Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

261–270 of 459 posts

Re: Bypassing airport security via SQL injection

#261
post #23

Not surprised that they deny the severity of the issue, but I am quite surprised they didn't inform the FBI and/or try to have you arrested. Baby steps?

Those kind of wheels turn very slowly. I will bet any takers $50 that Ian will be prosecuted.

edit: OK, that's enough takers.

Re: Bypassing airport security via SQL injection

#262
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

> The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

There's plenty of terrorists, but destabilisation of Middle East diverted them away from continental US. Wasn't that the whole point of Afghanistan and Iraq wars?

Re: Bypassing airport security via SQL injection

#263
post #136

Earlier quoted context omitted.

Well, the value is ok, if considered seriously. Also, any certificate bears a certificator company name. We can always say "company A was hacked despite having its security certified by company B". So that company B at least share some blame.

In practice, most commercial attestations/certifications contain enough weasel language that the certifier isn't responsible for anything missed (i.e. reasonable effort only). But yes, there are many standards for this (e.g. SOC Type 2 reports). In defense of their utility, the good ones tend to focus on (a) whether a control/policy for a sensitive operation exists at all in the product/company & (b) whether those co…

Yes, certifiers are not responsible in legal sense, but nothing stops us from posting crap about them on internets.

Re: Bypassing airport security via SQL injection

#264
post #179

Earlier quoted context omitted.

MS could have provided security hooks similar to BPF in Linux, and similar mechanisms with Apple, rather than having Crowdstrike run arbitrary buggy code at the highest privilege level.

They could have, however the timeline the regulators gave Microsoft to comply was incompatible with the amount of work required to build such system. With a legal deadline hanging over their heads Microsoft chose to hand over the keys to their existing tools.

I've seen this stated before, but I haven't been able to find reliable data on when regulators required Microsoft to provide the access that they provided, or whether there's been time to provide a more secure approach. Do you know?

Re: Bypassing airport security via SQL injection

#265
Why does KCM still need to exist? It doesn't help airlines nor air crew:

Pilot: "Years ago we’d get a random enhanced check (which just means go to TSA precheck) now and then. These days it’s 60% of the time, so it’s not possible to get a whole crew through KCM anymore, and we wait on each other because the jet can’t be boarded until the flight attendants are ALL through security, and with the 2022/2023 KCM random checks being so high, that just doesn’t happen. Honestly, I rarely use KCM anymore. I just walk through TSA precheck. The odds are we’re going there anyway so just cut to the chase and hit precheck."[1]

VIP treatments (including the likes of KCM) should be removed no matter if someone is a prime minister[2], media personality[3] or airline CEO. In this way, VIPs can experience the inadequate security processes and staffing levels that everyone else has to deal with, and hopefully with their louder voices will be able to force airports and government agencies to improve the situation for all.

[1] https://www.quora.com/As-a-pilot-how-does-it-feel-like-to-ha...

[2] https://www.theage.com.au/national/red-faces-as-nz-leader-ge...

[3] https://www.smh.com.au/traveller/travel-news/louise-milligan...

Re: Bypassing airport security via SQL injection

#266
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

> The article mentions that FlyCASS seems to be run by one person.

I wonder if they just subcontract everything? One popular hack of the preferences they give to veterans and minorities in government procurement is to have essentially one person fronts that get maximum preference and which subcontract everything to a real company at a markup.

Re: Bypassing airport security via SQL injection

#267

Earlier quoted context omitted.

> The value of those kinds of blanket security audits is questionable, You're totally right. Why are people afraid to say that they're worthless? Why caveat or equivocate? Adversaries in computer security do not mince words.

“Worthless” is quite a strong claim. There isn’t much work I’ve encountered that’s truly “worthless”, even though bad work can make me quite upset. Anyways, that’s why I would often caveat.

I'll say they are worthless because most of time they are dragging time away from things that could improve security. For example, $LastJob we spent a ton of time on SOC2 compliance and despite having applications with known vulnerabilities, we got hacked and ended up all over the news. Maybe of instead of spending all the time getting SOC2 compliance finished, we could have worked at upgrading those apps.

Actually, I doubt they would have upgraded the apps and pocketed the profits instead but SOC2 is providing cover instead of real change.

Re: Bypassing airport security via SQL injection

#268
post #196
post #185

Earlier quoted context omitted.

Oh, everyone knows that one single person can make things a lot worse . That's all that's happening here. That doesn't say anything about how much one single person can make things better . In the former case, your powers are amplified by the incompetence of everyone else involved; in the latter case, they are diminished.

Better / worse for whom? Given the nature of these systems, this 1 person likely made the day to day lives of a lot of people better, providing an (arguably) snappier web interface to existing systems. Granted, they've probably made someone's day a lot worse with this discovery, but..

This is exactly it

It was done for a reason and the fact that it persists despite all odds, means it’s doing something useful

Re: Bypassing airport security via SQL injection

#270
TSA is a $10.4B [1] security theater and mistake born out of fear.

Out of that multibillion dollar budget, TSA allocates $10.4M for “cybersecurity staffing, as well as the development and implementation of enhanced cybersecurity-related measures to improve cyber resiliency across the U.S. Transportation Systems Sector.”

Glad to see our tax dollars working so effectively! \s

What a joke of a country this is

[1] https://www.tsa.gov/news/press/testimony/2023/03/29/fiscal-y...

Post reply on HN