Live data from Hacker News

Hacking on a plane: Leaking data of millions and taking over any account

rez0.blog

31–40 of 91 posts

Re: Hacking on a plane: Leaking data of millions and taking over any account

#32
post #30

Not related to the content of the article, but to the presentation: that art work in the header is spot on, except maybe for what appears to be tree branches in the window. I think we are witnessing how generative are killing photo stock business.

I think they are supposed to be the ‘wing’

Re: Hacking on a plane: Leaking data of millions and taking over any account

#33
post #23

Earlier quoted context omitted.

These types of fails are generally due to incompetence, in my experience.

This one is 100% due to incompetence. There was no attempt at anything resembling security.

I'm not sure what your experience is, but mine is over multiple decades over multiple companies over multiple continents, and in general, corporate management, project management, and business analysts are not concerned about security.

Instead, they are interested in delivering buttons, fields, and streamlined workflows. Technical debt and library upgrades? Os upgrades? Forget about it. They need to deliver value back to the business in terms of faster business processes.

Only when the business is hacked or they fail compliance does the business leadership start to care.

Blaming the people with the hands on the tools is not fair when the business will not give the resources to do their work properly.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#34
post #32
post #30

Not related to the content of the article, but to the presentation: that art work in the header is spot on, except maybe for what appears to be tree branches in the window. I think we are witnessing how generative are killing photo stock business.

I think they are supposed to be the ‘wing’

I think it might be dragon wings

Re: Hacking on a plane: Leaking data of millions and taking over any account

#35

> Monday (November 21st) the airline was made aware of the issue > Wednesday (November 23rd) resolution has already been tested and deployed That's a pretty nice response time - compared to some big companies that are asking security researchers to not disclose vulnerability for six months.

Especially since the vuln was in a third-party system so the airline couldn't push a fix themselves.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#36

Earlier quoted context omitted.

Yep. It's a shame. I once (long ago :)) alerted our CTO to an ongoing attack in production after seeing some obviously attack-oriented requests coming in and hitting our gateway. It became a pretty high-visibility incident for about 20 minutes until a manager spoke up that his "pen test" was being performed. Looking into the "testing" that was occurring they were attempting to scan for decade-old PHP bugs in a set of…

So, to try and add some value to this conversation vs just reporting a personal anecdote... Do people here have suggestions for actually-good white-hat companies? Can you recommend companies that you've personally worked with who employ knowledgeable security engineers (hackers) to perform real penetration tests and conduct valuable security scans resulting in value-add reports your engineering team can work with? No…

we had a good experience with https://www.praetorian.com/services/penetration-testing/ earlier this year

Re: Hacking on a plane: Leaking data of millions and taking over any account

#37

Earlier quoted context omitted.

Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.

> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…

> Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN?

Going by the same logic, what can a black hat exploiting this bug do if the target ISN'T using a VPN?

Using or not using a VPN in the context of this bug is totally irrelevant.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#38
post #30

Not related to the content of the article, but to the presentation: that art work in the header is spot on, except maybe for what appears to be tree branches in the window. I think we are witnessing how generative are killing photo stock business.

Ew yeah the more you look at it the weirder it gets. Like what's between his fingers, or what is that keyboard layout? Is that supposed to be cash sitting on the armrest, or like a plane ticket?

Re: Hacking on a plane: Leaking data of millions and taking over any account

#39
post #8

The author did not mention if they were rewarded by the bug bounty program. A vulnerability of this severity surely requires a reward of some sort. Does anyone have any more information about whether or not this person was compensated for their work?

And how much they were compensated is also interesting...

Re: Hacking on a plane: Leaking data of millions and taking over any account

#40

Earlier quoted context omitted.

> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…

None of the impact of having your data leaked from your account is in any way modified by using a VPN for your data traffic while you are on the airplane. Hence the initial reply of that your suggestions of a VPN is irrelevant. Don't try to change this into a "oh but the data leak isn't really that bad of a vulnerability" after having lost that argument.

Where do I say "oh but the data leak isn't really that bad of a vulnerability"?

I tried to summarize what the vulnerability is. Why are you so upset about that?

Post reply on HN