Live data from Hacker News

British Airways: Suspect code that hacked fliers ‘found’

bbc.co.uk

61–64 of 64 posts

Re: British Airways: Suspect code that hacked fliers ‘found’

#62

Earlier quoted context omitted.

After years of watching actual users, my first guesses as to why the crooks went with a "paid certificate from Comodo" would be: 1. They genuinely didn't know about Let's Encrypt 2. Learning some new stuff to get a free cert didn't seem worth it because they're not paying anyway (at corps this is often because they have a bulk deal, or there will just be a Purchase Order so it's not their personal credit card bill, f…

> Learning some new stuff to get a free cert didn't seem worth it because they're not paying anyway Even if they are paying, the ROI on spending even a single day on learning new stuff is a long, long time if you're just buying a DV cert.

Learn new thing make brain hurt though. Maybe same for crook.

Re: British Airways: Suspect code that hacked fliers ‘found’

#63
post #45

Earlier quoted context omitted.

Wow, the Wii U is one? No wonder I had a bunch of Wii U users reporting my site stopped working when I started forcing HTTPS. "Minority of a minority", maybe, but I still got around five tweets about it when it happened; more than most other changes I make.

Just to be clear, you're serious right? Because yes, the Wii U has a browser, it hasn't been updated (because the Wii U is basically abandoned at this point) and it never did trust DST Root CA X3, which is the root via which trust to Let's Encrypt was bootstrapped in older browsers. Don't happen to have links for any of those tweets do you? I'd be happy to have an actual example of a user who ran into this for real (…

Yes, I'm serious, but it looks like I misremembered, because it took me forever to dig up the post (it turned out not to be on Twitter).

https://www.reddit.com/r/pokemonshowdown/comments/7eix1o/pok...

The problem wasn't just because of the HTTPS cert, but also because it didn't support WebSocket on port 8000.

Re: British Airways: Suspect code that hacked fliers ‘found’

#64
post #17
post #13

Here’s the thing tho’, BA’s website exists solely to provide information on and sell their own services. Why is there third-party anything on it in the first place? Fix that and you’ll fix everything, well almost. Disclaimer: worked on ba.com in the ‘90’s

It's not a third party script. It's a copy of modernizr hosted on their own server. Someone has either hacked their CMS (Teamsite) or it's an insider.

How do you know they use TeamSite? A similar hack occurred against TicketMaster. I wonder if they use TeamSite as well. Maybe a 0day?
Post reply on HN