Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

231–240 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#231

Why do Facebook and Twitter and etc. permit posting of airline QR codes and credit card photos without a safety warning and an option to safely blur out the sensitive bits?

If they'll do this for one case like QR codes on boarding passes, then the question and and expectation will arise, why don't they do it for every other possible case?

This is not their job and not their responsibility, period.

Re: Post a boarding pass on Facebook, get your account stolen

#232

Earlier quoted context omitted.

As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.

>requires the attacker to know you do this Nah, "well, it kinda looks like random characters" is information a support rep will give you. Welcome to social engineering and info escalation.

If the support rep is just giving away enough info to figure this out, there is nothing you can do to protect yourself against the company's policies.

Re: Post a boarding pass on Facebook, get your account stolen

#233

Earlier quoted context omitted.

As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.

As another commenter mentioned, a help desk rep once gave the clue "it's really weird" over the phone, which would easily indicate to an attack to try the mash the keyboard line. The random character thing isn't great for this use, it seems, as a result.

If support reps give enough information away over the phone to let someone guess a security question, there is nothing you can do to protect yourself from them.

Re: Post a boarding pass on Facebook, get your account stolen

#234
post #33

Earlier quoted context omitted.

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

At least here in Brazil, airlines are expected to authenticate you at boarding time and not a second earlier. This is the sanest option too, since they will have to authenticate you at boarding time anyway, and anything earlier will at most cause a mild economical loss for the company.

Re: Post a boarding pass on Facebook, get your account stolen

#235

I get it, be aware of what you post on facebook, but does this not rub anyone else the wrong way? Imagine you break into your friend's car, and rewrire the stereo system so the left speaker doesn't work. Then, you say, "yo, I broke into your car and rewired things. The locks on this car are faulty, better let the car manufacturer know. I should contact them myself and collect my bug bounty." And when your friend, a d…

It could be posting to Instagram, where a good number of people don't have their accounts set to private.

Someone could write a bot to scrape Instagram for photos with #airport #[name of airline] #[airport code], identify photos with tickets, and steal information that way.

Re: Post a boarding pass on Facebook, get your account stolen

#236
post #134
post #60

Earlier quoted context omitted.

And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.

Chances are they'll figure this out before the flight in question lands, and have someone to arrest the scammer at the destination.

At worst, the company is a flight seat in the loss. Is this really worth protecting?

Re: Post a boarding pass on Facebook, get your account stolen

#237
post #181
post #141

Earlier quoted context omitted.

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

I like the appeal (and the book) but I recall, when researching diceware, reading that this is a terrible idea in practice since the entropy is lowered dramatically by using natural language that's already in the public record. Even if they can't put every printed phrase into a lookup table, the probability of certain words following others wrecks the entropy.

Indeed, but for the attack discussed here (someone calls support and pretends they're you) you don't need that much entropy, as you can't test different phrases quickly.

Re: Post a boarding pass on Facebook, get your account stolen

#238
post #229
post #33

Earlier quoted context omitted.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

If you booked the flight together then it is very probable that it's seen in the booking system that you travel together. So it was probably a little bit mor that just his "word". (I'm, however, not judging if it was correct action on the counter stuffs behalf.) A friend of mine was once travelling to Bali and she posted pictures of the boarding pass on Twitter. It was a few weeks after the CCC talk by Karsten Nohl a…

See my other comment: https://news.ycombinator.com/item?id=15319656

Re: Post a boarding pass on Facebook, get your account stolen

#239

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

> The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed…

A fun place for names:

http://www.fantasynamegenerators.com/

Re: Post a boarding pass on Facebook, get your account stolen

#240
post #181
post #141

Earlier quoted context omitted.

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

I like the appeal (and the book) but I recall, when researching diceware, reading that this is a terrible idea in practice since the entropy is lowered dramatically by using natural language that's already in the public record. Even if they can't put every printed phrase into a lookup table, the probability of certain words following others wrecks the entropy.

You just need a larger number of random words to reach the same entropy as random passwords. It's not like your random password is made up from secret alphabets!
Post reply on HN