Live data from Hacker News

British Airways: Suspect code that hacked fliers ‘found’

bbc.co.uk

1–10 of 64 posts

Re: British Airways: Suspect code that hacked fliers ‘found’

#2
"According to RiskIQ, they even went so far as to acquire a Secure Socket Layer (SSL) certificate - which suggests to web browsers that a web page is safe to use."

The BBC's technology reporting usually isn't that bad for a mainstream audience, but this is just egregious. On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other completely exaggerating the difficulty of going HTTPS now we have LetsEncrypt.

Re: British Airways: Suspect code that hacked fliers ‘found’

#5
post #2

"According to RiskIQ, they even went so far as to acquire a Secure Socket Layer (SSL) certificate - which suggests to web browsers that a web page is safe to use." The BBC's technology reporting usually isn't that bad for a mainstream audience, but this is just egregious. On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other compl…

Although this comment in RisqIQ's report (https://www.riskiq.com/blog/labs/magecart-british-airways-br...) is even worse - it suggests that LetsEncrypt certs are less "legitimate" than paid ones: "Interestingly, they decided to go with a paid certificate from Comodo instead of a free LetsEncrypt certificate, likely to make it appear like a legitimate server"

Re: British Airways: Suspect code that hacked fliers ‘found’

#6
post #2

"According to RiskIQ, they even went so far as to acquire a Secure Socket Layer (SSL) certificate - which suggests to web browsers that a web page is safe to use." The BBC's technology reporting usually isn't that bad for a mainstream audience, but this is just egregious. On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other compl…

> On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other completely exaggerating the difficulty of going HTTPS now we have LetsEncrypt.

To a lay-person both those things ring very true, especially after Internet giants like Google have pushed https into everyone's throats.

Re: British Airways: Suspect code that hacked fliers ‘found’

#7
This is interesting as a lot of initial speculation for this attack focused on the large amount of 3rd party JS being loaded into the BA payment pages as a likely source of compromise.

Instead this looks like a fairly well executed "traditional" attack on BAs CMS/Web server infrastructure.

It's a good example of why even front-end infrastructure components need good protection...

Re: British Airways: Suspect code that hacked fliers ‘found’

#8
Genuine question... Why the scare quotes around the word "found"? I'm assuming "hacked fliers" refers to the people who had their details stolen. So how exactly did they "find" the "suspect code"?

English is my first language, but I'm really struggling to grok this headline.

Re: British Airways: Suspect code that hacked fliers ‘found’

#9
post #2

"According to RiskIQ, they even went so far as to acquire a Secure Socket Layer (SSL) certificate - which suggests to web browsers that a web page is safe to use." The BBC's technology reporting usually isn't that bad for a mainstream audience, but this is just egregious. On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other compl…

Getting a Comodo cert like as the attackers did is extremely non-trivial (at least for the first time). It took me upwards of 4 weeks plus a trip to an actuary and multiple calls with my CPA.

Re: British Airways: Suspect code that hacked fliers ‘found’

#10
post #8

Genuine question... Why the scare quotes around the word "found"? I'm assuming "hacked fliers" refers to the people who had their details stolen. So how exactly did they "find" the "suspect code"? English is my first language, but I'm really struggling to grok this headline.

I think it’s because it’s not been confirmed by BA that this was the attack used.
Post reply on HN