Teenager Bill Demirkapi had been ghosted. Hard. "It didn’t feel good,Yoshihiro Tanbara Archives" he explained to the large crowd gathered to hear him speak. "It hurt my feelings.”
But Demirkapi, despite his status as a recent high-school graduate, wasn't lamenting the traditional spurned-love problems typical of his cohort. Far from it. Instead, he was speaking at the famous DEF CON hacker conference in Las Vegas, and the ghoster-in-question was educational software maker Blackboard.
Demirkapi had reported numerous vulnerabilities in Blackboard's software to the company; after initially being in communication with him, the company stopped responding to his emails. But Demirkapi, who found he could access a host of student data — including family military status, weighted GPAs, and special education status — through vulnerabilities in Blackboard's system, was undeterred.
In fact, he was just getting started. And Blackboard wasn't his only target.
Over the course of his high school career, Demirkapi — a budding security researcher — also investigated K-through-12 software maker Follett. In doing so, he determined the company left millions of student and teacher records exposed to anyone who bothered to look.
Specifically, he explained, there were more than 5 million student and teacher records in the system that covered over 5,000 schools. Left exposed were students' immunization history, attendance data, school photos, birthdays, and more.
"It was my data too in there," he told the audience of decidedly not teenage hackers. "This was pretty crazy stuff."
He tried to do the right thing and notified both his high school and the software manufacturers of his discoveries. Using a flaw in the system to alert students and teachers to its vulnerabilities, however, earned him a two-day suspension.
"Two days off of school," he said of the punishment. "I think it’s a pretty big win-win."
SEE ALSO: Remotely hacking elevator phones shouldn't be this easyEventually, Follett and Blackboard did listen — and many of the vulnerabilities he reported were patched at the end of July.
"Blackboard is always working hard to improve both the security of our products as well as the process and procedures we leverage in support of security," read a statement the company provided Demirkapi and he shared with DEF CON.
Asked by a member of the crowd what he's going to do next, Demirkapi gave an answer that elicited raucous applause from the hacker crowd: "Start college, maybe break their software."
Never give up on your dreams, Bill. The privacy of millions of students and teachers is counting on it.
Topics Cybersecurity
Adorable new 'Game of Thrones' Funkos will make you forget the tiresome bloodshedAriana Grande's mom shares heartwarming message on Memorial DaySteve Ballmer shows off his AIThe problem with millennials isn’t millennials—it’s how you’re leading themDon't count on Netflix as net neutrality's saviorThe final 'House of Cards' Season 5 promo is so deliciously creepyCan Vox become a better Medium than Medium?Will a robot take your job? This website provides an answer (that you probably won't like)There are now Harry Potter books in Hogwarts House colors, because of courseStudents create impressive schoolwork waterfall to celebrate the end of the yearKremlin's sexy music video tells kids protesting corruption isn't coolYou used to call Trump on his cellphoneYou can now apply for a refund from your kids' unauthorized Amazon inKathy Griffin's bloody Trump photo gets the internet to agree on somethingLike Kickstarter, but for legal casesExecutive from Lucasfilm had a perfect retort for a maleQueen Elizabeth II reportedly a big fan of her life story in 'The Crown'Two friends play the absolute best ongoing game of 'The Floor is Lava' everUFC fighter proposes marriage to partner after knockout winTerrifying footage emerges from raging storm in Moscow The hat for Elon Musk's 'Boring Company' is predictably boring Uber's new driver features could mean more destination discrimination Facebook's 'Liam' chatbot helps employees talk about scandals Lyft accused of ignoring 'ongoing sexual assaults' in disturbing lawsuit Twitter forgets dead people, suspends plan to delete inactive accounts Looks like Hillary Clinton and the internet are on the same page about this Mike Pence email thing Climate change models have been accurate since the 1970s Greta Thunberg arrives in Portugal on her way to climate talks Barbra Streisand doesn't need people, she needs pancakes Grandma and stranger she accidentally texted celebrate Thanksgiving together for a fourth year Internet quickly turns GOP's Obamacare replacement plan into a meme No, a Japanese man wasn't crushed to death by his porn collection Here is a glorious infographic ranking Kellyanne Conway's most embarrassing moments Apple unveils the most popular iPhone apps of 2019 Everything coming to Amazon Prime Video in December 2019 Meet your new takeout ordering hero, Mozzarella Stick Guy Watch this bro get into the Trolling Hall How to talk to kids about gender Top 10 most popular GIFs of 2019, according to Giphy 11 times Emma Watson was the hero we all needed
1.4201s , 10132.71875 kb
Copyright © 2025 Powered by 【Yoshihiro Tanbara Archives】,Evergreen Information Network