Live data from Hacker News

Hacking on a plane: Leaking data of millions and taking over any account

rez0.blog

1–10 of 91 posts

Re: Hacking on a plane: Leaking data of millions and taking over any account

#3
post #2

I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?

I'm not the author of the article. But I think developers thought "ahaha who's going to checkout? Someone that has developer tools in airplane? Good joke bob!"

Re: Hacking on a plane: Leaking data of millions and taking over any account

#4
I can understand when there's a bug that causes something like this. It doesn't excuse it, but we all introduce bugs in code, and sometimes they're disastrous.

But this? This is just straight up careless, thoughtless design with zero regard for security whatsoever. It's inexcusable.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#6

When on any sort of public WiFi network, use a VPN. If anyone has a story about how "that's not enough" I'm eager to hear it. Can't be too careful, can we?

This has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#7
post #4

I can understand when there's a bug that causes something like this. It doesn't excuse it, but we all introduce bugs in code, and sometimes they're disastrous. But this? This is just straight up careless, thoughtless design with zero regard for security whatsoever. It's inexcusable.

Airplane wifi is very much still in the "enterprise software" phase, by which I mean a lowest bidder sells it to someone who will never use it and buys it with only some corporate objective in mind. I've been using it a lot recently, across several airlines, and the experience is universally bad. It doesn't surprise me they also skimped on security

Re: Hacking on a plane: Leaking data of millions and taking over any account

#8
The author did not mention if they were rewarded by the bug bounty program. A vulnerability of this severity surely requires a reward of some sort.

Does anyone have any more information about whether or not this person was compensated for their work?

Re: Hacking on a plane: Leaking data of millions and taking over any account

#9
post #4

I can understand when there's a bug that causes something like this. It doesn't excuse it, but we all introduce bugs in code, and sometimes they're disastrous. But this? This is just straight up careless, thoughtless design with zero regard for security whatsoever. It's inexcusable.

Airplane wifi is very much still in the "enterprise software" phase, by which I mean a lowest bidder sells it to someone who will never use it and buys it with only some corporate objective in mind. I've been using it a lot recently, across several airlines, and the experience is universally bad. It doesn't surprise me they also skimped on security

At least as far as the connectivity itself goes, Viasat's Ka-band airplane WiFi is actually really good.

As luck would have it, I've got a flight coming up in a few days on a plane using the provider implicated in this article. I'll be doing some poking around myself for sure.

Post reply on HN