Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

161–170 of 459 posts

Re: Bypassing airport security via SQL injection

#161

Earlier quoted context omitted.

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist

Part of the reason why Crowdstrike have access, why MS wasn't allowed to shut them out with Vista was a regulatory decision, one where they argued that somebody needs to do the job of keeping Windows secure in a way that biased Microsoft can't.

So, I guess you could have some sort of escrow third party that isn't Crowdstrike or MS to do this "audit"?

Or see this for a much better write up: https://stratechery.com/2024/crashes-and-competition/

Re: Bypassing airport security via SQL injection

#162

Earlier quoted context omitted.

That's of course the stupidest possible domain for a government website. (Or at least it's up there) Fundamentally, it has given control over the DNS records to a different country (.me == Montenegro). It's training people that really, any domain could be a government domain, you'll never know.

Yes, welcome to the rest of the world.

You're aware that there's a registry per country, no? And that that each country can choose to set aside a subdomain for all government services?

Yes, it's unfair that the US gets naked .gov - but that doesn't preclude the rest of the world from doing the right thing, and it certainly doesn't excuse the US government doing the stupid thing.

Re: Bypassing airport security via SQL injection

#163

The dudes who did this are going to probably be visited by homeland security or FBI. Not sure what they thought they will get out of this. I don't think the government cares about security, but they are vengeful.

And what will homeland security or the FBI get out of it after concluding that that these "dudes" are two well known talented security researchers trying to conduct responsible disclosure to make air travel safer?

These aren't two dudes acting ethically, these are "two hackers arrested by the FBI for breaking into TSA security", good job FBI!

Re: Bypassing airport security via SQL injection

#164
post #142

Earlier quoted context omitted.

That's of course the stupidest possible domain for a government website. (Or at least it's up there) Fundamentally, it has given control over the DNS records to a different country (.me == Montenegro). It's training people that really, any domain could be a government domain, you'll never know.

Because it's not a government website, it's a company the government contracts with.

Yes. I know how this works. This doesn't change that's it's stupid. You can't outsource stupid and then claim it's not your problem.

Re: Bypassing airport security via SQL injection

#165
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error Because it's a scam and the system is a grift. I'm a pilot and own a private aircraft. Landing at any airport, even my home airport which is restricted by TSA is legal without any special requirement or background check. In fact, I have heard horror stories where TSA wouldn't let a pilot retrieve their aircraft for some bulls…

Just goes to prove that old saying true: "With friends with helicopters, who needs more friends!"

Re: Bypassing airport security via SQL injection

#167
post #54
post #47

Earlier quoted context omitted.

Is this a reference to a past event? I don't get it.

Yes. https://www.reddit.com/r/IAmA/comments/1ahkgc/i_am_weev_i_ma...

Jeez, I just read about him. Was he the first who went down the alt right pipeline? What happened there?

From goatse security to the Daily Stormer.

Re: Bypassing airport security via SQL injection

#168

Earlier quoted context omitted.

They often do. The value of those kinds of blanket security audits is questionable, however. (This is one of the reasons I'm generally pro-OSS for digital infrastructure: security quickly becomes a compliance game at the scale of government, meaning that it's more about diligently completing checklists and demonstrating that diligence than about critically evaluating a component's security. OSS doesn't make software…

> The value of those kinds of blanket security audits is questionable, You're totally right. Why are people afraid to say that they're worthless? Why caveat or equivocate? Adversaries in computer security do not mince words.

I’d rather understate a medium-confidence opinion than overstate it.

Re: Bypassing airport security via SQL injection

#169
post #82

Earlier quoted context omitted.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

> hiding in Ukraine Huh. Uh, weird choice, given, well, you know…

Before he spent some time in Transnistria as well, which is also a weird choice.

Re: Bypassing airport security via SQL injection

#170
post #24

The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.

There's still _plenty_ of time for that to happen. I wouldn't want to be this person right now. I like my dog alive.
Post reply on HN