Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

191–200 of 459 posts

Re: Bypassing airport security via SQL injection

#191
post #126

Earlier quoted context omitted.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

I've written this comment here before, but I'll do it again. "Post-9/11" began minutes after the first planes found their targets. Flight 93—the one that crashed in Pennsylvania—never made it because the passengers revolted after hearing about the other planes. It only took a few minutes for the calculus to change. Knowing what was up, those passengers flipped from wait-and-see mode to fuck-you mode. This is pretty g…

It was a paradigm shift.

This recent video by RealLifeLore drives it home: https://www.youtube.com/watch?v=550EdfxN868&t=1504s

  the last time in history that Sovereign American territory was invaded and occupied by a
  hostile foreign power was between 1942 and 1943 when the Japanese occupied the
  small and sparsely populated Alaskan islands of ATU and Kisa which they struggled to reinforce with supplies and
  were only able to hold on to for a year before getting overrun by much better supplied American and Canadian soldiers
Up until 9/11, the US people had forgotten what it was like to be on defense.

Later in the video: https://youtu.be/550EdfxN868?si=gpTplY4Z36tJPxLv&t=2706

  that doesn't mean that the US cannot be hurt or have its interests disrupted in other ways the US Mainland
  can obviously still become the subject of major attacks from hostile foreign powers if not outright invasions and the
  biggest and worst attack that ever befell the US on its own territory happened recently only 23 years ago

Re: Bypassing airport security via SQL injection

#192

Earlier quoted context omitted.

As my good fortune would have it, I'm called to jury duty two weeks from now. I doubt I'll be sat though. Should I be, I'll keep the above in mind.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, it's the defendant's right. How can I waive the defendant's constitutional right to a trial where jury nullification is a possible outcome?" However, it was a rape trial, where nullification would be an awful outcome (basically saying: yeah, he raped her, but that shouldn't be illegal in this case ... yuck), so I kept my mouth shut. But it still bothers me that the judge was so glib about "waiving" the constitutional rights of the defendant.

Re: Bypassing airport security via SQL injection

#193
post #146

Earlier quoted context omitted.

They tend to specifically choose against people with critical thinking skills.

Everyone says this but when people say "critical thinking skills" it really means "is obvious they will willfully disobey the instructions given to them by the judge and hold their own moral/ethical code above the law." You're literally describing jury nullification in a situation where by the hypothetical judge's instructions they're obviously guilty. I might agree with you that the law is bullshit but by right you…

> hold their own moral/ethical code above the law ... I might agree with you that the law is bullshit

This is the entire reason that we have trial by jury and not trial by judge. I'm not sure how this got lost over the centuries. If 12 of your peers think you did it but the law is bullshit and you shouldn't have your life destroyed because of some stupid technicality in a bullshit law, then you should walk free! I'm aware this has been used to horrible ends in the past (e.g. 12 white jurors nullifying a lynching) but that's a problem with jury selection (and those so-called peers), not with nullification.

> You're literally describing jury nullification in a situation where by the hypothetical judge's instructions they're obviously guilty

Yes, that is the only time nullification is relevant. If a judge can lead the jury to one verdict or another via his instructions, then it's not a trial by jury at all. It's a trial by judge. The founders understood that -- they didn't want a trial by judge. The jury is a check on the judge's power!

Re: Bypassing airport security via SQL injection

#194

Earlier quoted context omitted.

Yes, welcome to the rest of the world.

You're aware that there's a registry per country, no? And that that each country can choose to set aside a subdomain for all government services? Yes, it's unfair that the US gets naked .gov - but that doesn't preclude the rest of the world from doing the right thing, and it certainly doesn't excuse the US government doing the stupid thing.

The US government can still basically yoink any ccTLD very very easily. It won't, but it could.

Re: Bypassing airport security via SQL injection

#195
post #92
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

It’s also just one of those hard things to prove: is TSA actually stopping attacks like 9/11? The simple presence of them might be enough of a deterrent or we might just be extremely lucky. Seems these days the real threat is drunk passengers attacking flight attendants.

Have they caught and arrested any would-be bad guys? Should be pretty easy to verify.

Re: Bypassing airport security via SQL injection

#196
post #185

Earlier quoted context omitted.

This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…

Oh, everyone knows that one single person can make things a lot worse . That's all that's happening here. That doesn't say anything about how much one single person can make things better . In the former case, your powers are amplified by the incompetence of everyone else involved; in the latter case, they are diminished.

Better / worse for whom?

Given the nature of these systems, this 1 person likely made the day to day lives of a lot of people better, providing an (arguably) snappier web interface to existing systems.

Granted, they've probably made someone's day a lot worse with this discovery, but..

Re: Bypassing airport security via SQL injection

#198

Earlier quoted context omitted.

That's not really how this works. TSA is maliciously incompetent, but there is a reporting pipeline and procedure for these things that's formalized and designed to protect exactly this kind of good-faith reporting[1]. (It's very easy to believe the worst possible thing about every corner of our government, since every corner of our government has something bad about it. But it's a fundamental error to think that eve…

the more safe way is to have a US congress member read the report into a hearing....as the funny thing is that US has a law and rule that a congress person is not breaking the law if reading something into a hearing...sort of US Congresses own SQL injection....

I can't decide whether it would be considered an SQL injection or a SSRF attack, actually. I'm leaning towards the latter. Or maybe even a reflected XSS?

Re: Bypassing airport security via SQL injection

#199
post #192

Earlier quoted context omitted.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

I had a very similar situation when I was called. The trial subject was systematic elder abuse and neglect by a person in a position of power at a hospital. I was very glad to not be chosen. I would not have nullified and I did not want to spend weeks hearing about how this woman basically tortured helpless people.

Re: Bypassing airport security via SQL injection

#200

So, the trick here would be to purchase a ticket with a major airline, pack a no-no in your carry-on, and then bypass TSA security by adding yourself to the Known Crew Member list of a small airline using the third-party FlyCASS system, via the SQL-injection. You'd then board the major airline with the no-no. Is that the vulnerability?

Pretty much, although most TsA check lines no longer require even a boarding pass- so in theory you could pack a bomb with you then bypass all the security theater with this.

My presumption was that when you give TSA your ID and they scan it, their systems check that there’s a boarding pass in your name (and DOB)?
Post reply on HN