Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

31–40 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#31
post #15

Earlier quoted context omitted.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Facebook has a billion users. To think that anything someone does there is the first or only time it happens is probably incorrect.

That is a pedantic response. Replace "only" with some mathematically qualified low number of pictures on facebook that have legitimate barcodes in them. Is it more than 1:100_000 photos posted? Probably not.

Re: Post a boarding pass on Facebook, get your account stolen

#32
post #15

Earlier quoted context omitted.

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Isn't embedding QR codes the reason they were created in the first place? It's an optical data format designed to be easy for computers to read.

You're basically evaluating the cryptographic merits of CSV.

Re: Post a boarding pass on Facebook, get your account stolen

#33
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend".

Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk is small because identity theft and authentication hacking is not possible in this case. The Airport is a highly controlled environment and thus someone pulling this will have a higher chance of getting arrested. On contrast, you can't just take anonymous IPs on the Internet for their words. You have to carefully authenticate them and even then you can still have issues.

Re: Post a boarding pass on Facebook, get your account stolen

#34

I get it, be aware of what you post on facebook, but does this not rub anyone else the wrong way? Imagine you break into your friend's car, and rewrire the stereo system so the left speaker doesn't work. Then, you say, "yo, I broke into your car and rewired things. The locks on this car are faulty, better let the car manufacturer know. I should contact them myself and collect my bug bounty." And when your friend, a d…

Analogies almost always make for tedious discussions.

Re: Post a boarding pass on Facebook, get your account stolen

#35
post #33

Earlier quoted context omitted.

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

This is the case I've seen the most. It also really speaks to what is the ultimate security hole which is human error and social engineering. Granted your friend was not being malicious, the fact that it was that easy is scary.

Re: Post a boarding pass on Facebook, get your account stolen

#36
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager

The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

Re: Post a boarding pass on Facebook, get your account stolen

#37
post #15

Earlier quoted context omitted.

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

The issue here is the airlines, not Facebook...

Re: Post a boarding pass on Facebook, get your account stolen

#39
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

I use my real birth date when dealing with my bank or government departments. Everyone else gets the same fictitious but approximately correct date.

Re: Post a boarding pass on Facebook, get your account stolen

#40
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

But the attacker kind of has to know the answer is gibberish from the bat, otherwise they'd either guess or pretend to not remember a real answer, which is noticeably different from saying something like "oh, that's 30 random characters but I don't have the note with me right now".
Post reply on HN