Campus ID News
Card, mobile credential, payment and security
FEATURED
PARTNERS

Campus card “hack” overstated but important

CampusIDNews Staff   ||   Apr 01, 2003  ||   ,

In the past week, a flurry of controversy has surrounded the reported “hacking” of the Blackboard transaction system. On April 12, 2003 Blackboard initiated legal action to stop two students from presenting at a hacker’s conference in Atlanta, Georgia. Their presentation, “Campuswide System Vulnerabilities Update,” was promoted as an overview of a means to compromise Blackboard’s transaction system. A Dekalb County, Georgia Judge granted a temporary restraining order prohibiting the men from discussing items relating to the topic–thereby canceling their presentation.

The events that culminated in this legal action began some time ago. Last year, details began circulating that a document had been posted to a hacker web site detailing plans to compromise the Blackboard transaction system. The article was written by a Georgia Tech student who, along with a student from University of Alabama New College, had done a significant amount of research on the Blackboard system and the underlying technology. The research included at least one incident that was deemed “hacking” by the students, but deemed “vandalism” by Blackboard.

This is an extremely difficult issue to weigh. A couple of enterprising young men studied a system and attempted to report issues that they viewed as significant to its continued security. Was their real intent to defraud the Blackboard system? Or to steal soft drinks from the Georgia Tech auxiliary services department? Probably not. Was it purely an altruistic desire to help make a commercial transaction system more secure to the benefit of all? Again, probably not. Chances are it was a bit of a desire to help, coupled with a lot of free time, and big shot of ego. This is a common recipe for hacking… though it is also a common recipe for vandalism.

It is important to remember that the Blackboard system was never actually compromised. It was only theoretically compromised. I have seen theoretical security breaches many times in the technology sector (the breaking of DES, the microwave oven attack on smart cards, the million computer attack on triple DES…). None of them hurt the practical security of the technologies in question–but they did point to potential areas that could be worked on to make a more secure environment. In order for the campus card industry to continue to mature, our response to this event will be crucial. We must learn from it and improve all of our processes and systems–not just the one singled out in this particular attack. The lesson here is twofold: as campuses we need not panic over theoretical attacks and as an industry we need not crucify the messenger–even if their judgement was bad in the end. We will delve into this issue more deeply in next month’s issue. Stay tuned.

Chris Corum, Editor • [email protected]

|| TAGS:
Subscribe to our weekly newsletter

RECENT ARTICLES

MyVenue POS with Illumia mobile credential on phone
Feb 26, 26 /

Transact + CBORD partners with MyVenue to extend stored value to campus stadiums

Transact + CBORD (rebranding to Illumia in March 2026) announced a new agreement with sports and entertainment point-of-sale (POS) provider MyVenue. The partnership allows students to use their campus card and stored-value campus funds for purchases inside stadiums and arenas. The integration adds MyVenue’s high-volume point-of-sale platform to Transact + CBORD’s campus commerce platform. Designed […]
ColorID receives HID's Elite Partner Status

ColorID recognized with HID Global’s highest level partner status

ColorID announced that it has achieved HID Elite Technology Partner status within the HID partner ecosystem. This designation recognizes them as one of a select group of partners demonstrating advanced technical expertise, strategic integration capabilities, and excellence in delivering solutions built on HID technology. The HID Origo Technology Partner Program is designed to foster collaboration with […]
Transact and Genea discuss their partnership for cloud-native access control in higher education
Feb 19, 26 /

Illumia and Genea partner to bring cloud-native access control to higher education

In this episode of CampusIDNews Chats, leaders from Transact + CBORD (rebranding to Illumia in March 2026), Genea, and Mercer University discuss a new partnership delivering cloud-native access control to higher education. The collaboration brings together Genea’s modern physical security solution and Illumia’s identity, credentialing, and commerce platform. Mercer is a key initial implementation of […]
CIDN logo reversed
The only publication dedicated to the use of campus cards, mobile credentials, identity and security technology in the education market. CampusIDNews – formerly CR80News – has served more than 6,500 subscribers for more than two decades.
Twitter

Great inverview on the Public Key Open Credential (PKOC) standard with ELATEC's Jason Ouellette, Chairman of the Board for the @PSIAlliance.

Attn: friends in the biometrics space. Nominations close Friday for the annual Women in Biometrics Awards. Take five minutes to recognize a colleague or even yourself. http://WomenInBiometrics.com

Load More...
Contact
CampusIDNews is published by AVISIAN Publishing
315 E. Georgia St.
Tallahassee, FL 32301
www.AVISIAN.com[email protected]
Use our contact form to submit tips, corrections, or questions to our team.
©2026 CampusIDNews. All rights reserved.