Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

11–20 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#11
And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question..

My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager

Security questions weakens the security of an account, they are easily found information that people can just guess.

Re: Post a boarding pass on Facebook, get your account stolen

#13
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.)

"You .. give real answers for your security questions? Seriously?"

I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Re: Post a boarding pass on Facebook, get your account stolen

#15
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Re: Post a boarding pass on Facebook, get your account stolen

#16
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

A nice feature would be for them to decode and display the barcode info when you're uploading.

Something like “This image contains the following info: . Would you like us to blur that out? (Y/n)”

Re: Post a boarding pass on Facebook, get your account stolen

#17
post #2

Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…

The real problem is that once again someone treated what should simply be an identifier to look up data as something more. Why not store all this information on the server that an authorized person can see when they scan a uuid on the boarding pass? Would they allow boarding of the network was down?

Re: Post a boarding pass on Facebook, get your account stolen

#19
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Yes, I try to make the fake answer sound legitimate though

City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#!

It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

Re: Post a boarding pass on Facebook, get your account stolen

#20
post #15

Earlier quoted context omitted.

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

I’ve seen people and business pages post Snapchat and LINE QR codes
Post reply on HN