Live data from Hacker News

United Airlines Bug Bounty: An experience in reporting a serious vulnerability

randywestergren.com

1–10 of 80 posts

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#5
Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#6
If you know the PNR of an itinerary and the person's last name you can quite easily do most of what was described in this article via United's website or over the phone. Always makes me laugh when I see folks posting full images of their plane tickets online, they so easily could have their travel plans screwed. :(

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#8

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

Yes, it's really unreasonable.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#9
Just checked this using mitmproxy. My United MileagePlus Account is definitely there.

Also, you need a valid MP#, and the # is not sequential (nor all numbers).

At least they're using https.

Edit: Also annoying the app keeps making calls to Gogo wifi and some other Wifi page.

Edit2: I just realized United _did_ fix it. Thought it said they refused to fix it.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#10

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

Bloated beauracracies need agile ways to respond to important situations. Giving them a pass because they are bloated won't make that happen any sooner, and it does need to happen.
Post reply on HN