- There were a chain of human and technical vulnerabilities exploited
- MAC addresses can be changed – nearly all ethernet controllers and some wireless chipsets support changing the MAC address;
- MAC addresses are public knowledge. Anybody who ever receives a packet from your machine has your MAC address – and don't forget that Apple devices send tons of auto-discovery broadcast packets; and
- Anybody suitably competent to pull off the technical side of the attack is likely to be able to spoof MAC addresses.
It's worth noting that Knoll's letter also includes this gem of total misunderstanding:
"... date stamps are easy to edit. In fact, the photos you shared with me clearly include an "edit" button in the upper corner for this very purpose."
The article seems to me to be far more about low-burden-of-proof disciplinary panels – where the same people who set the rules interpret and administer the rules whilst trying to appear reasonable.
The fact that a "defendant" asks for a date and time of alleged incidents before submitting evidence is not at all "puzzling" – the alternative is submitting every photo over a months-long time-frame, which is certainly not reasonable.
Just to be clear.
Windows 10, MacOS and Ubuntu, all allow one to set/override their MAC address usually via a dialogue box.
I don't recall ever using a DSL/Cable modem that did not support setting/overriding the MAC address.
Just about every single DOCSIS network still in existence uses BPI+ to encrypt the traffic to each customer to make sure that you can't just sniff traffic for the entire neighborhood and steal service. BPI+ has a certificate that is minted and signed at the factory with the device's MAC address in it. If you tried to change the MAC address, even if you had root, you wouldn't have a valid certificate so the modem would never get a connection.
Protocol wise, a MAC address is fundamentally the choice of the client. And for cloning, they aren't even obscure but printed right on every device.
That this has to be continually re-explained to lawyers unfamiliar with technology, because they see some identifier and immediately assert it's immutable until rebutted, is getting to the root of the real problem here. An ethernet MAC is at best, circumstantial - acceptable for tracking down a lead, but means jack-squat when it comes to proof.
Furthermore, the fact that we're still going over this in a technology forum demonstrates the probable lack of competent diligence done by the school's IT department before presenting their "expert" opinion.
I'm guessing that the evidence they've got is that the IT dept have the MAC address that was used by the devices that connected to their network, and have associated MAC addresses with the IP addresses allocated. Then that IP was used to connect to their internal system to change grades.
It's pretty flimsy evidence, as anybody who had received a packet from her machine on the same network (i.e. if she ever connected to the university, which she allegedly did) would know the MAC address. So when I say it's public knowledge, I suppose I should've said it's public knowledge given you can connect to the same network. It really wouldn't be that hard to frame someone that way, and things like iTunes library sharing really help – because they conveniently tell you whose library is being shared.
It's quite possible that somebody who knew who she was and who knew her MAC address could have done this. That could have been somebody sat in the same class. It's also entirely possible that she had the technical skills to pull of the technical side of the hack (bypassing 2fa) and didn't know a thing about networking.
It also sounds like they have figured out the IP address that she has used to connect to her own university intranet account and found that it matched the IP that accessed the hijacked account. That's again pretty inconclusive.
From reading the article, the technical side of the attacks seems to be illegitimately using an administrators password. There are no details of how the hacker obtained the password, perhaps they just glanced over the shoulder of the library staff member as they entered it?
Even so, if she knew when she hacked the accounts she could create edited photos without them telling her when she hacked them (assuming she recalled when she did it)
If she were guilty of hiring somebody to do the hacking but not actually doing it herself, then she might not know when the sensitive times were and would therefore be unable to fabricate evidence covering the sensitive times. That's what you pointed out, however it's not particularly relevant. The possibility that she was the technically competent hacker who was capable of fabricating EXIF data is a strong enough possibility for the university to meet their low standard of proof, and consequently determine she's guilty.
Far too emotional and completely out of place for a Dean writing an official letter.
The glaring question is what evidence is there that this was not done with a remote-access trojan on her computer? The article says that other students' grades were changed, and I can think of no better cover than making sure the blame falls on someone else.
Very true. During my onboarding at Gatech, they clearly told us (in similar words): "Unlike courts, the burden of proof is on you, not on us. If caught hacking, you'll serve jailtime then come back to find us waiting."
By the way, the reason to retain a lawyer is so that you don't unwittingly say something that could create criminal liability. Nobody has a right to attend Tufts and as long as they follow their policies a lawyer or court is not going to stop them expelling you.
This is pretty normal for K-20 committees though, they operate as extrajudicial kangaroo courts that can easily acrew students out of their education and labor.
now that you mention it, that's a starkly direct conflict of interest.
The K-20 education sphere loves its kangaroo courts though, most LGBTQ+ people I know have been cheated of their high school diploma by this scam perpetuated by school administrators.
Don't be different in any way, lest an administrator chooses to boot stomp you amd refuse to acknowledge you ever took courses at their school.
I know one trans person who was set to go to an Ivy League school (incrediby adept at mathematics) that got outed and has been relentlessly harassed by both their parents and school.
I've been trying to encourage them to fire high school and go all Running Start, cause it ain't gonna get better wrt the school administrators being horrid. They likely won't graduate if things fail to improve.
Edit: This is in Seattle Public Schools proper, Bellevue, Northshore and other districts are on point about expelling those that cop to not being straight or cis. Its been painful to watch bright kids get needlessly ejected from the system that is supposed to provide them an education.
Shorter version: preponderance of evidence, which is usually the burden schools are most prone to adopting, isn't it?