Cornell Blog: An unofficial blog about Cornell University

Protect your CUID!

Posted in Life at Cornell by Cornell's Most Infamous on May 1st, 2005.

The Facebook recently added measures to prevent anyone from finding out your student ID (they plugged an XSS hole, actually), but that doesn’t prevent you from screwing up. A freshman who shall not be named is currently using a scan of student ID for a Facebook profile pic:

Some freshman

This is bad for so many reasons. Knowing your student ID is just one step towards complete identity theft, so please, never post a scan of your ID online. Do you really want someone else eating your hard-earned dining hall meals?

This entry was posted on Sunday, May 1st, 2005 at 4:26 am and is tagged with cuid, facebook, student id, dining hall, freshman, identity theft, measures. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback.

5 Responses to “Protect your CUID!”

  1. Anonymous says:

    out of curiosity, what features did they add?

  2. prying1 says:

    Gee, For a stewdint he has sum lurnin’ to do…

  3. Suzi says:

    ACK! My daughter is completely addicted to the face book, since her college just got it. Come to think of it, she always leaves hundreds of non-refundable and non-carry-over-able dollars in her meal account each semester, so I’d actually appreciate it if somebody *would* use that money for food. Such a waste!

    Found you through Blog Explosion, by the way. Nice blog!

  4. They plugged the following holes, first reported on Bugtraq (a security exploits mailing list):

    http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-11/0192.html

    http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-11/0200.html

    I woudn’t really call it adding features, but rather adding security that should have been there in the first place.

  5. Thanks for the comment, Suzi! Facebook is cool, but after the first while of using it, I only visit on occasion, like most people I know. Only the new inductees are easily amused. And, since it’s a web site I could code myself, it doesn’t impress me much.

Leave a Reply

Powered by WP Hashcash