National Post

Student expelled from Montreal college after finding ‘sloppy coding’ that compromised security of 250,000 students personal dataA student has been expelled from Montreal’s Dawson College after he discovered a flaw in the computer system used by most Quebec CEGEPs (General and Vocational Colleges), one which compromised the security of over 250,000 students’ personal information.Ahmed Al-Khabaz, a 20-year-old computer science student at Dawson and a member of the school’s software development club, was working on a mobile app to allow students easier access to their college account when he and a colleague discovered what he describes as “sloppy coding” in the widely used Omnivox software which would allow “anyone with a basic knowledge of computers to gain access to the personal information of any student in the system, including social insurance number, home address and phone number, class schedule, basically all the information the college has on a student.”“I saw a flaw which left the personal information of thousands of students, including myself, vulnerable,” said Mr. Al-Khabaz. “I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong.” (Image courtesy of safesolvent.com)

Student expelled from Montreal college after finding ‘sloppy coding’ that compromised security of 250,000 students personal data
A student has been expelled from Montreal’s Dawson College after he discovered a flaw in the computer system used by most Quebec CEGEPs (General and Vocational Colleges), one which compromised the security of over 250,000 students’ personal information.

Ahmed Al-Khabaz, a 20-year-old computer science student at Dawson and a member of the school’s software development club, was working on a mobile app to allow students easier access to their college account when he and a colleague discovered what he describes as “sloppy coding” in the widely used Omnivox software which would allow “anyone with a basic knowledge of computers to gain access to the personal information of any student in the system, including social insurance number, home address and phone number, class schedule, basically all the information the college has on a student.”

“I saw a flaw which left the personal information of thousands of students, including myself, vulnerable,” said Mr. Al-Khabaz. “I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong.” (Image courtesy of safesolvent.com)

  1. thegoldenboyisaac reblogged this from ambergerchild
  2. squeakysammi reblogged this from smilesmakemyday
  3. suppadupp reblogged this from smilesmakemyday
  4. smilesmakemyday reblogged this from nationalpost
  5. symphonic-virtuoso reblogged this from nationalpost
  6. photochepooka reblogged this from robolord
  7. robolord reblogged this from nationalpost
  8. 8bitrk-d reblogged this from rollin-around-at-340ms
  9. strawberrydacri reblogged this from shainashit
  10. sciencewand reblogged this from azyrian
  11. ambergerchild reblogged this from nationalpost
  12. boldandsaucy reblogged this from nationalpost
  13. cauda-pavonis reblogged this from thatconfusedfreak
  14. thatconfusedfreak reblogged this from emciel
  15. sabelmouse reblogged this from iggymogo
  16. inhalethemelody reblogged this from jesterdoll
  17. shainashit reblogged this from theperksofbeingpizza
  18. lattendicht reblogged this from emciel
  19. xxxonastick reblogged this from deadinmagazines and added:
    Heh. Dawson expelled me too. They’re uber dicks when it comes to appeals. There’s an online petition for Ahmed though,...
  20. light-the-fire-within reblogged this from nationalpost and added:
    shouldn’t be expelled,...should be thanked...i don’t know,...
  21. carolol reblogged this from nationalpost
  22. shadesmind reblogged this from 9ma
Blog comments powered by Disqus