Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

391–400 of 459 posts

Re: Bypassing airport security via SQL injection

#391

Earlier quoted context omitted.

Pilots are also now told to not open the cockpit door, no matter what's happening in the cabin and to land the plane. There is a near 0 change you could take control of the plane. I would be more concerned about someone bringing a bomb on board.

The thing with this hack though is that it seems to be able to greenlight someone pretending to be staff to enter the cockpit as a passenger.

How did they get the keycode? It’s basically two factor. You need both the code and the pilot allowing you in.

I’m pretty sure there is a second code on some planes that alerts the pilots someone is attempting to force the crew to open the door.

Re: Bypassing airport security via SQL injection

#392
post #192

Earlier quoted context omitted.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

Which countries make Jury Nullification a constitutional right for defendants? I looked at the wikipedia article (US section), and it only refers to it as power possessed by a jury.

Re: Bypassing airport security via SQL injection

#393

Earlier quoted context omitted.

The first bullet point on the /partners page of login.gov (regarding who should use it) says: > You are part of a federal agency or a state, local, or territory government I'm talking about a more generic service that any random industry system or individual can use. The way many websites use Google's OAuth without using really using Google's APIs. Things that just want someone else (Google) to handle asking for and…

Not 100% sure how I feel about random companies being able to definitively identify me. I’m sure we’re drifting in that direction anyway, but it feels like it would negatively impact privacy online.

> Not 100% sure how I feel about random companies being able to definitively identify me.

But that is not what we are talking about. It is not that you are browsing the web randomly and some random company identifies you as d1sxeyes.

It is that you can identify yourself towards any company if you choose to. Then you can decide if that is in your best interest or not.

Re: Bypassing airport security via SQL injection

#394

Earlier quoted context omitted.

>destabilisation of Middle East diverted them away from continental US I put on my critical thinking hat and look at the timeline of "US meddling in the Middle East" and "first terror attack in the US by a middle eastern". I then notice that the years are 1948 and 1993 respectively and that wet roads actually do not cause rain after all.

I assume by 1948 you mean Israel’s declaration and subsequent war of independence. The US had nothing to do with Israel forming beyond being part of the UN vote - Britain was the architect of this part of the Middle East and is responsible for every border drawn by all nations there. This was fallout of the Ottoman Empire choosing to go to war against Western Europe and being defeated (after hundreds of years of inco…

Overt U.S. meddling began (and in a very significant way) in 1956 with the Suez Crisis.

The US had nothing to do with Israel forming beyond being part of the UN vote

True for the U.S. at the government -- but not for the U.S. as a country. One of the earliest major Zionist associations (the Federation of Zionist Societies - a forerunner of the modern ZOA) was formed in New York in 1897. The movement would continue to receive key funding from American backers, and held one of its key meetings in New York in 1942:

https://en.wikipedia.org/wiki/Biltmore_Conference

The movement's ideological (some would even say "spiritual") underpinnings can be traced to the mid-19th century writings of this American playwright and utopian activist - said to be the originator of the idea of resettling Jews in Palestine, predating the efforts Herzl himself by half a century:

https://en.wikipedia.org/wiki/Mordecai_Manuel_Noah

So American meddling in the region goes back quite far indeed.

Re: Bypassing airport security via SQL injection

#395

Makes you wonder why there were no plane hijacks since 9/11. TSA does not seem a credible prevention mechanism given how easy it is to go around it.

Because you can't get near the pilots anymore, and because everybody assumes a hijack is suicidal and reacts accordingly.

Re: Bypassing airport security via SQL injection

#396

So, the trick here would be to purchase a ticket with a major airline, pack a no-no in your carry-on, and then bypass TSA security by adding yourself to the Known Crew Member list of a small airline using the third-party FlyCASS system, via the SQL-injection. You'd then board the major airline with the no-no. Is that the vulnerability?

Sounds like you get to sit in the cockpit too?

Yes you could sit in the third seat, the jumper seat, with this. I feel like one could already sneak something malicious through TSA (this already happens and if you attempt it enough times eventually you'll get through), but being able to sit in the freaking cockpit behind the pilots who assume you're another pilot is CRAZY.

Re: Bypassing airport security via SQL injection

#397

Earlier quoted context omitted.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

How do you have a conviction temporarily overturned? I thought the US had rules about double jeopardy. Unless you're referring to some other charges he hasn't been tried for.

They ruled it was tried in the wrong jurisdiction thus basically never happened. There is likely a sealed indictment awaiting in another jurisdiction where they will try again, now knowing the trial strategy of the defense.

Re: Bypassing airport security via SQL injection

#398

The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…

Part of being a good manager is knowing how to get good folks to give you advice on things you don't understand, and knowing how to follow that advice. Yeah, its hard- but that's a huge part of the whole dang job!

No manager (or human) is perfect, mistakes happen- we need to be humble enough to listen and learn from mistakes.

Re: Bypassing airport security via SQL injection

#399

The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…

>> The TSA's response here is childish and embarrassing,

> It’s very hard for management, even IT managers,

I'm confident that the grandparent's comment is correct.

TSA is closer to the issue than HSA; I'd wager big that they sense embarrassment.¹²

TSA management would have immediate access to people capable of framing the issue correctly, including their own parent agency. Their reaction was never going to be held back by technical facts.

    ¹ US Sec/LEO/IC agencies have a long and unbroken history of attacking messengers that bring embarrassment. There is ~no crime they are more dedicated to punishing.

    ² The worlds easiest presupposition: Discussions took/are taking place on how they might leverage the CFAA to deploy revenge against the author.

Re: Bypassing airport security via SQL injection

#400

Earlier quoted context omitted.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

How do you have a conviction temporarily overturned? I thought the US had rules about double jeopardy. Unless you're referring to some other charges he hasn't been tried for.

Overturning a conviction is usually permanent, however, that does not necessarily mean the verdict becomes Not Guilty, and only when the verdict is Not Guilty does double jeopardy come into play. It is possible for a higher court to overturn a lower courts decision, have it returned for reconsideration, or even a whole retrial. In other cases a higher court will overturn a verdict and instruct the lower court the change the verdict to Not Guilty.
Post reply on HN