone to perhaps chime in too... In the "good" old days (some of us will recall mind you), those in power ($) controlled all information flow. We now have (though not as strong as I would like it) outlets in which an individual, without corp sponsorship, can have their voice hosted and maybe heard. This is a vast improvement.
- userbinator 7y agoTo those wondering what I meant, I've heard the saying goes like this: "those who work in a noose-making factory should be wise to not make them too strong, lest they find themselves with one around their necks." It's not directly applicable to this instance, but more aimed towards those who are literally helping companies strengthen their walled-garden control. those in power ($) controlled all information flow. ...replace '$' with 'knowledge (of bugs, etc.)' and that would be more accurate.
- ColanR 7y ago> Something has changed It's like everyone is looking for approval, and in more public settings.
- mnoah 7y agoPeople are motivated by things like this, to do more and to achieve more. I am perfectly ok with people seeking attention for things they did to better the world. The opposite, not so much.
- throwaway-ehki 7y agoI think this is a space where concerned parents with technical knowledge can help, not by hacking, but by asking for documentation like proof of security audits from their local school board. It’ll up the pressure on vendors to get their act together.
- Conlectus 7y agoInteresting to see this come up. About 2 years ago I found a similar exploit in blackboard (XSS that could lead to session hijacking) and found that there was absolutely no way to report the vulnerability except through their help-and-support chat. After reporting it, they thanked me and said they would be in touch when they addressed it. I never heard from them again, and it seems they didn't take security much more seriously.
- save_ferris 7y agoHad a similar issue with Southwest Airlines a while back. I wound up emailing a VP directly with screenshots and repro steps by looking up other SW email addresses to figure out their work email format, and then getting the VP's name from LinkedIn. The VP responded pretty quickly, forwarded my email on his people, and I wound up getting some free miles. I was kinda surprised to learn how easy it is to get most corporate email addresses through this experience.
- rtkwe 7y agoThe public disclosure part is really important as it's basically the main stick forcing companies to actually fix things in a timely manner in any case where there's not a direct threat of financial loss to the company.
- non-entity 7y agoI once reported a similar XSS session hijacking bug in the LMS our district used in highschool. The response? Something along the lines of "hmm, maybe you just shouldn't do that"
- bsenftner 7y agoNow consider that for 10 years, minimum, these exploits have been known and easily discovered... enabling enough private data of high school students anywhere these applications were used to manipulate the students and/or more easily social engineer accounts at other institutions. The information gained undoubtedly contained social security numbers, parents full names and so on - the exact verification information used to "recover" lost passwords at locations not yet supporting multi-factor authentication.
- mariuolo 7y agoI'm surprised they didn't go Aaron Swartz on him.
- cantcomplain 7y agoMy school has blackboard for awhile now, I've always suspected it to be vulnerable but never really tested it. Particularly, you can make forum posts and view/edit the HTML that the WYSIWYG editor creates. This always made me feel like there's probably an XSS vulnerability there