British Airways: Suspect code that hacked fliers ‘found’
61–64 of 64 posts
Re: British Airways: Suspect code that hacked fliers ‘found’
#62Earlier quoted context omitted.
After years of watching actual users, my first guesses as to why the crooks went with a "paid certificate from Comodo" would be: 1. They genuinely didn't know about Let's Encrypt 2. Learning some new stuff to get a free cert didn't seem worth it because they're not paying anyway (at corps this is often because they have a bulk deal, or there will just be a Purchase Order so it's not their personal credit card bill, f…
> Learning some new stuff to get a free cert didn't seem worth it because they're not paying anyway Even if they are paying, the ROI on spending even a single day on learning new stuff is a long, long time if you're just buying a DV cert.
Re: British Airways: Suspect code that hacked fliers ‘found’
#63Earlier quoted context omitted.
Wow, the Wii U is one? No wonder I had a bunch of Wii U users reporting my site stopped working when I started forcing HTTPS. "Minority of a minority", maybe, but I still got around five tweets about it when it happened; more than most other changes I make.
Just to be clear, you're serious right? Because yes, the Wii U has a browser, it hasn't been updated (because the Wii U is basically abandoned at this point) and it never did trust DST Root CA X3, which is the root via which trust to Let's Encrypt was bootstrapped in older browsers. Don't happen to have links for any of those tweets do you? I'd be happy to have an actual example of a user who ran into this for real (…
https://www.reddit.com/r/pokemonshowdown/comments/7eix1o/pok...
The problem wasn't just because of the HTTPS cert, but also because it didn't support WebSocket on port 8000.
Re: British Airways: Suspect code that hacked fliers ‘found’
#64Here’s the thing tho’, BA’s website exists solely to provide information on and sell their own services. Why is there third-party anything on it in the first place? Fix that and you’ll fix everything, well almost. Disclaimer: worked on ba.com in the ‘90’s
It's not a third party script. It's a copy of modernizr hosted on their own server. Someone has either hacked their CMS (Teamsite) or it's an insider.