Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

281–290 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#281

It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…

> a link directly to the page that would let me make changes to the reservation, with no security barrier at all.

This is most likely intentional.

Most business travel gets booked by assistants / travel agencies / client reps / etc. They are going to use their own account when booking tickets, and then forward reservations or boarding passes to the actual passenger. That passenger then wants to for example reschedule in a hurry when a meeting overruns, or change seats or meal choice without having to explain their seating preferences over the phone (is 25C still available? No? Then get 27A).

Security wise it would be better to have some sort of delegated permissions system, where the travel agent can add email addresses who are allowed to access the booking, you then have to create an account with the airline and prove that you own that email... but I don't see the airlines pissing off their most profitable customer segment with extra hassle to add protection against misforwarded emails.

Re: Post a boarding pass on Facebook, get your account stolen

#282
post #272

Earlier quoted context omitted.

That might have been the theory of security questions early on. But by now I'm sure I've filled out security questions dozens of times. Whatever the intent, from my perspective as a user, they're in the "speed bump" category of security. For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying v…

> For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying via internet form is pretty easy. Walking into a building with 100 cops bearing fake ID is a whole different level. This is a great idea. Not only can the police verify that a given photo ID matches the person in front of them, they can…

The idea sounds nice in theory, but the only reason any administration would implement this would be to remove anonymity from the internet. Your ability to recover accounts would just be a side effect of the system designed to allow the government to track everything you do.

Re: Post a boarding pass on Facebook, get your account stolen

#283

Earlier quoted context omitted.

I mean the "post a boarding pass on Facebook" part.

They were showing off their nice apple hardware and international plane tickets. It's the standard "my life is perfect" instagram user.

What’s the bigger security threat in this scenario?

Re: Post a boarding pass on Facebook, get your account stolen

#284
post #60

Earlier quoted context omitted.

So what's going to happen is that 2 of the same person show up to the plane... and the copy cat goes on the plane and then you check in, and they say, nope, not you. And then you pull your passport. And then they go get the other person off the plane.

And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.

And you get a change notification email and you can the airline and scanner gets arrested

Re: Post a boarding pass on Facebook, get your account stolen

#286
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

I try to leave them unset where I can (probably doesn't help over the phone; I'm thinking more of online accounts), such as on eBay which keeps prompting me to set security questions but going back to the homepage lets me avoid doing so.

For sites that force you to set them (and where I care - otherwise they just get random nonsense), and for my bank, I have a set of plausible but false answers I use. Not bulletproof of course, but definitely not googleable and avoids the "I just set it to something random" attack.

Re: Post a boarding pass on Facebook, get your account stolen

#287
post #193

Earlier quoted context omitted.

Diceware is memorable but not guessable. Source: https://en.wikipedia.org/wiki/Diceware https://www.rempe.us/diceware/#eff

Agreed, but the context was using memorable phrases from literature , in which case they are guessable. Post edited to clarify.

Gotcha. Thanks for the clarification.

Re: Post a boarding pass on Facebook, get your account stolen

#288
post #93

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

I never quite got this "mother's maiden name" thing. Isn't your mother's maiden name... your mother's current name, minus the extra surname she got when she married? Why is this treated as a hard-to-discover information?

It also is from an era when you would assume that a person's mother was in fact married. Less likely today.

Re: Post a boarding pass on Facebook, get your account stolen

#289
post #198

Earlier quoted context omitted.

correct horse battery staple?

This is a reference to the XKCD comic, Password Strength [1]. [1] https://xkcd.com/936/

And for those who think the reference is so well known it doesn't need citing: https://xkcd.com/1053/

Re: Post a boarding pass on Facebook, get your account stolen

#290

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

> The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed…

Yes, you should just make up a fake personal profile, and base your answers on that. True answers and human-bypassable answers are all bad, whereas fake answers open you up to a world full of entropy.
Post reply on HN