Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

131–140 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#131

Earlier quoted context omitted.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

I believe the general recommendation I saw was to type something in lines of "never accept this answer - it's probably someone trying to impersonate me | 2DXSDGREDV@#!" (although it's probably hard to do so if the maximum acceptable length is too short)

This is how you get engraved plaques, or birthday cakes, with the message NO MESSAGE JUST LEAVE IT BLANK on them.

Re: Post a boarding pass on Facebook, get your account stolen

#132
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

> The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account

I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed keyboard" line and got in. TL; DR I think this system is less safe than just making up cars, cities, et cetera.

Re: Post a boarding pass on Facebook, get your account stolen

#133
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

Facebook will probably target ads based on scraping data and machine learning from barcodes they recognize -- for their user's convenience of course, then blur them so their competitors can't do the same thing -- for their user's privacy of course.

Re: Post a boarding pass on Facebook, get your account stolen

#134
post #60

Earlier quoted context omitted.

So what's going to happen is that 2 of the same person show up to the plane... and the copy cat goes on the plane and then you check in, and they say, nope, not you. And then you pull your passport. And then they go get the other person off the plane.

And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.

Chances are they'll figure this out before the flight in question lands, and have someone to arrest the scammer at the destination.

Re: Post a boarding pass on Facebook, get your account stolen

#135

Earlier quoted context omitted.

A nice feature would be for them to decode and display the barcode info when you're uploading. Something like “This image contains the following info: . Would you like us to blur that out? (Y/n)”

This image contains the following info: (long line of gibberish, the boarding pass ID) User: srsly fb? OK

Detecting if the embedded data is from a boarding pass is not difficult, nor is parsing it[0] and displaying it in a human-friendly format to "prove" that it's probably sensitive ("The boarding pass you posted belongs to John Smith and contains their American Airlines frequent flyer number. Are you sure you want to share this?")

[0] https://www.iata.org/whatwedo/stb/Documents/BCBP-Implementat...

Re: Post a boarding pass on Facebook, get your account stolen

#136
post #123
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

My bank's terms of service bans recording passwords - ie managers.

Wow. What bank?

Re: Post a boarding pass on Facebook, get your account stolen

#137
post #105

Earlier quoted context omitted.

It's not about what you say, it's about what an attacker can get away with saying. And they can almost certainly get away with "I just mash the keyboard."

Ah, I see what you mean. Perhaps instead of grabbing a handful of characters from /dev/urandom, you generate a passphrase (a few random dictionary words)?

Been doing this for several years and prefer this method. I also try to reduce the number of times I use a particular security question. However, I don't think the problem comes from what questions you use or what answers you provide. It becomes like others have pointed out, a problem of what a hacker can get away with answering when asked by a phone representative. Although, I do think this approach provides a little more security than just answering the "what city were you born in" question with the correct answer on every site.

Re: Post a boarding pass on Facebook, get your account stolen

#138
post #81

Earlier quoted context omitted.

Not just easier, but actually more safe. The person on the phone isn't usually aware about your security "paranoia" and is being evaluated on how much customers he/she has been able to help. As such most helpdesk employees will accept the answer "Oh I forgot, I do remember I put some random characters in there"... and your random password end up not helping you after all.

As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.

As another commenter mentioned, a help desk rep once gave the clue "it's really weird" over the phone, which would easily indicate to an attack to try the mash the keyboard line.

The random character thing isn't great for this use, it seems, as a result.

Re: Post a boarding pass on Facebook, get your account stolen

#140
post #2

Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…

Is the problem the airline or the person posting it online?
Post reply on HN