Jukebox

This thing is disabled temporarily. I'll have it back shortly, without auto-play Tom

Mar
09

Go, Harvard!!!!

By Tom Whiting
(No Ratings Yet)
Loading ... Loading ...

Harvard is apparently kicking out 119 applicants because they “hacked” into their files. Ummmmm, hellllooooo? What constitutes hacking here? And who the bloody HELL wrote security for this application? Let’s see here, shall we?

Harvard hired a bunch of cheap idiots to code an application that would send information to the school. Good? Bad? Weelllll, given the fact that the application is incredibly flawed, I’d say POOR CHOICE. See the flaw here


The ApplyYourself code had a bug such that editing the URL in the “Address” or “Location” field of a Web browser window would result in an applicant being able to find out his admissions status several weeks before the official notification date.

Goodie
So, now any kid can edit an address and “poof”, they’re able to see an application? Come on now, who defines hacking here? This is SURE the hell not hacking, in ANY sense of the word!

Hey, careful, you can’t click that back button, that’d be “hacking” into my server.
Hey, you can’t go to http://dvds.wolfstream.net/index.php , that’s HACKING the server!
Hey, you can’t change anything in the URL bar, that’s “hacking” the server.

Get my point? I’m sure you do by now. The fact that Harvard, one of the more “elite” schools out there decided to rely in such an INSECURE application, well, that’s just absurd.

So, who’s to blame here? The bank manager who “accidentally” forgets to lock the safe , and disables the alarm, then going home, forgets to lock the door? Or the common person who, upon seeing the safe open and unlocked, walks in, out of curiosity, and then DOESN’T take anything, mind you, but walks right out?

Even better, and I love this analogy:

Fiddling with the URL is like walking up to the admissions desk, asking to see your own file, and them handing it to you. In this case the website is playing the role of the admissions desk. It’s their fault that they had insufficient controls on the distribution of admissions files.

Yeah, so, who is responsible there? The person that actually SHOWED the files (ie: HARVARD) or the person who looked at them (ie: the student who accessed them publicly).

Hellooooooo, people, can we say SECURITY here? I mean, come on, what 7 year old child doesn’t know better than to secure a website like this. Good god, ANYONE could have gotten that information, even worse yet:ANYONE COULD HAVE POSTED THAT URL!

Yup, it’s true. ANYBODY could have posted a url, hell, it takes about 5 seconds to post a URL in a browser, soooo, how has harvard gone to the trouble of “verifying” this? HAVE THEY? Most likely not. The response to the cluebies that developed the application? Most likely something like “We’ll do it better next year guys”. God, what a bunch of complete idiots.

Hey, don’t close that browser, you’re hacking into my server!! STOP THAT!.

Enough said, that just completely pisses me off. NOTHING pisses me off more than stupidity, and believe me, THIS is ultimate stupidity, in and of itself. And people wonder WHY I chose not to go to college? The people running these colleges apparently are dumber than their students…

Can we say LAWSUIT!??? Good luck getting out of THIS one, Harvard.

Categories : blog
(28 views)

Leave a Reply