UK Teen Hacked 150,000 Printers
motherboard.vice.com
motherboard.vice.com
Particularly towards the end, s/he comes across extremely self-aware, and makes some salient points around the state of school CS education in the UK. It certainly resonated with my experience.
Fucked until Uni and not great then.
The RPi was intended to be low cost computer that kids could hack on similar to what happened with the C64 back in the day.
I'm glad it's being worked on, and I'm sure it will be better for those going through now - but if the subject of this post is in 'high school', s/he had none of that.
We had 'ICT', in which we learnt to operate Microsoft products.
The worst part about my school's IT classes was how we were supposed to officially document our progress by taking a screenshot of the work we did, printing it out, cutting it out with scissors and sticking it into our classbooks with PVA glue - like right out of primary school. The fact we were doing this right into Yr.10 just felt insulting - and surely a better demonstration of IT proficiency would be to maintain our work-logs in a purely electronic format? Isn't using a backwards format like (literally) pasted-in screenshots the antithesis of information technology?
In the UK you can do proper Computer Science in high-school at A-Level (ages 16-18), I did it myself - I'd describe it as a somewhat cut-down version of my undergraduate computer-science degree: we did briefly cover the basics of fundamental computer architecture, formal logic and logic-gates, database theory, and software development - the problem is that very few schools actually offer the subject (like 90% of schools offer ICT at A-Level, but I reckon less than 50% offer Computer Science) - and that's due to the staffing: if you can teach Computer Science for A-Level then you're going to be qualified to work as a software developer for a multiple of a typical teacher's salary. My only real criticism of A-Level Computer Science (at least when I did it) was that schools could choose between Pascal/Delphi, VB6, and Java - my school chose VB6 - possibly the worst possible choice considering both how antiquated it was (this was in the mid-2000s so VB.NET/C# were already well-established) but also, more importantly, how it's a poor tool for computer science because VB6 lacks class inheritance and instills bad habits (e.g. SQL concatenation).
When I worked at Microsoft in the US, they took part in a programme called "TEALS" where professional software engineers employed by MS and other companies (Amazon, Facebook, Google all have Seattle offices) are invited to teach high-school AP class computer science classes part time, and I understand it's proving to be quite successful. I think this system should be expanded to allow other industries to take part - I'd sure love to have given chemical engineering or architecture a try in high-school - and kids often need decent exposure to industry if they've yet to decide what they'll do at university and beyond.
No way, he could easily get his own lab in AWS and probably for not much cost since he is in Uni. Hell, buying used stuff from ebay or some other auction site and hacking those for legitimate research would also be a path. Medical devices are probably low effort, high reward.
I definitely get where he's coming from with not having peers interested in security. Message boards and chats only do so much, but there's ample knowledge out there to build a plan for how you want your life to go from this upbringing. Going to a few conventions (even alone) would probably do wonders for him in terms of making connections but those can be expensive.
Maybe we're missing something here, but I got the impression that this is an incredible time for talented people. I've learned all about hacking online - kernel hacking, remote exploits, DEP/ASLR bypass techniques, Kali Linux for penetration testing, exploit-db.com and Metasploit for inspiration, the great tutorials of corelan.be and other great minds and so much more - it's all there, readily available for free.
You don't even need a big budget to build a controlled environment - Raspberry Pi's, maybe some cheap routers and computers and you're ready to go.
What? S/He said s/he's in secondary school.
You can get certain AWS products for zero cost, for a year, but you need a .ac.uk or equivalent email address.
But I don't think the problem is not that society has problems finding interesting challenges for highly skilled young people like him. It's unfortunate his school doesn't have hackathons and other activities, but he's not dependent on such circumstances. I think his problem is that he doesn't recognize that he's in full control of his life.
I've talked with several security researchers who hack IoT gadgets and other things for a living - they write their own ROP chains, hack web applications and test software for airlines with very high security standards - and they told me that they take every talent they can get. They're getting 4 to 5-digit daily rates for penetration test gigs and are well-respected. So there's demand and there are great people who want to share their knowledge.
So my question: Instead of hacking printers, why not talk to companies who are searching for his talent?
I'm not defending the current state of CS education, it's really bad and decoupled from reality, but it's no excuse for gifted people to give up and justify blackhat hacking - which is just another word for being criminal.
Edit: Absolutely agree on the click-baity title!
I've always found these kind of comments unusual. How old is old enough? For me this usually came off as arrogant.
> the feeling of being superior is a common problem for all types of skills if you're young
I know plenty of people who still have that exhibit that sort of behavior in pretty much every age bracket. Arrogance doesn't correlate to age. It's kind of arrogant to say "You cant think that way, you're too young" too.
If you don't have debt, you have to prove you can already do the work required. I don't know where the idea comes from that software gets a magic exception to everything because 'potential'. Talent means you're already showing you can do what they want.
Over my high school years I was incredibly frustrated by the things I was taught in ICT GCSE and ICT A Level (at the time there was no computing GCSE/A level offered by my high school). And even now, I'm studying for a BSc in Computer Science and I'm surrounded by people who probably can't write a hello world application without getting help from a TA.
I find the state of things really ridiculous and I wonder whether all UK universities are like this. What frustrates me the most is when my professors are seemingly putting a cap on my grades. It feels like they are pushing everyone who is lagging behind up (past the 40% pass mark) and everyone who's doing exceptionally well down (towards the 70% mark). I'm guessing that it makes sense to retain as many students as they can and at the same time ensure that the course isn't too easy, but it seems incredibly unfair.
Also, what is up with the grading system? A "first" is 70%+, and as soon as you achieve that as an average you're indistinguishable from anybody else.
If you're really good, you have remarkably good grades and do interesting projects in your spare time. w.r.t. your understanding of unfair: Don't compare yourself to fellow students, because they are by definition average. If you want to profit from your advantage: do stuff, get connected with great minds, build projects. This will get you years ahead of your fellow students who are busy passing the exams. What about this incredibly unfair advantage? ;)
"People need to take their printer out of the public internet unless it's needed..."
I'm trying to think of a single reason that a printer would need to be exposed to the public internet in any way at all. Even a corporation sharing printers between offices surely would rely on inter-site VPNs rather than just opening ports and exposing the printer to the world?
If anyone can think of a good reason to put a printer on the internet I'm all ears because I'm struggling to think of a good reason.
Credit to the teenager for not doing something malicious and in fact just being a little playful with it and educating the owners with a cheeky print out. Good work, I hope he can do well going forward and get a career from his skills despite his worries about grades etc.
Is Port 5222 required inbound for the print server? No, only 5222 outbound is required.
443 TCP (HTTPS), with connections to: https://www.googleapis.com/* https://accounts.google.com/* https://www.google.com/cloudprint/*
5222 TCP (XMPP, using STARTTLS), with a persistent connection to: talk.google.com
There are hundreds of thousands of printers, mostly at Universities, that can be installed just pasting their WAN IP address into the Windows "Add Printer" wizard...
I was also very tempted to just spam a bunch of gibberish to the printer on the network labeled "Presidents Office", but decided that might raise a few red flags.
¯\_(ツ)_/¯
Anyone else found this part a little bit sad and somewhat disturbing?
Used to be very convenient that I could send off a few documents to print before I left home at morning, and have them waiting at the printer when I arrived at campus.
Even after they added "swipe your card to print" to reduce waste, using plain old lpr to the printer IP still worked (it even cut in front of the queue, to much grumbling from the chemistry students we shared computer labs with).
I know exactly what he did, and the only reason I didn't do it myself was because I didn't want the inevitable legal problems.
Best of luck to this kid, because as smart as he is, and as destructive as this isn't, the law takes a very dim view of taking over other's equipment, even if it's wide-open.
Up until sixth form college, it's pretty much 'how to use Microsoft Office the class', with programming being mostly non existent and even coding in HTML being rare in a lot of cases. So anyone who doesn't study IT past the age of 16 or have an interest in computers outside of school is likely going to be absolutely clueless in regards to how to use a computer.
Once you're in sixth form college, it's then hardly any better, with the worst ones literally being 'how to use Microsoft Office, Access and Front Page edition'. So you could theoretically get away with not writing a single line of code until university, despite doing 'IT' as much as humanly possible.
Add the lack of extra activities, and well... anyone who's done programming at all may as well skip GCSE and A level IT altogether, since it's got absolutely nothing of value to someone with even the simplest computer skills.
Thank god you don't need a degree to get work as a developer in this country. Otherwise we'd have barely anyone interested in programming at all.
He's also right about the internet of things being a security disaster... but hey, absolutely everyone with experience in this stuff knew that already.
That said, he should probably get out of this blackhat stuff now rather than later, since it's very likely he'll be caught and end up facing a pretty long prison sentence at some point in time if he doesn't. Especially when you realise most people will see what he's doing here and think it's somehow as serious as breaking national security.
edit: I feel like in small startup offices not locking your computer is a subtle sign that you trust your team, but this might be just my weird interpretation
Compare that with the internet where everyone is just as far away as anyone else, you can automate the malicious actions, and attribution is a pain.
A classmate got hosed for doing something very similar years ago.
What a bummer. When I was a kid, I was nowhere as skilled as this guy, but I was online a lot and talked to a fair amount of people whom I would consider friends.
It seems that today, it should be even easier to reach out and connect to people with your shared interests, especially when those shared interests are effectively marketable skills and ought to translate into job offers out of high school.
https://arstechnica.com/security/2014/02/dear-asus-router-us...
but with printers?
javascript:window.location="http://news.ycombinator.com/submitlink?u="+encodeURIComponent((document.location+'').replace(/.utm_.*$/,''))+"&t="+encodeURIComponent(document.title)[EDIT:] ok moving that parenthesis and avoiding the update of document.location didn't take me too long...
He's not broken, the school system is.
I hate news organizations using curse words. Don't get me wrong, using curse words is completely fucking fine, but it's weird in the worst way seeing news organizations using these words, they're supposed to carry a voice of impartiality. It's extremely unprofessional, and it seems overly emotional and petulant to use curse words. The Vice is absolutely one of the worse offenders of this.
While Vice does run some good content, calling them a news organization is hardly accurate.
"Javasript is sooo broken.. the world is unfair", "Iot is sooo shit...", "Language X is soo bad.. thanks Obama", "Framework Y is soo 2016...".
Thousand people are trying to make a difference in the world and the ones just writing articles about "XY is shit" do mostly nothing. News about bad, bad "IoT", are so low hanging fruits to click-bait. There is almost never a constructive appraoch. Just complain and generate clicks.
Where are the leading ideas to make "IoT" better? Where is the differentiation, that open printers installed by stupid users are not a prove how "shit" IoT is?
You might also say the "internet is shit" because there is major dataleak happens every week.
... just my 2 cents...
Xerox is not a small startup that just wants to make printing easier. Even if it was, at least some basic security practices should be considered.
I mean i'm here writing a dinky little website using SQL and golang (i am a newbie at bout) and I am sterilizing inputs to make sure that SQL injection can't happen. Meanwhile the United Nations(!!) website has been exploited by same. There's even a defcon(?) talk about how a firm was hired to asses the security of that UN website and when the guy sent them an email saying that it is vulnerable to SQL injection, they responded by threatening him to never do that (year later it wasn't fixed). Wish i could find that talk.. it was great. Then there is the Technicolor router (big company) that my cousin has, that i just googled to find it vulnerable to all kinds of things and just horrid in general. Then there is ...
For a large class of cases — though not for all — in
which we employ the word meaning it can be explained
thus: the meaning of a word is its use in the language.
---Ludwig Wittgenstein