Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

231–240 of 459 posts

Re: Bypassing airport security via SQL injection

#232
post #169
post #82

Earlier quoted context omitted.

> hiding in Ukraine Huh. Uh, weird choice, given, well, you know…

Before he spent some time in Transnistria as well, which is also a weird choice.

It's an excellent choice IMO from his perspective. They grant citizenship after 1 year with not a lot of questions and have a cash economy. And they don't extradite to the US.

Re: Bypassing airport security via SQL injection

#234
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

The real reason is that people make mistakes all the time. There is no shortage of potential mass murderers, are there are plenty of successful ones. But if their plans are too ambitious or involve too many people, they tend to fail due to stupid mistakes. And when those stupid mistakes happen, security agencies (and even ordinary police) have a good chance of catching them.

Re: Bypassing airport security via SQL injection

#235

Earlier quoted context omitted.

This exists in some European countries, in Hungary for example you have an identity service (KAU) which authenticates you and operates as an SSO provider across a number of different government properties. The United States has it, too: https://login.gov But with a government as large as America's it's going to take time to get everyone converted to the new system.

Americans as a whole are so allergic to government doing anything that we can't even get a national ID system nor a centralized database of gun sales or ownership. The bogeyman of evil Big Government, privacy, and censorship gets invoked. It's fine if the Free Market does it, so Google, Facebook, Amazon, Twitter, Microsoft, et al get a free pass.

The "free" market, i.e., government-funded market.

Re: Bypassing airport security via SQL injection

#237
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

That's bc TSA is all theatre. They fail Homeland Security audits more often then they pass. [1]

It's supposed to give you the illusions of security while giving a DHS a bigger budget, and it employs a lot of low skilled workers.

It is what you should think of when you think "big, dumb government."

[1] https://abcnews.go.com/US/tsa-fails-tests-latest-undercover-...

Re: Bypassing airport security via SQL injection

#238
post #197

Why do people even attempto to disclose this? These guy are going to end up with some serious federal charges.

They should just leave the system wide open?

post it on 4chan from behind seven proxies and let full disclosure do its thing

Re: Bypassing airport security via SQL injection

#239
post #126
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

Pilots are also now told to not open the cockpit door, no matter what's happening in the cabin and to land the plane. There is a near 0 change you could take control of the plane. I would be more concerned about someone bringing a bomb on board.

Re: Bypassing airport security via SQL injection

#240

> We did not want to contact FlyCASS first > as it appeared to be operated only by one person > and we did not want to alarm them I’m not buying this. Feels more like they knew the site developer would just fix it immediately and they wanted to make a bigger splash with their findings.

Agreed that they wanted to fully understand the extent of the hack before disclosing
Post reply on HN