Live data from Hacker News

How to own an airline in 3 easy steps and grab the TSA nofly list along the way

maia.crimew.gay

1–10 of 677 posts

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#2
Headline buries the real lede a bit in my opinion; the author has gotten a snapshot of the no-fly list from 2019. Presumably the system under attack processes more up-to-date versions of it regularly.

Corresponding news story: https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#3
> with pretty much no skill required

Seriously? I know like none of the tools or terms they used, like wtf is shodan?

In general the author doesn't seem to follow the white hat guidelines, and I'd be worried what they've done is quite illegal (possibly on a federal level if the nofly list is so secret)

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#4
For those unaware, maia is a pretty prolific hacktivist, and it has been indicted by a grand jury for a variety of USA govt penetrations but has USA proceedings on hold until it's extradited, which it's confident won't happen.

https://en.wikipedia.org/wiki/Maia_arson_crimew

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#5

> with pretty much no skill required Seriously? I know like none of the tools or terms they used, like wtf is shodan? In general the author doesn't seem to follow the white hat guidelines, and I'd be worried what they've done is quite illegal (possibly on a federal level if the nofly list is so secret)

maia[0] (it/she pronouns) is almost certainly aware of that this is illegal, and has been indicted by a grand jury for other government hacks.

shodan[1] is a search engine that deals in hosts and ip addresses rather than web pages, and is a goldmine for finding everything from exposed ip webcams to jenkins instances.

[0]: https://en.wikipedia.org/wiki/Maia_arson_crimew

[1]: https://www.shodan.io/

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#6

Headline buries the real lede a bit in my opinion; the author has gotten a snapshot of the no-fly list from 2019. Presumably the system under attack processes more up-to-date versions of it regularly. Corresponding news story: https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...

Also seems to have gotten a crew list from the CommutAir’s CASS or possibly from other airlines as part of the shared deadheading crew list, which includes crew addresses and employment information.

There were also prod AWS credentials in the files exposed in Jenkins.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#7
This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#8

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

Yeah cause we should totally have a top secret no fly list

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#9

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

Am I missing something? It seems Maia didn't share the data at all, and only offers to if someone can demonstrate they will use it responsibly.

Moreover, depending on the contents of the list, this likely offers proof of what is generally suspected, that the no fly list is a form of discrimination and authoritarian overreach, targeting people that haven't been convicted of a crime but are "suspected" due to race, religion, etc. The whole thing is probably unconstitutional/illegal, but it's hard to prove that since it's been secret.

This seems like a clear case of hacktivism- trying to expose an unethical government program for what it is, so that it can be stopped.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#10

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

Yeah cause we should totally have a top secret no fly list

Maybe we should or shouldn't, but the potential victims of this aren't just some greedy corporation. Leaking the no fly list could cause irreparable harm to individuals whose names are on it or even similar, causing discrimination by employers and other organizations.
Post reply on HN