Skip to Content, Navigation, or Footer.
Monday, July 27
The Indiana Daily Student

A spider's web

Cybercrime raises new questions

If you leave a $5 bill on a table in the middle of the Wright Cafeteria and walk away, chances are in an hour, it will be gone. That's your fault, right? \nBut if you leave the door to your house unlocked, are you to blame if a thief walks in and takes your television? \nMonday, the case of Indiana University v. the Emergency Web site "hacker" was heard by a campus judicial board. Sophomore Benjamin Brodsky was charged with accessing the Emergency Web site and posting unauthorized messages. Those messages benignly asked students to call their local legislator and plead for a snow day on Jan. 27. \nBrodsky gained administrative privileges to the site simply by typing his IU username and password into a blank field. \nBrodsky said he shouldn't be prosecuted by the University because he did them a free service. By posting the humorous message, Brodsky identified a weakness in the University mainframe, which has since been patched. \n While IU pays millions for Internet security each year, Brodsky exposed the security flaw free of charge. \n At issue here is a fundamental problem of the New Era in which we live in. Should someone who takes advantage of a security flaw be punished, or should we thank him for calling it to our attention, thereby causing the flaw to be fixed?\n It is a difficult moral dilemma and one that cyberpolice are increasingly being forced to face. \nIn a fascinating article in the The New York Times Magazine last month called "Virus Underground," Internet hackers make the case that by mischievously exposing security flaws, they are in fact strengthening the "immune system" of the Internet. \nBrodsky likes to think he is a computer genius. His Web site, www.nff.be, proudly details his feat.\nBut the fact is, this security flaw was enormous. It is the $5 bill on the lunchroom table, not the unlocked door to your home.\nAnd the way in which he drew attention to the flaw was by posting a message that was a mere nuisance at best. \nThe ease of his access is an embarrassing joke to a University that prides itself on being one of the most wired in the nation. \nAt Monday's hearing, Brodsky was given one year of disciplinary probation. He is also prohibited from viewing the Emergency Access Web site, which means that if Osama Bin Laden pops into town, Brodsky will be the last to know. \nWe feel that his actions do not deserve a year's probation. \nBrodsky alerted us to a frightening question: Why was a Web site as vital as the Emergency Alert System, which tells us the security level of the campus, so vulnerable that anyone with a username and password could access it? \nWe certainly don't have to think too hard to start wondering what other IU Web sites are waiting to be cracked. Are our social security numbers, financial aid statements and grade reports in jeopardy? \nLet us hope IU takes the security of these private bits of student information more seriously than it does its Emergency Alert System.\nThe next "hacker" might not have Brodsky's sense of humor. \nWhat really should be on trial here is IU's Internet security.

Get stories like this in your inbox
Subscribe