<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; security flaw</title>
	<atom:link href="http://venturebeat.com/tag/security-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Sat, 25 May 2013 19:48:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; security flaw</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>Find a computer bug, get threatened with jail, get expelled from college</title>
		<link>http://venturebeat.com/2013/01/21/find-a-computer-bug-get-threatened-with-jail-get-expelled-from-college/</link>
		<comments>http://venturebeat.com/2013/01/21/find-a-computer-bug-get-threatened-with-jail-get-expelled-from-college/#comments</comments>
		<pubDate>Mon, 21 Jan 2013 19:50:31 +0000</pubDate>
		<dc:creator>John Koetsier</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[OffBeat]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ahmed Al-Khabaz]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[computer bug]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[Dawson College]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Skytech Communications]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=607765</guid>
		<description><![CDATA[<p>One Canadian computer science student has discovered the three simple steps to ruining your&#160;life.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=607765&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.com/2013/01/21/find-a-computer-bug-get-threatened-with-jail-get-expelled-from-college/medium_401770711/" rel="attachment wp-att-607797"><img class="aligncenter size-full wp-image-607797" alt="medium_401770711" src="http://venturebeat.files.wordpress.com/2013/01/medium_401770711.jpg?w=640&#038;h=427" width="640" height="427" /></a>One Canadian computer science student has discovered the three simple steps to ruining your life:</p>
<ol>
<li>Find a bug that could reveal the personal information of 250,000 students</li>
<li>Report it to the proper authorities at his school, <a href="http://www.dawsoncollege.qc.ca/" target="_blank">Dawson College</a> in Montreal, Canada</li>
<li>Get threatened with jail, and get expelled from college</li>
</ol>
<p>Twenty-year-old Ahmed Al-Khabaz found a flaw in the college-management <a href="http://www.skytech.com/en/omnivox.sky" target="_blank">Omnivox software</a> that most colleges in Quebec use, <a href="http://news.nationalpost.com/2013/01/20/youth-expelled-from-montreal-college-after-finding-sloppy-coding-that-compromised-security-of-250000-students-personal-data/" target="_blank">according to Canada&#8217;s National Post</a>. He reported it to the college&#8217;s director of IT, who congratulated him and thanked him.</p>
<p>But two days later, when Al-Khabaz decided to double-check whether a fix was in place, he was surprised by a phone call from Edouard Taza, the president of Skytech, the company that makes Omnivox. Al-Khabaz say that Taza accused him of implementing a &#8220;cyber-attack,&#8221; threatened him with jail, and forced him to sign a nondisclosure agreement.</p>
<p>But despite his cooperation with what some might say was an unreasonable and bullying approach, Al-Khabaz was expelled from college.</p>
<p>Calls to Donna Varrica and Carey-Ann Pawsey at the Dawson&#8217;s communications office go straight to voicemail, but the college has posted a statement on its website, standing by its decision and saying that Al-Khabaz had been warned on at least one occasion to &#8220;cease and desist.&#8221;</p>
<blockquote><p>Dawson College stands by its policies regarding academic integrity and professional code of conduct. The provisions of these policies are clearly stated in the Institutional Student Evaluation Policy and the Code of Conduct on the website (listed below).</p>
<p>Under the terms of Quebec privacy laws, it is illegal to discuss the details of student files with individuals or with the media. Dawson College practices due process and due diligence in every case brought before the review committee. If a student does not agree with a decision, he or she has the right to appeal, as spelled out in the policies</p>
<p>In the recent case of Ahmed Al-Khabaz, which he himself brought to the media, the College stands by its decision. The reasons cited in the National Post article for which the student was expelled are inaccurate. The process which leads to expulsion includes a step in which a student is issued an advisory to cease and desist the activities for which he or she is being sanctioned, particularly in the area of professional code of conduct. Conditions for remaining in the College on good terms are clearly explained in person to the student.</p>
<p>When this directive is contravened by the student by engaging in additional activities of the same sort, the College has no recourse but to take appropriate measures to sanction the student.</p></blockquote>
<p>I have not been able to speak to Al-Khabaz yet, but based on the publicly available facts, Dawson College and Skytech &#8212; sounds suspiciously like Skynet, no? &#8212; should be thanking him and perhaps rewarding him.</p>
<p>VentureBeat has reached out to Edouard Taza, Skytech&#8217;s president, and will update if he responds.</p>
<p><em>photo credit: <a href="http://www.flickr.com/photos/luigipics/401770711/" target="_blank">Gìpics</a> via <a href="http://photopin.com" target="_blank">photopin</a> <a href="http://creativecommons.org/licenses/by-nc-nd/2.0/" target="_blank">cc</a></em></p>
<br />Filed under: <a href='http://venturebeat.com/category/business/'>Business</a>, <a href='http://venturebeat.com/category/offbeat/'>OffBeat</a>, <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=607765&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/01/21/find-a-computer-bug-get-threatened-with-jail-get-expelled-from-college/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/01/medium_401770711.jpg?w=160" /><source url="http://venturebeat.com/2013/01/21/find-a-computer-bug-get-threatened-with-jail-get-expelled-from-college/">Find a computer bug, get threatened with jail, get expelled from college</source>
		<media:thumbnail url="http://venturebeat.files.wordpress.com/2013/01/medium_401770711.jpg?w=160" />
		<media:content url="http://venturebeat.files.wordpress.com/2013/01/medium_401770711.jpg?w=160" medium="image">
			<media:title type="html">medium_401770711</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/6d4d24b12c84be6eecddf121bc3fee48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">johnkoetsier</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/01/medium_401770711.jpg" medium="image">
			<media:title type="html">medium_401770711</media:title>
		</media:content>
	</item>
		<item>
		<title>Stupid Smart Cover lets anyone break into your passcode-protected iPad 2</title>
		<link>http://venturebeat.com/2011/10/21/ipad-2-security-flaw/</link>
		<comments>http://venturebeat.com/2011/10/21/ipad-2-security-flaw/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 07:16:00 +0000</pubDate>
		<dc:creator>Tom Cheredar</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[iPad 2]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Smart Cover]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=343769</guid>
		<description><![CDATA[<p><strong>July 9-10, 2013</strong><br />
      San Francisco, CA</p>
<p>  Early Bird Tickets on Sale</p>
<p>If you think your iPad 2 is completely secure after enabling the passcode protection feature for iOS 5, then think again.</p>
<p>Apple blog 9to5 Mac, citing a German site,&#160;&#8230;</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=343769&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div class="post-meta-blurb post-meta-before blurb-cat-mobile"><div class="event-boilerplate-mobilebeat">
  <div class="logo-date-wrap">
    <a href="http://mobilebeat2013.com" data-vb-ga-outbound="MB2013boilerplateTOP"><img src="http://venturebeat.files.wordpress.com/2013/02/mobilebeat-boilerplate.png" alt="MobileBeat 2013"></a>
    <div class="date-location">
      <strong>July 9-10, 2013</strong><br>
      San Francisco, CA
    </div>
  </div>
  <a href="http://mobilebeat2013-MB2013boilerplateTOP.eventbrite.com/" class="cta" data-vb-ga-outbound="MB2013boilerplateTOP">Early Bird Tickets on Sale</a>
</div></div><p><img class="alignright size-full wp-image-343801" title="iPad-smart-cover-flaw" src="http://venturebeat.files.wordpress.com/2011/10/ipad-smart-cover-flaw.png?w=400&#038;h=400" alt="" width="400" height="400" />If you think your iPad 2 is completely secure after enabling the passcode protection feature for iOS 5, then think again.</p>
<p>Apple blog <a href="http://9to5mac.com/2011/10/20/anyone-with-a-smart-cover-can-break-into-your-ipad-2/" target="_blank" target="_blank">9to5 Mac,</a> citing a<a href="http://www.apfeltalk.de/forum/content/2677-ipad-passwort-umgangen.html" target="_blank"> German site</a>, reported a security flaw that allows anyone with one of Apple&#8217;s Smart Covers to gain access to the device &#8212; giving them free rein on emails, messages, browser history, contacts and any application with stored login information (Facebook, mobile bank account apps, Twitter, etc.).</p>
<p>The flaw can be exploited on a locked iPad 2 by holding down the power button, which will eventually prompt you to slide a horizontal scroll button to turn off the device. With the &#8220;power off&#8221; screen still up, close the smart cover. When you lift up the cover again the &#8220;power off&#8221; screen is still present, but clicking cancel brings you to the home screen &#8212; thus bypassing the need to enter in the correct passcode.</p>
<p>The trigger seems to be when the iPad is put to sleep (locked), which cannot be done by clicking the power button again. However, the iPad 2 can get around this because it uses magnet sensors from the Smart Cover to lock the device when the cover is on and unlock it when taken off. Since the first generation iPad isn&#8217;t compatible with Smart Covers, it doesn&#8217;t suffer from the flaw.</p>
<p>Some iPad owners are reporting that the security exploit isn&#8217;t limited to iOS 5, and will also work on version 4.3 of the operating system. I can&#8217;t confirm if this is the true because I don&#8217;t have an iPad running 4.3, nor do I have the desire to roll back the operating system to an earlier version. Although, anyone who is running 4.3 on their iPad is more than welcome to test the exploit and let us know if it works. (Just drop us a comment below, or email us at tips@venturebeat.com.)</p>
<p>Presumably, Apple will issue a fix in the next iOS update, which is due out any day now. In the meantime, if you&#8217;re worried about your iPad 2 geting compromised before the update is released, there is a temporary solution. As 9to5 Mac points out, iPad owners can disable the Smart Cover locking/unlocking function found in the Settings app under the &#8220;General&#8221; tab.</p>
<br />Filed under: <a href='http://venturebeat.com/category/business/'>Business</a>, <a href='http://venturebeat.com/category/mobile/'>Mobile</a>, <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=343769&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" /><style type="text/css">.blurb-cat-mobile .event-boilerplate-mobilebeat {
width:278px;
margin:0px 0px 10px 20px;
padding:10px;
float:right;
border:1px solid #e4e4e4;
font-family: 'Open Sans', sans-serif;
color:#000;
}
.blurb-cat-mobile .event-boilerplate-mobilebeat .logo-date-wrap {
width:100%;
display:block;
float:left;
margin-bottom:8px;
}
.blurb-cat-mobile .event-boilerplate-mobilebeat img {
float:left;
}
.blurb-cat-mobile .event-boilerplate-mobilebeat .date-location {
float:right;
font-size:12px;
line-height:14px;
text-align:center;
padding-left:7px;
padding-top:5px;
padding-bottom:3px;
border-left:1px solid #e6e6e6;
color:#585a5b;
}
.blurb-cat-mobile .event-boilerplate-mobilebeat .cta {
display:block;
clear:both;
width:100%;
border-radius:5px;
border:1px solid #1864b1;
color:#fff;
text-shadow: 0px -1px 0px rgba(0,0,0,0.3);
text-align:center;
text-decoration:none;
font-weight:600;
font-size:18px;
line-height:17px;
padding:4px 0px 6px 0px;
background: #1f80e4;
background: -moz-linear-gradient(top,  #1f80e4 0%, #1862ae 100%);
background: -webkit-gradient(linear, left top, left bottom, color-stop(0%,#1f80e4), color-stop(100%,#1862ae));
background: -webkit-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: -o-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: -ms-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: linear-gradient(to bottom,  #1f80e4 0%,#1862ae 100%);
filter: progid:DXImageTransform.Microsoft.gradient( startColorstr='#1f80e4', endColorstr='#1862ae',GradientType=0 );
}</style>]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2011/10/21/ipad-2-security-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2011/10/ipad-smart-cover-flaw.png?w=140" /><source url="http://venturebeat.com/2011/10/21/ipad-2-security-flaw/">Stupid Smart Cover lets anyone break into your passcode-protected iPad 2</source>
		<media:thumbnail url="http://venturebeat.files.wordpress.com/2011/10/ipad-smart-cover-flaw.png?w=140" />
		<media:content url="http://venturebeat.files.wordpress.com/2011/10/ipad-smart-cover-flaw.png?w=140" medium="image">
			<media:title type="html">iPad-smart-cover-flaw</media:title>
		</media:content>

		<media:content url="http://2.gravatar.com/avatar/2398004bfb5f0b388f1598ca705f59c7?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">vbtomcheredar</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2011/10/ipad-smart-cover-flaw.png" medium="image">
			<media:title type="html">iPad-smart-cover-flaw</media:title>
		</media:content>
	</item>
	</channel>
</rss>
