4 ms·
Lesson learned. Keep vulnerabilities to your self.
by pknopf 7y ago
Lesson learned.
Keep vulnerabilities to your self.
- colechristensen 7y agoMeh, anyone who knows anything would look very positively on a kid who had the curiosity and ability to do that and suffered ridiculous consequences. The suspension is a badge of honor, a great story, and generally a life long benefit. When I was in high school a few of us grabbed passwords from unencrypted wifi/network protocols (maybe it was POP3 logins, I don't remember) and "reported" it with some harmless website defacing, telling the admin (who was a cool guy). Nothing happened and I don't think anyone ever even noticed.
- busterarm 7y agoFunny, I was nearly expelled from my high school for finding and immediately reporting a vulnerability, without having actually exploited it. Also my story is far too common. Most of the people in charge don't know anything! Many of us in the industry who have been around the block a few times support either selling your exploits or open disclosure. We have our reasons.
- leeter 7y agoI had a friend that noticed some really nasty vulns in his college's software (passwords in plaintext in the page, and the reset question and answer). I coached him how to very carefully report them and he had some help from family. But given that the uni takes federal funding he could have easily landed a federal felony for just reporting, and all he did was do view source on the page.
- munk-a 7y agoIt depends how much your school throwing the book at you derails your life. I agree that white-hack vulnerability discovery should be celebrated, but right now even ethical hacking can have severe penalties on opportunities available and your mental state. This even extends into victimless[1] hacktivism. (@see Aaron Swartz) 1. This is my opinion, not a declaration of fact.
- Spooky23 7y agoAll depends on the individual you are reporting to. It can get worse. My brother had a classmate who ended up being subject to pretty intense investigation for something similar, mostly because the IT guy was incompetent and characterized a problem in a certain way. He wasn't charged, but it cost his family a bunch of money. I would advise anyone to never volunteer anything of a infosec nature in a public school environment.
- rootusrootus 7y agoOr just go public instead.
- smarks 7y agoI don't think this case follows the usual story of "person reports vulnerability and is punished for it". See my other comment for details and a link: https://news.ycombinator.com/item?id=20709592 https://news.ycombinator.com/item?id=20709592
- earthboundkid 7y agoThe lesson I learned in school was it’s obvious that you’re the one who exploited the system when you’re the only computer nerd who uses the machine.