TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Reports: Hackers release stolen LAUSD data ahead of ransom deadline

7 点作者 hassanahmad超过 2 年前

2 条评论

codetrotter超过 2 年前
“This content is not available in your country&#x2F;region.”<p>Alternate link: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;QObx5" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;QObx5</a><p>Also, for anyone else wondering what “LAUSD” is; it’s Los Angeles Unified School District.
throwawayKiwi9超过 2 年前
I have worked for a few school districts and the security has always been very poor. Nobody really hardened Windows too much, leaving the attack surface wide open. In grade 8 I discovered blank admin creds. In grade 12 trivially pwned our grade system with url enumeration. I disclosed these responsibly. The local community college had numerical birthdays for student AND FACULTY passwords and published the full class rosters on Moodle for any student with basic OSINT skills to have some fun, although I think this policy was changed after they got owned last year. I tried to tell them. Schools either need to go full Chromebook, or get a SOC, or we need to start really investing in Linux-based school infra. Or Windows needs to make group policy easier maybe. I found something called Univention Corporate Server, a German debian-based offering which seems fair, but I can&#x27;t speak for it in practice.. One of the problems is School vendor software is typically beyond bad. Very, very expensive with ANCIENT libraries. Payroll uses super old programs because they comply with obscure and complicated state tax requirements for schools, that they probably paid 40k for. I&#x27;m just ranting at this point... <i>Sigh</i> I just got hired to work at a college again and would love some thoughts this, news like this always triggers me. I&#x27;m not sure what I&#x27;ll be walking into just yet. Lately I see districts moving responsibility onto cloud vendors.