Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

311–313 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#311
post #254

Earlier quoted context omitted.

Median novel has some 65k words. Take all (consecutive) quotes of 2 to 24 words, and you have some 1.5m phrases. Take the top 666k books (apparently there've been about 130m titles been published in total, about 5m in the Amazon Kindle store), and you're at about 1e12 phrases, or 40 bits of entropy, or worse than a password with 7 random letters/digits/symbols. You could probably improve on it considerably by selecti…

I am pretty confident that some phrases would repeat.

True, so even less entropy.

Re: Post a boarding pass on Facebook, get your account stolen

#312
Something I also do which guards against social engineering attacks is that I have a set of fake answers for common "secret questions". These exist nowhere but in my head. I figure it's a extra obfuscation step and could very well be a blocker if anyone was trying to get into any of my accounts.

Re: Post a boarding pass on Facebook, get your account stolen

#313
post #260

Earlier quoted context omitted.

> You're basically evaluating the cryptographic merits of CSV. I am not. I am weighing features vs unintended harm. Yes, the airlines shouldn't be including this data in the barcodes. It is improper to expose end users to this liability. And simply telling them not to expose them isn't a solution. But if FB can detect harmful barcodes in an image, by all means they should remove the photo. This is no different than G…

Is there any data in the barcode that's not also printed (in plain text) on the boarding pass?

There is, that is issue. DoB specifically which in the US is used (dumbly) as PII.
Post reply on HN