Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

21–30 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#21
post #15

Earlier quoted context omitted.

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Facebook has a billion users. To think that anything someone does there is the first or only time it happens is probably incorrect.

Re: Post a boarding pass on Facebook, get your account stolen

#22
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

Incentives.

Re: Post a boarding pass on Facebook, get your account stolen

#23

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

I do this too, some phone number checks and email checks are surprisingly good.

Re: Post a boarding pass on Facebook, get your account stolen

#24
post #2

Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…

The real problem is that once again someone treated what should simply be an identifier to look up data as something more. Why not store all this information on the server that an authorized person can see when they scan a uuid on the boarding pass? Would they allow boarding of the network was down?

There are procedures in place in case the network is down. I have flown with hand-written boarding passes multiple times in the past (they even had special cards for that situation laying around). On the other hand there were flights that were grounded as there was some network malfunction. I guess it depends on the specific problem they have.

Re: Post a boarding pass on Facebook, get your account stolen

#25
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s.

You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

Re: Post a boarding pass on Facebook, get your account stolen

#26

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

The search space for city names is tragically finite.

There are ~35,000 cities and towns in the U.S., but if you start weighting those by populating (and birthing hospitals and centres), you're going to reduce that count considerably.

https://www.reference.com/geography/many-cities-united-state...

Re: Post a boarding pass on Facebook, get your account stolen

#27
post #15

Earlier quoted context omitted.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Facebook has a billion users. To think that anything someone does there is the first or only time it happens is probably incorrect.

If something is a security issue for 99% of users, the 1% will have to just accept it.

Case in point: app sandboxing. I, for one, don't want it, but it's everywhere.

Re: Post a boarding pass on Facebook, get your account stolen

#28
post #27

Earlier quoted context omitted.

Facebook has a billion users. To think that anything someone does there is the first or only time it happens is probably incorrect.

If something is a security issue for 99% of users, the 1% will have to just accept it. Case in point: app sandboxing. I, for one, don't want it, but it's everywhere.

What if it turns out to be 70/30 or 50/50?

Stuff like this should be configurable or over-ridable, especially when it has legitimate uses.

There will always be a balancing act between features, security and usability, to ram the needle one way and to say 'tough luck' to everybody else is not a solution because then people will try to find ways around the block.

Re: Post a boarding pass on Facebook, get your account stolen

#29
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

[deleted]

Re: Post a boarding pass on Facebook, get your account stolen

#30
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

Aren't all the variations of bar codes just a way to make it easy for computers to read things? What other utility do they have?

It's a hilarious perversion of the technology to use computers to blur the thing we created so computers could read.

Post reply on HN