Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

221–230 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#221
post #32

Earlier quoted context omitted.

Isn't embedding QR codes the reason they were created in the first place? It's an optical data format designed to be easy for computers to read. You're basically evaluating the cryptographic merits of CSV.

> You're basically evaluating the cryptographic merits of CSV. I am not. I am weighing features vs unintended harm. Yes, the airlines shouldn't be including this data in the barcodes. It is improper to expose end users to this liability. And simply telling them not to expose them isn't a solution. But if FB can detect harmful barcodes in an image, by all means they should remove the photo. This is no different than G…

>This is no different than Github scanning for AWS creds or MongoDB passwords in repos.

But Github doesn't do that either.

Amazon pays a contractor to scan Github repos for keys.

Re: Post a boarding pass on Facebook, get your account stolen

#223

Just to clarify in case someone assumes the same thing I did from the headline: it isn't the Facebook account that gets stolen, but the airline website account.

It seems the attacker/pen-tester got access to the guy's passport number. I wonder how easy it would be to do identify theft and gain entry into other accounts.

A much better title would be: Post a boarding pass online, get your identity stolen.

Re: Post a boarding pass on Facebook, get your account stolen

#224

Earlier quoted context omitted.

Because he's an information security expert.

I mean the "post a boarding pass on Facebook" part.

They were showing off their nice apple hardware and international plane tickets. It's the standard "my life is perfect" instagram user.

Re: Post a boarding pass on Facebook, get your account stolen

#225
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

For security questions for sites I dont care about, I pick the subjedt of the question and use that: "What city were you born in" == "city" "what was the name of your first pet?" == "pet" etc.

I use profane language since in my opinion the answer should still be hashed if I'm verifying it through the website.

Mom's maiden name: InfectedPussyPimple

How she got dad, I'll never know!

Re: Post a boarding pass on Facebook, get your account stolen

#226
post #162

Earlier quoted context omitted.

Necronomicon quote? Nice. This has me thinking about what I can do to make my security answers to security questions untethered from PII. A book quote is a really good idea.

Close! Cryptonomicon. I'm guessing that having every book loaded into a password cracking database, subdivided and indexed by each leading phrase word, is still computationally infeasible for non-government actors.

No need to have every book loaded, only the top 50000~ read by people who would use that method of passphrase generation should work fine (and be feasible for almost everyone). Cryptonomicon would probably be in that list.

Re: Post a boarding pass on Facebook, get your account stolen

#227

Why do Facebook and Twitter and etc. permit posting of airline QR codes and credit card photos without a safety warning and an option to safely blur out the sensitive bits?

Because it would be ridiculous to make Facebook and Twitter part of that security perimeter.

Relevant xkcd: https://xkcd.com/463/ ("You're doing it wrong")

Re: Post a boarding pass on Facebook, get your account stolen

#228
post #207

Earlier quoted context omitted.

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

The problem is that anything which you remember that well is likely to be discoverable by other people. For instance, if someone's mother is dead there's a good chance that her obituary will be online and list the names of her children and her maiden name. Likewise, you could find the name of a person's elementary school via looking at their posts on Facebook in many cases - or if not their posts, then their siblings or their friends. So these kinds of questions are hardly a great proof of identity if it can be found online with a bit of searching.

Re: Post a boarding pass on Facebook, get your account stolen

#229
post #33

Earlier quoted context omitted.

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

If you booked the flight together then it is very probable that it's seen in the booking system that you travel together. So it was probably a little bit mor that just his "word". (I'm, however, not judging if it was correct action on the counter stuffs behalf.)

A friend of mine was once travelling to Bali and she posted pictures of the boarding pass on Twitter. It was a few weeks after the CCC talk by Karsten Nohl and Nemanja Nikodijevic (https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme...), so I warned her that it might be not the best idea to post these images. She was very self-assured and replied that she's almost in the plane so there's not much risk.

I've asked if it would be OK for me to test and she was fine with it. I could log in to her booking without problems (booking code and the name which I knew anyway were on the images). In the system I saw the other person she was travelling with., I could change seats and names of passengers. I think I could even change the date of the flight back (but I'm no longer sure about it).

But this is how I'm pretty sure that if you've booked together, this might habe been visible in the booking system.

Re: Post a boarding pass on Facebook, get your account stolen

#230
post #207

Earlier quoted context omitted.

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

Hum... I'd say that the entire point of security question is that incompetent people can appease non-technical bosses by claiming that they follow best practices.

Where they stand at the security line is irrelevant, because their mere existence on a place is already a symptom of a deep level of incompetence and an almost sure prediction of a compromised system. Besides, security is usually chain-like (compromise one node and it's broken), not army-like (compromise one node and you'll have to fight the next).

Besides, most people do not have a favorite color, do not remember the name of their 3rd grade teacher, and have severe doubts about what counts as their "first" pet. Yes, they are intended into solving a real problem, but nothing about them survives any amount of questioning.

Post reply on HN