I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
Hacking on a plane: Leaking data of millions and taking over any account
11–20 of 91 posts
Re: Hacking on a plane: Leaking data of millions and taking over any account
#12How is something like this not picked up in a pen test? Can only assume there never has been..
Re: Hacking on a plane: Leaking data of millions and taking over any account
#13I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
Re: Hacking on a plane: Leaking data of millions and taking over any account
#14When on any sort of public WiFi network, use a VPN. If anyone has a story about how "that's not enough" I'm eager to hear it. Can't be too careful, can we?
This has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.
Re: Hacking on a plane: Leaking data of millions and taking over any account
#15Earlier quoted context omitted.
This has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.
This has to do with being on a public network (an airplane), does it not? Maybe your outrage is over-the-top.
Re: Hacking on a plane: Leaking data of millions and taking over any account
#16How is something like this not picked up in a pen test? Can only assume there never has been..
Probably because a lot of pen testing is security theatre.
In practice, PCI standards compliance is a mess of people selling "point and click compliance solutions," companies being too big to be properly audited, code churn between audits, companies misleading auditors or hiding key data. Security theater is especially pervasive in PCI compliance.
Re: Hacking on a plane: Leaking data of millions and taking over any account
#17Re: Hacking on a plane: Leaking data of millions and taking over any account
#18> Wednesday (November 23rd) resolution has already been tested and deployed
That's a pretty nice response time - compared to some big companies that are asking security researchers to not disclose vulnerability for six months.
Re: Hacking on a plane: Leaking data of millions and taking over any account
#19How is something like this not picked up in a pen test? Can only assume there never has been..
* run scanner
* print out report
not a lot of deep diving
Re: Hacking on a plane: Leaking data of millions and taking over any account
#20How is something like this not picked up in a pen test? Can only assume there never has been..
so many "pentests" are: * run scanner * print out report not a lot of deep diving