Skip to content or view screen version

Oxford Uni Network Hacked

ciderpunx | 16.07.2004 15:19 | Technology | Oxford

2 student journalists have managed to break into the University's computer network.

Two first year students at Oxford Uni have managed to break into the computer network, while investigating it's level of security for a Student Magazine.

Patrick Foster and Roger Waite were able to retrieve email passwords, listen in on MSN Messenger conversations, and even view live CCTV camera footage.

After they contacted the University, the authorities, rather than thanking them for revealing potentially dangerous flaws in their IT setup, reacted in typically draconian fashion, summoning them to a Court of Summary Jurisdiction, where they could be fined up to £500 and suspended from the university (known as rustication). The case was also referred to Thames Valley Police. If they had not contacted the university authorities, it's unlikely that their activities would ever have been exposed.

If people who test networks responsibly are treated in this way, the University can never expect to improve it's security - those with more malicious intentions are hardly likely to own up to their activities!

Students have the right (not least in the light of the Data Protection Act) to have private information kept secure - the University have failed them. Students should encrypt all information held on the "swiss cheese security" university computer system using a known safe copy of gpg -  http://www.gnupg.org/ (pgp for M$ windoze users  http://www.pgpi.org/products/pgp/versions/freeware/winxp/8.0/ )

Here are the links:
 http://www.oxfordstudent.com/2004-05-27/news/1
 http://www.oxfordstudent.com/2004-05-27/editorial/1
 http://slashdot.org/article.pl?sid=04/07/16/021200&mode=thread&tid=126&tid=146&tid=172&tid=99
 http://www.guardian.co.uk/online/news/0,12597,1261609,00.html
 http://news.bbc.co.uk/1/hi/education/3897755.stm

ciderpunx

Comments

Display the following 9 comments

  1. MS weakness — Journo
  2. pegasus — cat /dev/null > /bin/win32
  3. Education — sas
  4. Responsible behavior — IT support
  5. cat /dev/null > /bin/win32 — manic depressive
  6. hack? bollocks — ben
  7. re: cat /dev/null > /bin/win32 — srm -f /bin/win32
  8. re: re: cat /dev/null > /bin/win32 — manic depressive
  9. Computers — I can't believe any of us came here to air our stupid views!