Live data from Hacker News

Hacking on a plane: Leaking data of millions and taking over any account

rez0.blog

81–90 of 91 posts

Re: Hacking on a plane: Leaking data of millions and taking over any account

#81

I think the way that airlines handle this is to squash as many seats together as possible so it's not possible to open your laptop to do hacking. Problem solved!

Or even better invest in standing tech and cram like a subway, and fire all the stewardess, make it remote piloted and outsource to the south asian countries to fly it. Security + revenue + cost cuts. All in one shot.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#82
post #46

Earlier quoted context omitted.

Ew yeah the more you look at it the weirder it gets. Like what's between his fingers, or what is that keyboard layout? Is that supposed to be cash sitting on the armrest, or like a plane ticket?

Is he wearing a hoodie or a down jacket, and why is his neck wrap thingie seems to be integrated into the hoodie. Also, he seems to be wearing some sort of leather harness or backpack. Weird stuff!

Since we're already off-topic, I have to say this comment feels like it would fit perfectly about some JRPG protagonist I just haven't heard of.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#83
> I tried customer_id … That also worked!

What did you try exactly?

There's several of these "I changed X and got Y" without ever showing what X is, just alluding to it. That grinds my gears in any blog post, perhaps only second to not stating which version/system some code is running against.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#85
post #8

The author did not mention if they were rewarded by the bug bounty program. A vulnerability of this severity surely requires a reward of some sort. Does anyone have any more information about whether or not this person was compensated for their work?

let's play the guessing game :)

the fact that he mentions the bounty but not the reward means he probably got a reward. If he did not get one, he would have mentioned it.

it was not a ridiculous amount because 1. he would have refused it and talked about it. 2. the money was good enough for him to comply and not cite the companies

was it a large amount ? it could be the reason why he's not telling it. Companies don't want to be spammed by script kiddies attracted by the "largest reward in town".

Re: Hacking on a plane: Leaking data of millions and taking over any account

#86

Earlier quoted context omitted.

so many "pentests" are: * run scanner * print out report not a lot of deep diving

Yep. It's a shame. I once (long ago :)) alerted our CTO to an ongoing attack in production after seeing some obviously attack-oriented requests coming in and hitting our gateway. It became a pretty high-visibility incident for about 20 minutes until a manager spoke up that his "pen test" was being performed. Looking into the "testing" that was occurring they were attempting to scan for decade-old PHP bugs in a set of…

One valuable thing that did come out of that is that it proved your monitoring works and you caught the attack quickly. I also had a similar experience in where we were getting bombarded with alerts from our wifi controller all of sudden. It turned out that a pen tester showed up in the middle of the day and started to run “scans” probably with Nessus or something.

I could have done all of this myself and saved the company tens of thousands of dollars but I think management insisted it came from an outside company. It would be nice though to find an actual pen tester from the back alley of DEFCON who you have to pay in crypto or precious metals and have them do some actual hacking. :)

Re: Hacking on a plane: Leaking data of millions and taking over any account

#87

> Monday (November 21st) the airline was made aware of the issue > Wednesday (November 23rd) resolution has already been tested and deployed That's a pretty nice response time - compared to some big companies that are asking security researchers to not disclose vulnerability for six months.

Yeah is really refreshing, I was expecting the worst like the OP getting banned/sued by the airline and detained by the TSA.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#88

I think the way that airlines handle this is to squash as many seats together as possible so it's not possible to open your laptop to do hacking. Problem solved!

Or even better invest in standing tech and cram like a subway, and fire all the stewardess, make it remote piloted and outsource to the south asian countries to fly it. Security + revenue + cost cuts. All in one shot.

You need 3 remote (contract) pilots, the plane only responds to a quorum of synchronized inputs. Then you can drive the price down as you let them fly multiple planes at the same time. Perhaps even a gig economy play here.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#89

When on any sort of public WiFi network, use a VPN. If anyone has a story about how "that's not enough" I'm eager to hear it. Can't be too careful, can we?

OK, I'm honestly curious, because the idea in my head is this:

Using a VPN to protect you from the dangers of public Wi-Fi is worthless, because HTTPS already does everything VPN companies claim their VPNs do to protect you, such as protecting people from snooping your banking information or redirecting you to some "Wells Fargo But It's A Phishing Frontend" website, because HTTPS provides both encryption and, through certificate verification by way of the browser's own trust store, validation that you're connecting to the domain you think you're connecting to and an MITM attack isn't going on.

If I'm somehow wrong about any part of that, I'd like to know.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#90

> Monday (November 21st) the airline was made aware of the issue > Wednesday (November 23rd) resolution has already been tested and deployed That's a pretty nice response time - compared to some big companies that are asking security researchers to not disclose vulnerability for six months.

Yeah is really refreshing, I was expecting the worst like the OP getting banned/sued by the airline and detained by the TSA.

If I was the author, I'd be kept up at night by the idea of being kidnapped in the middle of the night and whisked off to some black site, however likely or unlikely that is.
Post reply on HN