Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

371–380 of 459 posts

Re: Bypassing airport security via SQL injection

#371
post #351

Earlier quoted context omitted.

You don't have to pretend to be a pilot. Any cabin crew is allowed in the cockpit, AFAIK

Not just cabin crew, a lot of the time anyone flying standby is offered the jumpseat if there are no other seats available out of courtesy. Especially if they are an airline employee, but often non-employees too.

In US, and I imagine elsewhere....this is completely untrue for any commercial flights or honestly anything carrying legitimate insurance.

I have never heard of a plain clothes non-employee in cockpict jumpseat.

Re: Bypassing airport security via SQL injection

#373
post #212

Earlier quoted context omitted.

Have they caught and arrested any would-be bad guys? Should be pretty easy to verify.

Well Guantanamo Bay still exists. From https://en.m.wikipedia.org/wiki/Guantanamo_Bay_detention_cam... : > As of August 2024, at least 780 persons from 48 countries have been detained at the camp since its creation, of whom 740 had been transferred elsewhere, 9 died in custody, and 30 remain; only 16 detainees have ever been charged by the U.S. with criminal offenses. Given what we do know about the secretive and ill…

780 persons - 740 persons transferred - 9 persons dead = 31 persons that should remain. Oh wiki.

Re: Bypassing airport security via SQL injection

#374

Earlier quoted context omitted.

And what will homeland security or the FBI get out of it after concluding that that these "dudes" are two well known talented security researchers trying to conduct responsible disclosure to make air travel safer?

These aren't two dudes acting ethically, these are "two hackers arrested by the FBI for breaking into TSA security", good job FBI!

Made the world a safer place again, by capturing two evil terrorists! Also: Good that our security is impenetrable, as we can see here!

Re: Bypassing airport security via SQL injection

#376
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

[deleted]

Re: Bypassing airport security via SQL injection

#377

The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

[flagged]

Re: Bypassing airport security via SQL injection

#378

Earlier quoted context omitted.

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…

Good observation! This person is obviously meeting a need, and probably doing pretty well for themselves, SQL injection and all.

> The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…”

Yup. This is something on the order of a large-scale blackpill meme lately. Comment sections are usually rife with low-agency thinking. Which is quite something in tech, given that devs are the means of production for tech. True, tech as of late seems to be veering into more capital-heavy ventures (AI), probably to head off existential risk from the fact that a few skilled individuals can still really make a dent.

It all comes down to belief and will.

Re: Bypassing airport security via SQL injection

#379
post #24

The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.

[deleted]

Re: Bypassing airport security via SQL injection

#380
post #185

Earlier quoted context omitted.

This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…

Oh, everyone knows that one single person can make things a lot worse . That's all that's happening here. That doesn't say anything about how much one single person can make things better . In the former case, your powers are amplified by the incompetence of everyone else involved; in the latter case, they are diminished.

When things go well nobody notices. I’ve certainly headed off and found/fixed a lot of bad decisions in my career, some of my own included. There was a lot of impact there, and it’s good when it’s invisible!
Post reply on HN