School Laptop Spying Program Has A 'Hacker-Friendly' Security Vulneratibility
from the but,-of-course-it-does dept
It always happens. A technology used for spying on people always opens up security vulnerabilities. Sony's "rootkit" DRM had huge security vulnerabilities that let people do bad things to your computer. And now comes the news that the LANrev system used by the Lower Merion School District to secretly photograph students at home also just happened to have a big security vulnerability that, in theory, made it possible for others to spy on children without them knowing it as well:The LANrev program contains a vulnerability that would allow someone using the same network as one of the students to install malware on the laptop that could remotely control the computer. An intruder would be able to steal data from the computer or control the laptop webcam to snap surreptitious pictures....To be fair, there's no evidence that anyone used this hack outside of the researchers who have discovered it, but it still raises more questions about the wisdom of using such software, especially on laptops used by kids.
The vulnerability in the LANrev system lies in the symmetric-key encryption it uses for authentication between the client and the server, and isn’t related to the optional Theft Track feature. Therefore, even computers that are not using the theft feature are potentially vulnerable.
The authentication key is stored in the client-side and server software and is fairly easy to decipher, says Frank Heidt, president and CEO of Leviathan. It took Leviathan just a few hours to determine that it’s a stanza from a German poem. The key is the same for every computer using LANrev.
The LANrev client software on a computer is configured to contact a server every minute or so to check in and see if the server has any commands for it. Knowing what the key is would let an attacker who has installed a sniffer on the network intercept that ping and masquerade as the server in communication back to the laptop. It requires the attacker to be on the same network as the target machine -- for example, on a wireless network at the school or anywhere else that offers free Wi-Fi the student might use.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: lower merion, security, spying, students, vulnerability
Reader Comments
Subscribe: RSS
View by: Time | Thread
It just gets better and better
[ link to this | view in thread ]
Re: It just gets better and better
[ link to this | view in thread ]
PileOn++
One static key for every installation, every server to client session.
It would be a just and quick death of the product if they would would just put on a black shirt, show up in a hipster coffee shop and start quoting some Teutonic verse!
Would it help if I said "please"?
Big Brother sucks.
[ link to this | view in thread ]
Password
- You know we could have it generate...
- Shutup, I'm in charge here.
[ link to this | view in thread ]
People still use these companies without knowing who they are.
People don't care about security: period.
[ link to this | view in thread ]
Re:
FTFY
Everyone cares about security when they realize theirs has been compromised.
[ link to this | view in thread ]
I've found that there are a number of legitimate uses for spying programs. As one example, I put spying programs on my computer so I can do make sure my hair remains tidy.
If someone doesn't have a spying program on their computer, I load up a program like LanRev so I can do my hair. Sometimes I forget to uninstall it. But that's because I'm interested in my hair and also have Aspergers, which means I can only wear shoes that have velcro.
[ link to this | view in thread ]
Re:
[ link to this | view in thread ]
Re: Password
Now the evidence will show there really was child porn being made...Its out there...you know it..I know it...that school will now need to be "saved" because they will be labeled as child molesters
[ link to this | view in thread ]
Re: Re: Password
[ link to this | view in thread ]
really
you know in some back room in that school district there's a pile of hard drives full of video of 13 year olds discovering Internet porn I can't believe no ones going after them on that
[ link to this | view in thread ]
They aern't the only ones
[ link to this | view in thread ]
Re: Re:
At my last job I was astounded how little of this stuff was understood by my coworkers, fellow professional programmers; most of them didn't have the first clue about the considerations necessary for even the most rudimentary security concerns. They probably would have shipped something just as crappy as this stuff if I hadn't been involved.
[ link to this | view in thread ]
and now you twits with iphones...
they have had vulnerabilities.
FOR A LOT LONGER THEN YOU KNOW
[ link to this | view in thread ]
OH and wonder why pirates dont use video tech
like that uber secret pirate site?
THIS is why its been known to me at least 6-7 years.
only thing i use a cam for is the special offline box i have that never goes near the net and has a motion sensor that will start recording when someone changes the video in front
[ link to this | view in thread ]
I Would Be Furious
[ link to this | view in thread ]
In fact, privacy and security are two important reasons I try to stay exclusively with open source.
And, yes, commercial vendors prefer closed source. We the people must pressure them to open up by voting with our dollars and choices.
[ link to this | view in thread ]
re
Let's try to give these people the benefit of the doubt, here. I've read a lot of news stories about this event, and never once did I get the impression that any of them were pedophiles. Facts may prove me wrong, but I'd rather wait for the facts. What they did should be obviously wrong to most people, but lets not jump to that conclusion.
"At my last job I was astounded how little of this stuff was understood by my coworkers, fellow professional programmers; most of them didn't have the first clue about the considerations necessary for even the most rudimentary security concerns."
Yes, you would hope they would. But remember that IT people tend to be pigeon-holed. If you spend a lot of time writing database apps, you tend to know little about comm. Its also a different world today, and a lot of people still in IT come from a time when security was not a big issue. I wrote a lot of strcpy()s - never once did I have to think about a buffer overflow. Security consciousness requires a sort of 'backward' mindset. Most engineers think about how to write software that works, not how to break it. If you're not a criminal, you tend not to think like that. It takes getting used too. Today's programmers will have to learn to think that way.
Basically, I think these were people who were trying to protect the kids, and got carried away. Some with voyeuristic tendencies. You would think some of these teachers would have read 1984, and the US Constitution, and tried to understand them both.
[ link to this | view in thread ]
hacker for hire
whitehat@cyber-wizard.com
whitehat@cyber-wizard.com
whitehat@cyber-wizard.com
change univ grades
change gpa
[ link to this | view in thread ]
Re: hacker for hire
[ link to this | view in thread ]
this person robbed me 300us
whitehat@cyber-wizard.com
mr.hacker4hire@gmail.com
this are his emails
[ link to this | view in thread ]
Kevin response to:( hacker for hire)
[ link to this | view in thread ]
ad
hi steeal me 100us its a fake
[ link to this | view in thread ]
hACKER
[ link to this | view in thread ]
[ link to this | view in thread ]
Re: Kevin response to:( hacker for hire)
[ link to this | view in thread ]