Feeds

Student hackers: we didn't defeat campus debit card system

Wiping the Blackboard clean

  • alert
  • submit to reddit

Security for virtualized datacentres

Two student hackers yesterday settled a lawsuit filed against them by campus debit card firm Blackboard with an admission that they never built a device to defeat the system.

Georgia tech student Billy Hoffman (AKA Acidus) and University of Alabama student Virgil Griffith (Virgil) were to present a paper on security flaws involving Blackboard's popular university ID card system at the Interz0ne.com conference last April. Blackboard Inc. got wind of the talk on the supposed shortcomings of its Blackboard Transaction System and filed suit against the pair.

At first the case looked like a big company using lawyers to gag security researchers but subsequent reports on the case reveal something more complex was going on. For instance, the Washington Post reports that in March Hoffman attended a trade show for campus card users as a paid consultant for Blackboard competitor NuVision Networks.

The Blackboard Transaction System is used by many US universities; it enables institutions to manage student accounts, lets students spend their money on the Web or on campus using their student ID card. The system can be Web-enabled or integrated with campus equipment such as cash registers and vending machines.

Hoffman's Web site (www.yak.net/acidus), according to Blackboard's lawyers, detailed plans to "release code to make a computer emulate any Blackboard reader, as well as the hardware designs ... to make a drop in replacement for any Blackboard reader" during the cancelled talk.

But Hoffman and Griffith did not actually make a device that could manipulate the Blackboard system for illicit gain, at least according a settlement the pair made with Blackboard Inc. this week.

AP reports that the settlement requires the students to "apologize to Blackboard and its clients, promise that they never built a transaction processing system and serve 40 hours community service". In return Blackboard Inc. has agreed to call off its lawyers.

"They actually didn't do a lot of the things they were claiming to do," Blackboard spokesman Michael Stanton told AP. "They knew full well the claims they were making were silly. They're obviously bright young guys, but a little misguided in where they were focusing their attention."

Blackboard said the settlement shows its systems are secure but the whole case is better understood as a successful attempt to protect the firm's reputation against the possibly exaggerated claims of a pair of student hacker/crackers. ®

Related Stories

DMCA threats gag security researchers

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.