Hacker News new | ask | show | jobs
by Kylekramer 4826 days ago
It was due to my alma mater's (McGill) poor security, but IDs + some minor extra info like DOB were able to be used for a lot of stuff (if i recall correctly ID was the username with DOB as the default password and voila, you got free reign to everything from financial information and even withdrawing a person from Uni entirely) when I was in school.

It is mostly due to the trusting and insular nature of universities where they assume that there isn't going to be malicious attacks, but I can see why they rather not have that information given away.