Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

11–20 of 459 posts

Re: Bypassing airport security via SQL injection

#12

I hate the TSA with every ounce of my being and these articles reinforce why. Incompetent and useless agency that only serves to waste people's time. Can't believe it still exists; 9/11 and the Bush administration really did a number on this country.

We as a civilization are terrible at getting over things, it seems.

Re: Bypassing airport security via SQL injection

#13
You know it's bad when it's so bad that as I write this no one has even bothered talking about how bad storing MD5'd passwords is. This even proves they aren't even so much as salting it, which is itself insufficient for MD5.

But that isn't even relevant when you can go traipsing through the SQL query itself just by asking; wouldn't matter how well the passwords were stored.

Re: Bypassing airport security via SQL injection

#14
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo.

If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.

Re: Bypassing airport security via SQL injection

#15
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

If anyone from there reads the parent, they should know they have created an atmosphere where the worry of possible prosecution over responsible disclosure has the potential to scare away the best minds in our country from picking at these systems.

That just means the best minds from other, potentially less friendly countries, will do the picking. I doubt they will responsibly disclose.

Re: Bypassing airport security via SQL injection

#16
post #6

A good old SQL injection negates the entire security theatre worth probably billions a year, hilarious, but probably not all too surprising.

Does anyone remember Bruce Schneier and his faked boarding passes? The TSA scribble used to be the weak point of the entire system.

Re: Bypassing airport security via SQL injection

#17
Honestly, this is the most shocking part:

> We did not want to contact FlyCASS first as it appeared to be operated only by one person and we did not want to alarm them

It’s incredible (and entirely too credible) that this kind of “high security” integration could be built in such an amateur way: and a good reminder why government projects often seem to be run with more complexity than your startup devs might think is necessary.

Re: Bypassing airport security via SQL injection

#18
Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents.

It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise and culture of the TSA. Any institution that covers up and ignores existential risks instead of confronting them head on will eventually implode by consequences of its own negligence- which hopefully will happen to the TSA.

Re: Bypassing airport security via SQL injection

#19
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

The statute of limitations is long and HSI often delays their indictment until the investigation is mostly wrapped up.

So you're suggesting they're not out of the woods?

Re: Bypassing airport security via SQL injection

#20
post #12

I hate the TSA with every ounce of my being and these articles reinforce why. Incompetent and useless agency that only serves to waste people's time. Can't believe it still exists; 9/11 and the Bush administration really did a number on this country.

We as a civilization are terrible at getting over things, it seems.

Oh it gets even more amusing. By the logic of the GP, Bush must have impersonated every member of the house and senate because they're not aware of how the TSA came into existence/how a law is created. The Aviation and Transportation Act garnered broad bipartisan support.
Post reply on HN