Teenager Bill Demirkapi had been ghosted. Hard. "It didn’t feel good," he explained to the large crowd gathered to hear him speak. "It hurt my feelings.”
But Demirkapi, despite his status as a recent high-school graduate, wasn't lamenting the traditional spurned-love problems typical of his cohort. Far from it. Instead, he was speaking at the famous DEF CON hacker conference in Las Vegas, and the ghoster-in-question was educational software maker Blackboard.
Demirkapi had reported numerous vulnerabilities in Blackboard's software to the company; after initially being in communication with him, the company stopped responding to his emails. But Demirkapi, who found he could access a host of student data — including family military status, weighted GPAs, and special education status — through vulnerabilities in Blackboard's system, was undeterred.
In fact, he was just getting started. And Blackboard wasn't his only target.
Over the course of his high school career, Demirkapi — a budding security researcher — also investigated K-through-12 software maker Follett. In doing so, he determined the company left millions of student and teacher records exposed to anyone who bothered to look.
Specifically, he explained, there were more than 5 million student and teacher records in the system that covered over 5,000 schools. Left exposed were students' immunization history, attendance data, school photos, birthdays, and more.
"It was my data too in there," he told the audience of decidedly not teenage hackers. "This was pretty crazy stuff."
He tried to do the right thing and notified both his high school and the software manufacturers of his discoveries. Using a flaw in the system to alert students and teachers to its vulnerabilities, however, earned him a two-day suspension.
"Two days off of school," he said of the punishment. "I think it’s a pretty big win-win."
SEE ALSO: Remotely hacking elevator phones shouldn't be this easyEventually, Follett and Blackboard did listen — and many of the vulnerabilities he reported were patched at the end of July.
"Blackboard is always working hard to improve both the security of our products as well as the process and procedures we leverage in support of security," read a statement the company provided Demirkapi and he shared with DEF CON.
Asked by a member of the crowd what he's going to do next, Demirkapi gave an answer that elicited raucous applause from the hacker crowd: "Start college, maybe break their software."
Never give up on your dreams, Bill. The privacy of millions of students and teachers is counting on it.
Copyright © 2023 Powered by
Teenager finds educational software exposed millions of student records-叶瘦花残网
sitemap
文章
115
浏览
885
获赞
4834
The Vatican was reportedly hacked by China
Sounds kind of like the plot of Mission Impossible IIIor a Dan Brown book.Hackers with links to theHacker modifies tractor to run 'Doom' amid long
Folks, we've done it.We've put in the work, and now we're reaping the rewards. Doomcan run on anythiGoogle dedicates its Doodle to getting people Covid vaccines
The Google letters are lining up to get vaccinated. Are you?Google used Wednesday's Doodle animationForeo UFO 2 review: This device takes sheet masking to the next level
Sheet masks are an affordable, no frills at-home facial treatment that are widely popular. So why noHow the Twitter hack highlights the dangers of Slack
Slack holds the keys to its customers' kingdoms, and has long been aware how problematic that is. TwBook clubs should always meet on Zoom
When the pandemic first hit, everything that was once an in-person experience was slammed into the tTwitter is redesigning Spaces and adding podcast suggestions
Twitter is still trying to make Spaces happen, this time by turning it into a podcast discovery platAmazon says Alexa will soon be able to mimic the voice of dead loved ones
Your dead loved ones are never really gone, they're just trapped inside Amazon's voice-assisted devi12 unexpected ways algorithms control your life
Mashable’s series Algorithmsexplores the mysterious lines of code that increasingly control ouNorton 360 in Australia: Everything you need to know
Our cybersecurity needs are constantly evolving, with brand new threats and nefarious malware showinApple Store is down in the U.S.
Apple's online store is currently down. Typically, this happens ahead of product launches, but this3 reasons to pamper your pet with ultra
The following content is brought to you by Mashable partners. If you buy a product featured here, weGoogle Arts & Culture brings 'ancient creatures' to augmented reality
A crustacean with scores of tiny eyes could be your newest houseguest — in augmented reality,Twitter tests co
Twitter is testing a Co-Tweet feature, as per mobile developer Alessandro Paluzzi and social media cHow to change your new Gmail layout back to the old version
Google recently did the unthinkable: It changed the way Gmail looks...again.It’s one of the gr