The Great Firewall of Yale
162.209.96.128
162.209.96.128
They claimed I was creating excess load, which is silly because if they really did the math, given how many people were using my service I was probably saving them resources.
There is no market in which you have to compete against the new (superior) competitor so the only tool you are left with are fallacies like referring to regulations and proper protocol.
See http://en.wikipedia.org/wiki/Crony_capitalism for details on political abuses, and http://en.wikipedia.org/wiki/Barriers_to_entry for examples of these fallacies.
There's no such thing as open market as long as there is also government and regulation (not that government or regulation are bad or anything).
But you're right, they're not the only tools. They're just (unfortunately) the strongest ones for those than can wield them.
Also this incident makes Yale look really bad... This could end some careers.
The result? An even older version of PeopleSoft (which apparently is Oracle's second-tier offering) than what was being sold to other universities in prior years.
It's barely useable at all. It's utter shit-ware. The prior in-house system, which was early-90s HTML presumably layered over 1980s mainframe software, was MUCH better.
Personally, I am convinced that this was a MASSIVE kickback scheme. Tens of millions, possibly hundreds of millions, have been stolen from the State of North Carolina, and people need to go to jail for it.
IIRC the project actually did get a special appropriation from the NC legislature, but don't quote me on that.
This isn't just incompetence, I think it is actually a cover for massive fraud. I know, always blame things on stupidity if you can... but from what I know, no, you can't in this case.
I wish some enterprising journalist would hurry up and investigate this... could net them a Pulitzer or something. That is why I am posting this comment.
zaidf, if you didn't realize this already (and you probably did), when you made your alternative portal, you were fucking with some very powerful people.
Meanhwhile, UNC has also been uncovered as using the Afro Studies department to hand out free grades to athletes for decades. There were hundreds of courses and grades listed that literally did not happen. Fraud is absolutely rampant at UNC. Maybe that's why our new Chancellor left after like a year? The state of NC needs to completely clean house.
I'm also well aware of the grading scandal as I still run a grade distribution site called blinkness.com which is heavily used on campis(even though I left unc years ago). We have a feature on the site called "Top A classes" and the professor in question always ranked very highly :)
Side note: those of you building apps aimed at specific industries, consider education (both K-12 and higher ed). As I said, I was at a .edu for ~8 years and, in my current role, I deal with a lot of K-12 schools. Both will spend outrageous amounts of money for decent software applications.
[0] coursegrapher.org
IE, could I mirror deep-level sports statistics without attribution? One would think the agency I "took" it from had applied meaningful resources to extrapolating this data, which may be in fact be statement of fact.
I'm purely playing devil's advocate.
See: http://en.wikipedia.org/wiki/Copyright_law_of_the_United_Sta...
But then there's the separate question of why Yale wants to do any of this.
I suspect that providing easy/effective access to course and professor ratings trampled on some feet. Somebody's course enrollment is hurting and making somebody look bad.
It needs to be an arrangement or presentation that involves a significant degree of creative choice, not an arrangement that is obviously inherent in or determined by the facts themselves. (For instance, an alphabetic arrangement of terms would obviously not be copyrightable either, but the order of a list of buildings ranked by prettiest might be).
The individual sports statistics are definitey not protected by copyright -- nobody can require me to get permission to tell you that Joe Blow has an RBI of X. But if you copy the entire database of sports statistics from someone, and present them in the same order/categories, those elements (selection and arrangement) _might_ be copyrightable -- it depends on the specifics and how well the lawyers make their case that the particular selection and arrangement involved were creative choices, not just obvious in the data itself.
In the U.S. , that you "applied meaningful resources to extrapolating" is completely irrelevant to copyright -- that it took lots of resources to assemble purely factual information still does not make them copyrightable. This is known as the 'sweat of the brow doctrine', and the courts in the U.S. decided that it did _not_ apply to copyright here. http://en.wikipedia.org/wiki/Sweat_of_the_brow#US_copyright_...
D&B and Lexis-Nexis have aggressively defended the copyright status of various aspects of their respective databases of facts, for example.
Say you had an public online store selling products.
Could somebody take those prices, aggregate them and let people see?
My understanding was that you can sue over that and that sites like Kayak or CamelCamelCamel used APIs.
Can anybody comment on whether this is
Note that Yale's complaint included concerns over "the prominence of class and professor ratings", and the student developers' response was to remove "the option of sorting classes by ratings". Subjective five-point ratings can be useful in many contexts, but in the context of education they can also give rise to genuine pedagogical concerns about the way in which students choose their courses.
Looking at the screenshot in the post, it is not difficult to see that the pattern of enrolments might very quickly become skewed towards those classes with higher average evaluation ratings (whatever such ratings might mean). If that happens, it suggests that some students may be making decisions about the courses in which they enrol based principally on factors other than their interests, abilities and future career paths, or without critical thought. Whilst other factors are relevant, including those for which an average of subjective evaluation ratings might be a plausible heuristic, that does not mean those factors should be the primary or predominant factors.
Without seeking to defend or condone Yale's response, there is more to the story than the tale of student censorship presented in the post.
Yale owning both the data and the interface is understandably important to them, though this might be an opportunity for the creators to work with the administration to reform the current system.
Many rankings are indeed subjective (books.. classes.. movies) - in fact that's rather the point: to render ones opinion.
If Yale prescribed to your notion of higher education, each student would be handed a list of pre-determined courses that he would have to take each semester. Instead, Yale students are allowed to chose their own courses/majors, and in some cases are allowed to create their own majors. Why? Because "choice" is the underpinning of the liberal arts philosophy.
So, within this context, I believe that I should be able to use a well-designed course listing platform as I am considering what courses to take. Especially at 58k/yr.
Still, this is a stupid move by Yale.
... not that that constitutes DPI either.
DPI specifically means examining the payload of the packet. This is not DPI.
I'm with the parent, I doubt they're doing DPI here.
There's a million other reasons to use https as well.
The way to get around transparent proxies is to use HTTPS btw.
http://www.aarongreenspan.com/authoritas.html
Some things never change.
Some things just make sense to do at national scale, even if there are a small minority who don't appreciate the benefits.
Many University networks are intentionally pretty open on the inside. Last I was at Uni, for example, CIFS was not blocked. CIFS is a common vector for malware to spread across a network.
So, blocking access to known malware hotspots works as a form of preventative maintenance. With a student body of 5,000 you are virtually guaranteed to have a cohort of that archetype of user that acquires new malware on a daily basis.
Edit: Obviously that isn't a good reason to block THIS website, just responding to the general question of filtering in the first place.
You would think that the Yale administrators would know better than this.
This public shaming will be received as insulting and provocative, and the deans will attempt to assert their dominance through the courts.
Preventing students from accessing the website is neither the goal nor is it a desired side-effect -- the goal is intimidation and generating evidence of wrong-doing. It's a game of poker for the administration and they showed their hand, and now they're waiting for the OP to call their bluff. This will not end well.
Every censor does it from an honest desire to keep this terribly misleading information away from the unknowing masses.
I don't think Yale is blocking the service in a conspiratorial effort to stymie students, but from a not well thought out desire to babysit.
So it seems you've met a few Yalies? b^)
> "[Administrators' primary concern was] making YC [Yale College] course evaluation available to many who are not authorized to view this information,”
> "[Administrators also asked] how they [the site operators] obtained the information, who gave them permission to use it and where the information is hosted."
Edit: Agreed, I don't buy these are the real reasons.
The students would regain access to their data (I realize that it has now been e-mailed to them) and it would be a great example of exactly how Tor can help "bypass" censorship.
Either the user installs it or not, it's their choice.
I am in no way advocating this abhorrent system of 'security'. Simply noting that it is obviously done in the workplaces and in many workplaces. That it can also be done here under 'security' pretences.
Respectfully, I disagree. This is certainly possible, but from an operational perspective this would be a nightmare. Even setting aside the likely backlash that would follow in response to such a sweeping policy change, university networks largely consist of diverse, user-managed devices, and supporting a transition through such a change would have a non-trivial cost.
Individuals at their workplace do also have user managed devices, they also are 'outraged'.
Regardless of which option you choose, you are required to install another program (unless the OUI of your MAC indicates that it is a device other than a computer) which scans your computer for malware and any software which the university does not allow you to have, such as torrenting applications, and will not allow you to connect to the network until after your machine is cleared. This program must be running the entire time you are connected to the network or you will be disconnected.
As a student who works as tech support in the dorms, it certainly is a nightmare!
I've always been leery of the mitm cert, not only from the users' perspective, but also from that of the organization. If a rogue administrator used the cert to set up a "real" mitm for a local bank's site, I think the school would be on the hook for that. That's just one example; one could imagine other variations on that theme. Whereas, if the school simply acted as a normal ISP, that whole class of vulnerabilities simply doesn't apply.
It's not a technical limitation but a moral one.
Most corporate environments typically do not "proxy" SSL, I know this from experience administrating networks and later abusing this with an SSH tunnel on port 443 allowing me unfettered access.
I'd be very interested in technical details on how that's implemented if it is.
See the following link for the specifics ... but needless to say its easy to block SSL access with a transparent proxy or layer 7 firewall. (which based on the error page looks like a Palo Alto device which definitely can do this...)
https://idea.popcount.org/2012-06-16-dissecting-ssl-handshak...
Obviously I don't know for sure but I would venture to bet this block was more an automated response than malicious intent against the site.
The issue isn't that Yale cut off the sites access to the school's servers. The issue is that Yale cut off their students access to the site. Furthermore Yale and the site were apparently in dialog before the block, and Yale raised copyright concerns (probably bullshit, unless they were copying course descriptions or something like that (I suspect course descriptions were involved initially): http://en.wikipedia.org/wiki/Sui_generis_database_right#Unit...).
It doesn't seem automated, and if there was a DoS wouldn't they just go out and say so?
Could it be in order to govern the information, rather than "copyright" per say?
My thinking is that, from Yale's perspective, having a 3rd party (and especially a student) be the go-to source for course info might be a bad shift in power.
When it's all in good kind, it may not look bad, and even if it is well intended, there are a few problems that could arise:
- Bugs in crawling code causing some course information to be false, omitted or stale.
- Changes in OCI causing said crawler to keep stale data and fail to update. - Students complaining to Yale with wrong information.
all the way to the more paranoid:
- 3rd party maliciously falsifying information.
- Generel confusion as to which information is reliable, driving students to have a more, rather than less, difficult time finding and verifying class scheduling.
I'm all for net neutrality and strongly against censorship in all forms, but "playing devil's advocate" can't there be a somewhat "legitimate" reason to shut the 3rd party page off for Yale students?
Of course there can be legitimate reasons. If the 3rd party inserted wrong data, or did 1,000 requests per second, causing high load on the servers, then I would call it legitimate.
However, the ones you've listed are not legitimate, because of the term "could." Anything could go wrong. An editorial in the local newspaper could have wrong information about the courses, but that doesn't justify the university excluding that edition of the newspaper from campus stores.
Things go wrong all the time. Someone may have printed out an old copy of the schedule, and based decisions on that. Or left a page on the screen for a week. Which means the system must already have support for people using stale information. Anything else is unreasonable. So long as the additional burden is not substantially higher than background, I don't believe there is a "legitimate" justification here.
As for copyright, this sounds very much like like Feist v. Rural. Quoting from Wikipedia: "Feist had copied information from Rural's telephone listings to include in its own, after Rural had refused to license the information. Rural sued for copyright infringement. The Court ruled that information contained in Rural's phone directory was not copyrightable and that therefore no infringement existed."
[1] https://www.beartracks.ualberta.ca/ [2] http://www.bearscat.ca/
I hope I don't give the administration any good ideas here, but I would seem that they have a much more efficient way to disable the site.
Incorrect - universities are now a business, nothing more. You can have your free speech so long as it makes the shareholders happy. Having students confused and lost (or being unable to chose the best education for themselves) is a fantastic way to have them repeat courses in the long run.
Tertiary education is no longer what it used to be. It is now exactly the same type of delusion that women face in terms of having to be slim; or consumers face in terms of having to have the latest iPhone or what have you.
What's next?
If you're numb to it, then it's imperative that it is news.
Imagine when the headlines read "Millions killed in Nazi camps" and people said "This is not news."
the most shocking realisation for me about the Snowden leaks was how apathetic people were toward their own civil liberties.
"Israel/Palestine peace talks halt." "Not news."
"Millions die of malaria." "Not news."
"Armed robbery at the corner of Ellis and Leavenworth St." "Not news."
"Your kid flunked his math exam." "Not news."
Just because somebody chooses to use Nazi Germany as an example, does not mean that they do not have a point. It certainly does not make them automatically wrong.
Let me use one of the examples provided by Crito below.
So pretentious, did a teenager write this?
if my university implemented a scheme like this, i'd feel exactly the same way.