Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

271–280 of 459 posts

Re: Bypassing airport security via SQL injection

#271
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

It sure would be nice if someday we get to have some TSA-free airlines and TSA-free flights for people that don’t want to get sprayed by ionizing radiation before every flight but don’t fly often enough to warrant a yearly membership fee. It would be interesting to see what people choose if a choice is available.

We haven’t had a large commercial plane go down in over 10 years since 9/11. Everyone that comes to the USA has been fully screened, vetted, and background checked. We’re all very safe. Mayorkis at the DHS has made sure there aren’t any terrorists in our homeland because the government only exists to protect us from danger and make our lives better.

Re: Bypassing airport security via SQL injection

#272

Earlier quoted context omitted.

I'm not saying anyone should be disallowed to run their own authentication. I'm saying we need the digital equivalent of "show me your driver's license".

Would that be https://id.me ? It's what the IRS uses.

And what a steaming pile of dogshit it was when I registered:

"Scan the front and back of your Driver's License."

[upload scan of front of DL @ 200DPI]

"Unable to find a face in the image you uploaded."

[upload scan of front of DL @ 300DPI]

"Unable to find a face in the image you uploaded."

Huh. Maybe I'll try with a lower resolution.

[upload scan of front of DL @ 72DPI]

"Thank you, now please upload the back of your Driver's License."

Hmm, 72DPI worked for the front, so...

[upload scan of back of DL @ 72DPI]

"Unable to read a barcode in the image you uploaded."

[upload scan of back of DL @ 200DPI]

"Unable to read a barcode in the image you uploaded."

[upload scan of back of DL @ 300DPI]

"Thank you for verifying your Driver's License".

Re: Bypassing airport security via SQL injection

#273

Earlier quoted context omitted.

As my good fortune would have it, I'm called to jury duty two weeks from now. I doubt I'll be sat though. Should I be, I'll keep the above in mind.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

Smarter people avoiding jury duty delegates justice to dumber people.

Yeah, I know you're busy and easily bored.

Re: Bypassing airport security via SQL injection

#274
post #169

Earlier quoted context omitted.

Before he spent some time in Transnistria as well, which is also a weird choice.

It's an excellent choice IMO from his perspective. They grant citizenship after 1 year with not a lot of questions and have a cash economy. And they don't extradite to the US.

They'll also not above confiscating your cash and killing you if its suits them. Or (before the war) they wouldn't think twice to send you to Russia to be used as a bargaining chip.

Re: Bypassing airport security via SQL injection

#275
post #126
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

If you can sneak in armed to a jump seat in the cockpit, better cockpit doors are actually in your favour.

Re: Bypassing airport security via SQL injection

#276
post #192

Earlier quoted context omitted.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

> But it still bothers me that the judge was so glib about "waiving" the constitutional rights of the defendant.

Around here, people are clamoring for a judge to be recalled because she is on top of rights for defendants. A recent one I watched on Zoom was a prosecution motion to revoke bail:

Prosecutor: "Because blah blah blah, and in addition the defendant shows no signs of taking responsibility for his actions, we..."

Judge, cutting her off: "I'm going to stop you there. The defendant entered a plea of not guilty, and as of this moment has not been found guilty at trial. In the eyes of the court, he has precisely zero obligation to take responsibility for alleged actions at this point in time."

Prosecutor was not happy.

Re: Bypassing airport security via SQL injection

#277
post #126
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

I would argue, the most effective change post 9/11, is the reinforcement of cockpit doors, and stricter cockpit access procedures.

Re: Bypassing airport security via SQL injection

#278
post #185

Earlier quoted context omitted.

This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…

Oh, everyone knows that one single person can make things a lot worse . That's all that's happening here. That doesn't say anything about how much one single person can make things better . In the former case, your powers are amplified by the incompetence of everyone else involved; in the latter case, they are diminished.

This case is a demonstration of how one person (sorry, two people, Ian & Sam) can make things much better.

Re: Bypassing airport security via SQL injection

#279

Earlier quoted context omitted.

“Worthless” is quite a strong claim. There isn’t much work I’ve encountered that’s truly “worthless”, even though bad work can make me quite upset. Anyways, that’s why I would often caveat.

I'll say they are worthless because most of time they are dragging time away from things that could improve security. For example, $LastJob we spent a ton of time on SOC2 compliance and despite having applications with known vulnerabilities, we got hacked and ended up all over the news. Maybe of instead of spending all the time getting SOC2 compliance finished, we could have worked at upgrading those apps. Actually,…

SOC2 covers a set of vectors (mostly social/separation of controls from what I’ve seen), and you were attacked on another vector.

Maybe the org prioritized poorly and sucks overall, but that doesn’t mean SOC2 or compliance generally is worthless.

Post reply on HN