15 ms·
Winning a hackathon, losing my sanity
- simonw 3y agoBad title, good article. It's about exploiting security flaws in a university meal accounts website to build a Spotify-wrapped style summary of student's eating habits.
- Retr0id 3y agoWhile they point out some flaws in the guest permission granularity, did they actually exploit any flaws, to make it work? My understanding was no.
- neltnerb 3y agoIt seemed to me like they actually got explicit consent to have guest permissions to view this information, I am honestly pleasantly surprised. Once I saw them looking at the security tokens I got worried, but they pulled it out of a tailspin pretty quick. > Because we can’t instruct students to copy-and-paste the URL (and thus their session key), we needed another way to access students’ transaction history. We turned our attention to JumboCash’s guest access feature. I am going to take "can't" as "were not willing to" which is more impressive. It sounds like they could pretty easily have convinced people to give them a lot more access than they realized, and chose not to go that route.
- hunter2_ 3y ago> I am going to take "can't" as "were not willing to" I disagree. I take "can't" as a reference to this earlier statement: > Change to another IP address, and it…breaks? I.e., they would need to not only ask for the key, but also use the same IP address that the key was generated with. Depending on what sort of NAT may or may not exist on campus, that could be difficult or easy.
- deleted 3y ago[deleted]
- jprete 3y agoI clicked through and skimmed for "losing my sanity". I didn't find anything - total clickbait headline - but it was interesting to note the utter lack of reasonable ACLing in the university's campus food-ordering system, as well as the social engineering "attack" of posing as users to post their project and get actual users to try it.
- reactordev 3y agoThe loss of sanity I reckon was when they found out about all the backdoors and lax security the old system had. Incrementing int for id's, the session key being part of the url as a parameter, the XML. This may be something you're ok with but for those of us who care about security, this would drive me mad as well.
- busterarm 3y agoState University of New York used to famously use students' Social Security Numbers for their student ids up until around 2005. That student id was printed on your student id card and used for just about every system on campus. They finally changed that system after lots of scams/fraud perpetrated against students brought the practice to media attention. Wild.
- bredren 3y agoI believe it was the same situation at Oregon state, around 2003. Perhaps it was easier for the ID vendor to key against a registrar db.
- reactordev 3y agoWow... That's definitely worthy of a daily wtf.
- bcrosby95 3y agoThis was pretty common. I went to two schools that did this in the late '90s and early '00s. T'was just a different time.
- 3y ago
- avg_dev 3y agoCool breakdown. A few thoughts: 1. I would never be so brazen (brave? have the guts?) as to try all of this. I would expect to be rate limited and throttled or banned or get a nasty letter from a lawyer or something. 2. The HTTPie thing was interesting. I am still not quite sure what that application is, but I am definitely going to stick with curl now. 3. They demknstrated a number of interesting strategies unrelated to tech per se like registering that new domain and getting people to add them as a guest account and making those fake posts on what I presume is a university message board type thing. I bet this is how people who are good at stuff like “growth hacking” or developing engagement numbers and such work. Pretty clever. Still makes me feel a bit uncomfortable. A cool story. I was hoping the demo image would say “you at $300 of omelets” but I guess it is probably not that fine grained?
- crazymoka 3y agoReminds me of a fun project I did in 2005. I made a course schedule generator that once you picked your courses it showed price comparison of text book prices from local university bookstore and amazon. I made a bit of money before receiving a lawyer call from the university. Funny part was, they could have used our course scheduler for students but no, they wanted students to still hand pick their classes one by one. This let you block off times you didn't want class and it would make a schedule around that. Reason was, "students might think they are registering for their class when they are not". We had an alert stating we didn't actually pick the classes and to log in __link__ to start. had the same warning everywhere. I lost the battle. :)
- lubesGordi 3y agoI'll be less nice than you and say I'd be pretty mad if I was building something legit but lost out to a project like this. You not being brazen to phish all your fellow students just means you're not an asshole (and I thank you for that).
- tr3ntg 3y agoPlaying devil's advocate here... university systems feel like a great place to poke around recklessly like this. Especially when presented publicly. Any holes in the system that enabled such ease of abuse should be patched up. I don't know the author but would guess these hacks would never be used "in production" or with any system expecting to earn money. They're pretty blunt about how hacky it all is, and they don't sound happy to have done it.
- rjbwork 3y agoCool project and write up. An aside - while I love the snark and making fun of these "legacy" systems, it has given me a window into my own maturity as an engineer. I was absolutely this cavalier and cocky about poorly implemented systems I've been a user or admin of in the past. But having now spent nearly a decade and a half getting paid for this work and seeing a lot of stuff and the evolution of best practices, I have much more empathy for the organizations and authors of these systems. There are very very few programs that ever achieve something like elegance and beauty when they collide with the real world.
- ok123456 3y agoJudging from the javascript, they scraped. The system they were scrapping would have been cutting-edge in 2004-5. Keeping something running that long, duck tape and all, is no small feat.
- simonask 3y agoI totally get what you mean, and I feel kind of the same but in reverse: When I was young, I was totally making systems like this legacy dumpster thermal experience. A lot of this stuff is hacked together by young aspiring programmers just finding their footing, often grossly underpaid, and with very little experience or formal training. Which is great, respect the hustle! But not so super when personal data is being handled. Luckily, it kind of looks like they maybe dodged that bullet in this case? Lesson of the day is: Use different passwords for each thing you log in to. :-)
- bigfatfrock 3y ago> A lot of this stuff is hacked together by young aspiring programmers just finding their footing, often grossly underpaid, and with very little experience or formal training. Which is great, respect the hustle! But not so super when personal data is being handled. Luckily, it kind of looks like they maybe dodged that bullet in this case? This is an odd generalization to me - are the massive mainframe COBOL systems handling personal data at banks to this day, "hacked together" by underpaid young programmers? I'm sure they were underpaid... but inexperienced with no formal training?
- caseysoftware 3y agoGreat line: "The portal is really a wrapper around the reanimated corpse of much older software, its rotting flesh visible through nonsensical decisions and the occasional XML response."
- tr3ntg 3y agoSeconding this. A beautiful line.
- riskable 3y agoHackathons and programming contests can be fun. The world could use more but more importantly, more fun ones. Yeah, we need solutions in healthcare and government but that's so boring and the prizes are usually pathetic. We need more flashy and fun ones! Especially ones that give the entrants something like a month instead of just a few days to come up with their entries. It'd also be great if there were more hardware-development hackathons. Give folks three months to make some hardware or a robot that does X. Make the prizes worthwhile for adult professionals! Spending a month of your free time for the chance to win $5,000 isn't very enticing. Make it $50,000 or more and I bet we'll see some really fantastic entries.
- suddenclarity 3y agoI think you're just getting too close to regular grants for research and development but with more losers. For example, Vinnova is handing out $5m for AI projects this year. Why participate in a contest when I can just get $100k from them by writing an application? In total, Vinnova handed out $300m last year with no follow-ups. That's just one organization.
- filoleg 3y ago> Why participate in a contest when I can just get $100k from them by writing an application? Because that grant comes with obligations and strings attached (which you gotta deal with, after your application gets approved and the grant hits your bank account). The whole idea behind grants like this is that you use it to start up a real company, and the grant-giver gets to be one of the first early investors in it (in case of success). With this in mind, most of the work on your project is also expected to happen after you obtain the grant. Hackathon winnings are supposed to be the exact opposite[0]. You do the work on your prototype on your own, you present, you win the prize with no strings attached, and that’s it. You aren’t expected to continue working on it after the hackathon as a condition to receive the prize (but you can of course, and you might even get encouragement and support from the sponsors/other entities at the event to do so). On a related massive side-tangent: I was sorely disappointed in hackathons back in college after going to a few major and local ones. Winners half the time didn’t have any even barely functional prototype and would gather wins off of powerpoints alone, half of them with proposals that wouldn’t even be feasible or possible to implement at all. A specific example that pissed me off at the time: the 2nd place winner at one of the Atlanta college hackathons I attended around 2014 was a team of 6 people with only a couple of devs. Their opening statement was like this: “none of us had any machine learning experience or knowledge until yesterday, but we learned it all in one day and decided to build an app that will tell you the full nutritional content of any dish you take a photo of, based on the food components in it.” First, I don’t think it is technically feasible to accomplish even in 2024. Second, claiming to have zero knowledge of machine learning and figuring it all out in one single day to the point of building a functional model that was beyond any cutting-edge research at the time was sussy. So naturally, I was excited to see what their prototype was. Turns out, there was no prototype and no code at all (which they easily admitted), just a powerpoint deck. Judges all fawned over it, and they won one of those “we are a startup accelerator and we would like to give you a grant to work on it afterwards to turn it into a real company, the grant is pre-approved and is waiting for you (if you are ready to commit)” sponsor grants. However, there was one time where I remembered the winners vividly (and the hackathon overall, as it was one of the very few that I would consider “proper”), because I was genuinely impressed by what they built, and felt it was very well deserved. I tried to keep up with what they were up to, as they continued working on that project in the open after the hackathon, and I am so happy I did. Spoiler: that team was the one that built WorkFlow[1]. Shortly afterwards, they actually released it in the App Store, and it kept growing over the years. It culminated into the team continuing to work on it full-time after graduating and getting acquired by Apple to build the improved native version of that, which is currently known as Apple Shortcuts. Which is an amazing tool I use all the time, and I am a bit surprised by how little discourse there has been about it in tech circles. Especially since it is clearly not abandonware, as Apple eventually expanded Shortcuts from iPhone to iPadOS and macOS, and it keeps being integrated into newer things Apple releases as well (like Home automation and plenty others). 0. Note: I am aware that a lot of hackathons now have similar type of “prizes” from some sponsors, where they give you a tiny (or often non-existent) cash prize and then offer to fast-track/pre-approve your grant application as a component of it. 1. https://www.michigandaily.com/uncategorized/mhacks-winners-prepare-launch-new-app/ https://www.michigandaily.com/uncategorized/mhacks-winners-p...
- jaflo 3y agoCool article and looks like a well deserved win! I like that the project was something fun and doesn’t take itself too seriously. And I liked the part about how they did Guerilla marketing too.
- NeoTar 3y agoIt seems there is a second story here about their University requiring the purchase of a 'meal plan' and that generally not being good value (costing more than the dishes individually)? Am I reading that between the lines correctly?
- suddenclarity 3y agoYes and no. It seems you're required to be on a meal plan. First-year students automatically (you might be able to downgrade) get a plan for $4019 which includes 400 meals and $75. Meals vary in price though. So if you max out on dinners ($14.97), in theory, you can get 405 dinners which would cost a total of $5974. In other words, a meal plan saves you $1955 vs buying individual meals. If you eat all three meals (breakfast, lunch, dinner), the average meal would equal $12.19. In other words, you'd get $4951 worth of food for $4019. To summarize, it seems the meal plan saves you money by giving you a discount. The problem (I assume) is that some students don't make use of their 400 meal swipes. https://dining.tufts.edu/your-meal-plan/your-meal-plan-options https://dining.tufts.edu/your-meal-plan/your-meal-plan-optio...
- Ensorceled 3y agoMy alma mater solved this issue by making the compulsory "meal plan" a credit for the campus wide system so you could eat in the residence dining hall (which was relatively cheap) or spend the credit at various food courts on campus (more expensive, but there is a Subway, McDonalds, etc. etc. as well as various non-franchised options). The second term, they added the credit on a weekly basis because a bunch of students had run out of credit before the end of the first term ... which, as our psychology department pointed out, was a completely predictable eventuality.
- Ensorceled 3y agoThe project calculates if the meal plan is good value FOR YOU based on your eating habits.
- nico 3y ago> Through some clever promotion on Ben’s part, we managed to get hundreds of students to use it in just a couple of days At the end of the day, marketing is just as important (or more), than the tech we build I won a hackathon this way too. We were the only ones who brought a printer to the event, we printed maybe 100 posters of our app with a QR code to use it, then we put the posters up all over the venue By the time to pitch came, we not only had a working proof of concept, we also had the data we collected from all the people who had already used it, so we were able to show traction in barely more than 24hrs We also spent at least 4hrs creating and rehearsing the pitch
- mprovost 3y agoThe ligature on "www" was making me doubt my sanity. I had to doublecheck that it's for real but it comes from the Berkeley Mono font.
- jessekv 3y agoWhat surprised me the most is that the public directory of all students and staff really is completely public. Anyone on the internet can use it to get names and emails of students.
- filoleg 3y agoI assume that is the case for almost all public universities in the US, or at least it was back when i was in college a decade ago. Also, those student emails listed in the directory aren’t personal ones, they are school-assigned ones, so I don’t think it is a major issue tbh. The only times I’ve ever got any emails sent to mine from people that obviously discovered it through the directory were from the recruiters (and those were definitely very welcome at the time).
- m3kw9 3y agoHackathons suck man staying up 36 hours to compete is some sadistic stuff
- guntherlaura73 3y ago[dead]