Berkeley HS student tried to rig his own election, exposing cybersecurity flaws
berkeleyside.com
berkeleyside.com
My presentation would have just been "I pressed F10, and typed in bad words", but it would have been preferable to a three day suspension, haha. I hope this is the outcome!
As an idiot I used my account and immediately got suspended.
We were using winpopup to send messages to each other, when I worked out how to send them to the entire subnet (or domain - I forget). Three months later I was hauled in front of the Deputy Rector to explain how I managed to 'write my name' on the admin office server. It turned out that they never turned on the monitor connected to the print server until the printer stopped working and they jumped to blaming me.
It took some really fast thinking to wriggle out of that one - I was warned 'he'd be watching me' from then on though.
I'd launch that on a few terminals on my way out of the lab.
Never did anything notable with it, but didn't get caught either.
I believe this sort of thing is the primary reason for needing to ctl-alt-del to login to windows. Though I'll bet most people wouldn't think much of a (fake) login screen just being there ready to go...they'd probably try to login anyway.
Unfortunately, the messages were appearing... on the domain controller.
I think I got a detention and a couple weeks ban from using the computers. Fair enough.
I got a five day suspension for showing a teacher I could log in before accounts were authorized while they were watching. Loaded the school's official website in a browser. Best week of high school.
Those things removed all motivation for 'vacation.' No one wanted to get suspended.
I guess it's just being older that you realize school is a fake world anyway, and expulsion is not a real punishment except to the school's budget. The community college path is cheaper and better anyway.
Expulsion was a real punishment back then. It may be less so nowadays, I'm not sure, but when I was in high school, without a diploma it was very difficult to get any kind of job beyond something menial, and nearly impossible to get into any kind of higher education, including community college.
Then again, two generations earlier than mine, you could support a family on an 8th-grade education -- although an 8th-grade education a hundred years ago involved more than a high school diploma these days.
Obviously the answer is no. Sometimes, catching someone breaking rules/laws after the fact is sufficient - 100% prevention of a crime before it happens shouldn't be the only way crimes are avoided.
Did the school make some poor choices with their cybersecurity? Sure. But an open/unlocked door does not give permission to steal or break the law, whether that door is digital or physical.
If, as you suggested, you commit theft, engagement with the criminal justice system seems appropriate, but maybe not if you rigged a school election.
I don't think it's a stretch to think that HS students should know better than to cheat - whether that's on a test, or a school-wide election.
The biggest loss of all would be to put it under the rug.
"Johnny it's really KEWL that you rigged the election, but it also made us sad. Please don't ever do it again."
You attract more flies with honey than vinegar. Good luck to the society whom discourages young outside-the-box thinkers and bright minds from pursuing intellectual passions within STEM. This is a huge problem in the US and it's culture around education.
Treat everyone else as an individual and real person. If this were not what amounted to a pointless election and therefore a dumb prank, there could be real consequences. Some jackass screwed around with his high school election, sure, I don't think a severe punishment is in order. Suspension? Detention? Sure, whatever.
You think that individual's individuality is supposed to somehow put him in front of everyone else affected by his actions? Or is it the fact that someone is interested in STEM, that makes them special?
There is sometimes a victim of actions (in this case, other people running, other people voting). You write as if they don't matter or exist.
Having been one of them high school hackers, and having been both threatened with jail and simultaneously being given the carrot of "don't do it again, and tell us what you know," the latter is going to produce a better outcome and if the student chooses to pick the former... well you gave them an honest choice.
Most kids doing this aren't malicious, but just trying to learn and have some damn fun. If you just jump straight to the stick, you're just going to end up with a bitter kid with some cybersecurity chops. Not the greatest combination.
And that's the point. You're dealing with smart, misguided youth with a literal hacker mindset. You'd hope this wouldn't need explaining on Hacker News, but here we are...
Having been in this kid's shoes many beers ago, I technically committed major felonies. The District flipped a lid, mind you I'd been reporting vulnerabilities two years, when I gained access to their server with their financials and PII. Wasn't doing it because I wanted to sell my shit-heel English teacher's identity to Russian cybercriminals... no... I was having fun learning and discovering this fucking awesome world of computers.
Those of y'all acting as if this kid if a real piece of work need to check your outlook. That is some real "get off my lawn" stuff. He's a high schooler, and capable enough to pull this crap off. Show him the right path, turn it into a teaching (it's school, y'all) moment, and if he doesn't want to walk the right path then who are we kidding, a detention isn't going to change that outlook anyway.
The problem with your attitude is that you have become the authoritarian in this situation. The district wasn't interested in fixing their security issues (their right), and you didn't like this, so you went ahead and broke into their systems anyway.
"I was having fun learning and discovering this fucking awesome world of computers."
There are plenty of other ways to do this.
"He's a high schooler, and capable enough to pull this crap off. Show him the right path, turn it into a teaching (it's school, y'all) moment"
A teaching moment would be punishment. Maybe a suspension. In the real world, you can't just trample on others' rights, without some sort of repercussions.
Also a teaching moment surely isn't a suspension. That's how you burn any bridges towards getting the kid to learn. You said that in the real world you can't trample others' rights, well sure but it's kind of the point that high school isn't the real world. A teaching moment would be sitting someone down, getting them to admit/explain what they did, telling them that in the real world they would get in trouble, and pointing them towards a better outlet. Teach them what it means to be a white hat and send them on their way.
I wasn't holding anything hostage. I didn't tell them "Fix it or else." I'd been reporting vulnerabilities I'd been finding. Found more. Reported 'em.
> In the real world, you can't just trample on others' rights, without some sort of repercussions.
Sounds like you've never lived in the real world.
Again, it's high-school. You seriously have no idea how to incentivize this type of kid.
You're the one talking about how it's somehow your right to break into private systems, because muh learning.
This doesn't sound like the real world to me.
"Again, it's high-school. You seriously have no idea how to incentivize this type of kid."
Why should we? Why shouldn't this type of kid have to follow the same rules as anyone else?
The administration was already aware of potential flaws in their system, but chose not to fix it. These kids decided to exploit them anyway. If this was at a workplace, they would be fired at best and have a criminal record at worst.
No one is saying this.
> Why should we? Why shouldn't this type of kid have to follow the same rules as anyone else?
Why don't we punish 5 year olds as adults? Hint: answer is the same.
> The administration was already aware of potential flaws in their system, but chose not to fix it.
And now they will. Both are at fault. Both have blame. But we're saying "Don't turn these kids into criminals. Push them to use their skills in a way that can help our society (ie: security researcher). They're still young enough that they can change. These aren't hardened criminals we're talking about. We're talking about kids.
tldr: Kids aren't adults. Who knew this was such a controversial topic?
Even if it's not actually important, it's the perception of importance to the student that matters. The idea that "it's ok to commit fraud if I think it's something important" is definitely one we don't want becoming widespread.
The guy accessed other people's email accounts. The punishment for "hacking the elections" is one thing, accessing someone's email account goes way beyond that. So even comparing it to abusing a paper ballot system is not at all appropriate. It's comparable to someone opening up your mailbox, reading your mail, then sending some in your name. For fun.
Among countless other problems, high school elections promulgate the idea that there can be only one hierarchy, that there is a group of "betters" that should comprise that hierarchy, and that the only measure of merit in that hierarchy is popularity.
This story resonates somewhat with me as I was definitely a problem-teenager but have since mellowed out substantially, thankfully without ever encountering trajectory-altering consequences (although probably deserving to in some ways)
When I look back I simply wasn't engaged/challenged in the right ways and was looking for every opportunity to challenge myself - even pushing the limits of authority was a source of enjoyment and punishment was almost a reward for me: I never really responded positively to punishment and definitely didn't learn anything from them.
This became really obvious to me after I had the following observations:
- at high school I was highly disruptive
- at college I was fully engaged because the environment was academically challenging
- many years after at coding bootcamp I felt some of the old teenage urges to disrupt bubbling under the surface when classes were too slow (thankfully I know much better than to act on them now)
So I guess my point is that it feels natural to condemn the individual, but we really don't know anything about them or their circumstances, and with my educator hat on, I'd rather assume a misguided individual and challenge myself to find a way to teach a new lesson than opt for the easy way out and condemn them with some kind of heavy punishment (like expulsion).
Perhaps in this case some of the following may be useful lessons:
- some labour-intensive efforts that directly relate to cleaning up the mess of security breaches and election counting
- work on fixing vulnerabilities of the school network (if money were no issue, have the student try to protect the school against a pen-tester, in the hopes of establishing some empathy for the difficulties of being a time-poor underpaid school sysadmin, or at the least have some constructively directed black/white-hat energy)
- find some relatable issues on the morality / pain of vote rigging and have the student study them
Rehabilitation versus retribution.
These are young people, who deserve leniency and opportunities to make mistakes and learn.
With that said, he was also an adult making a conscious decision to fight the system. TFA is still a minor, in high school.
Swartz was an adult who decided to do something illegal that he believed was nonetheless moral and the right thing to do. (I agree with his stance, but doubt I would have the balls for such civil disobedience.)
This HS student is a child who committed voter fraud in a student election for his own benefit. Nothing noble about that.
I believe it is fairly simplistic to just say good/bad without understanding the nuances and shades of gray in between.
If the security problem is more subtle than an open door it's not unheard of to consult the criminal, who may be given a lesser sentence or other freedoms for helping make everyone more secure.
Of course in this case all of that is kind of moot. The rigging attempt was crude and quickly detected. Everything worked as it should, and while organizing an election brings a high burden of ensuring no manipulation occurs, everything was executed perfectly. The real problem was students not being forced to change their default password, which is akin to an open door, just from a different department.
So punish them by sending them to DefCon?
You mean like the administrators of the school? You can set a temp password to immediately expire. What's notable is that even after this incident they still didn't do so, just encouraged students to change the default password during orientation.
> The investigators were also able to determine that the false votes were cast from a computer
I bet the real votes were cast from a computer too.
I could have rigged the vote to win at my school too, except that I wasn't in the right cliques. It would have been very suspicious if I won, and everyone knew I was "good with computers".
Our program actually saved who voted for who in plaintext. At least I got to see who voted for me.
IIRC, my high school government was very effective at choosing the prom theme and lobbying for a specific brand of crackers in one of the vending machines.
https://tvtropes.org/pmwiki/pmwiki.php/Main/AbsurdlyPowerful...
Like Trump and the rumored pee-pee tape?
(Sorry, couldn't resist!)
https://www.bmo.com/olbb/help-centre/en/my-profile/change-pa...
https://www.theglobeandmail.com/technology/digital-culture/w...
I'm sure they're all stored in plaintext in an ancient mainframe system, but that's not the reason for the odd requirement.
- Password can't be long
- Password can't be pasted
- Password must contain symbols
- Password can't contain symbols
I even locked myself out of my credit card (AMEX) account 3 times in less than 2 days because they have multiple different password reset forms, but one of them doesn't enforce their password length limit, so I successfully set my password to a password that was too long for the web/mobile login forms.
Why is this such a common thing?
Short answer I suspect is old systems with complicated dependencies.Not only does anything digital has to be transferred over, but often customers have to be persuaded to agree to new terms, which is obviously a long, complicated process.
They also have legal legacy as the government will always grandfather old accounts when the law changes. So the banks may have special accounts that are obsolete but a few customers like the perks, that could live in an old system of their own.
Plus there are various deals they've made over time that might restrict one part of the company from doing some activity, any kind of international stuff is a total mess, it goes on.
All this means they have a ton of duplication and are constantly trying to merge their internal systems, on top of the normal awfulness of any non-tech company trying to do technology.
As a consumer, do shop around for someone who has good security practices, and point non-tech people towards them.
Theoretically, in any fraud you can get all your money back, but if the bank decides it was your fault, you have to take them to court.
In summary: there are a lot of third party products for interacting with banking data. Different versions between those products still in use. The need to enforce security based on the product/interface with the worst usability (ie: most restrictive set of functionality or most bugs to work around)
The talk specifically talks about Open Financial Exchange (OFX) as one of these legacy pieces.
Can't be pasted has changed more recently to my knowledge Can't be long is due to some OFX protocols limiting password transmission length (and sharing passwords between services in plain text!) Special characters are disallowed because some of those characters were control characters for the communication markup.
One recent example I had was with an online account that demanded a password reset. One of the requirements was "no two consecutive or three sequential characters". I'm still not quite sure what exactly it means, but it was tripped by any sequence of characters like "ab" or "21", and as a result, my generated 16-character password with no meaningful words in it was not accepted.
You know what passed the filters though? "secret_1".
Msft employees: change this!
(Or they were sequential with blocks for each class)
(Ex: many libraries use your barcode number as your username)
I suspect the mistake stems from not understanding how passwords are stored.
(Eg: while yes, well set up systems hash passwords, usernames or any other identifier paired w the password are in cleartext, and in many cases huge swathes of the userbase can access them)
For example, 7500-7600 was Middle School "A"; 7600-7700 was Middle School "B" and so forth. Within those chunks, we couldn't really discern an order, alphabetical or otherwise.
I feel very sorry for people in todays world who don't get the "everybody gets one free pass" on these things we did back in the day. I think we need a clear statute of limitations on some stuff done by minors and near-minors, regarding their future lives. Nobody is going to be eligible for election to senate or the law courts, or to work in federal or state bodies if we don't work out how to deal with this kind of thing.
That said, I am pretty sure rigging an election is a good indication you have need of some ethics. Amusing, but also not a good idea.
This ranks (in my books) with the recurring "we thought we'd make a film about a bank robbery without informing the bank or the shopping mall about it" type cock-up: Actions have (unforseen) consequences.
The usernames of our voting system were our 5 digit student IDs. And the passwords... same as the usernames. I wrote a puppeteer script that looped through 2000 IDs and voted for everyone. They tracked me down through my home IP address -- if there is a next time, I'll definitely use Tor haha.
EDIT: Yeah, the school's VP picked up on it because normally about 40% of the student body actually votes -- but this time it was 100%; plus when student's started signing into their voting accounts, it claimed they already voted. Not my brightest moment.
Reminds me of an interview question: How would you do a reasonably good job of randomizing an incoming stream of items, while minimizing auxiliary storage?
Things only get difficult if you need exact results OR start doing things to make it "look" random - breaking up long runs of one vote, that sort of thing. (which of course makes it look distinctly nonrandom to someone with a stats background)
I didn't mean randomizing the votes. Perhaps I should have written "shuffling." I meant randomizing the order of the stream.
1. The items come in a stream, so you have to accept each one in order.
2. You have to output a stream too.
3. You get a fixed amount of storage, much smaller than the stream.
4. The items are arbitrary and unique, so there is no way to compact n items into significantly less then O(n) storage.
If the stream is large and sorted, you run out of buffer before the input stream gets past 'A'. You're forced to output thousands/millions of entries in a row that start with A. That doesn't look at all random.
It seems impossible if I understand the problem. Is one of my numbered statements wrong? Is there a way to get items out of order? Put items back into the stream? Is there a limited range of items? Getting unique items in order lets me compress the data very slightly, but 25% more storage doesn't fix anything either.
7 (+/- 2) is the magic number. However, you make a good point. This is highly dependent on exactly how large the data is, and how "casual" the human are.
Even with a small size like 200 a shuffler that weak won't do a good job of turning sorted into unsorted, even at a glance.
That depends on how casual the inspection is.
This part was the most interesting revelation in the article to me! It never would have occurred to me as a HS student to "cheat on extracurriculars"! I just did the stuff that was interesting.
In my opinion these two have done us all a service by showing what could go wrong.
"If a student does not change the default password, “anyone with access to your student ID number will be able to access and delete your emails, schoolwork, personal documents and anything stored on your Google Drive,” Stern wrote in his message to the student body."