Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

421–430 of 459 posts

Re: Bypassing airport security via SQL injection

#421
post #410

Earlier quoted context omitted.

It was the most humongous deal if we talk about IT security. SQL injection shouldn't be a thing in today's IT landscapes. And here we are giving everyone and their mother admin access to a database where the attackers can literally get not only on a plane but also in the fucking Cockpit. So yes, big big deal.

> where the attackers can literally get not only on a plane but also in the fucking Cockpit. You can easily get on a plane, you buy a ticket to board it. People try and succeed to get weapons through TSA checkpoints. I don't know what the idea is though. If you want to shoot and kill someone, do it at the security checkpoint, as happened at Domodedovo. People hijacked planes because the media covered it. You could al…

Or you could buy a real ticket, bypass security with this (and whatever you have in your bags), then hijack an international flight full of fuel.

This isn’t hard to exploit.

Re: Bypassing airport security via SQL injection

#422

Earlier quoted context omitted.

Which, ironically, made it impossible to prevent this crash: https://en.wikipedia.org/wiki/Germanwings_Flight_9525

This is easily prevented by requiring at least 2 people in the cockpit at all times. Some airlines had this policy long before Germanwings happened.

There's also at least one case[1] where the locked door itself stopped someone from stopping the crash (the CA had flying experience and Mentor Pilot[2] showed that even someone with no flying experience could be instructed to autoland if they know how to use the radio. If the CA had entered earlier they might've been able to land, though most of the passengers would've still died unfortunately.)

One of the more reasonable theories for MH370 is similar to the Germanwings case. Pilots can refuse access even if the person outside knows the access codes for the cockpit doors.

Unfortunately (as with everything else), even obvious improvements have potential downsides.

[1]: https://en.m.wikipedia.org/wiki/Helios_Airways_Flight_522 [2]: https://www.youtube.com/watch?v=YaOvtL6qYpc

Re: Bypassing airport security via SQL injection

#423

Earlier quoted context omitted.

I've written this comment here before, but I'll do it again. "Post-9/11" began minutes after the first planes found their targets. Flight 93—the one that crashed in Pennsylvania—never made it because the passengers revolted after hearing about the other planes. It only took a few minutes for the calculus to change. Knowing what was up, those passengers flipped from wait-and-see mode to fuck-you mode. This is pretty g…

It was a paradigm shift. This recent video by RealLifeLore drives it home: https://www.youtube.com/watch?v=550EdfxN868&t=1504s the last time in history that Sovereign American territory was invaded and occupied by a hostile foreign power was between 1942 and 1943 when the Japanese occupied the small and sparsely populated Alaskan islands of ATU and Kisa which they struggled to reinforce with supplies and were only ab…

> were only able to hold on to for a year before getting overrun by much better supplied American and Canadian soldiers

Not especially accurate. The US and Canadian forces that landed on Kiska had no opposition because the Japanese had already left. They did not overrun Japanese forces that were not there.

Wikipedia describes this as: "On 15 August 1943, 1st SSF was part of the invasion force of the island of Kiska, but after discovering that the island had been recently evacuated by Japanese forces, it re-embarked ..."

And yet, there were still friendly fire casualties, a point omitted from many descriptions of the invasion.

Re: Bypassing airport security via SQL injection

#424

Earlier quoted context omitted.

My presumption was that when you give TSA your ID and they scan it, their systems check that there’s a boarding pass in your name (and DOB)?

I don’t think so- I believe it just checks the outstanding warrant/no fly list and that’s all, but I could be wrong.

No, it checks that you have a boarding pass: https://www.tsa.gov/travel/security-screening/credential-aut...

> CAT is linked electronically to the Secure Flight database, which confirms travelers’ flight details, ensuring they are ticketed for travel that day.

Re: Bypassing airport security via SQL injection

#425

Earlier quoted context omitted.

This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're exceptionally unqualified for their jobs. Edit: Fixed a double negative (previously: This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're not exceptionally unqualified for their jobs.)

> If the managers involved here can't understand why this is a huge deal Was it a huge deal though?

If this is not a huge deal, than we don’t really need the TSA at all.

Re: Bypassing airport security via SQL injection

#426
post #192

Earlier quoted context omitted.

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

Which countries make Jury Nullification a constitutional right for defendants? I looked at the wikipedia article (US section), and it only refers to it as power possessed by a jury.

If a defendant has the constitutional right to trial by a jury, and that jury has autonomy to make an independent decision, then jury nullification is a possible outcome.

If jury nullification is not a possible outcome, then either the defendant doesn't have a right to trial by jury, or that jury is not allowed to make an independent decision.

Defendants don't have a direct constitutional right to jury nullification (the Constitution doesn't say anything about nullification). It's just a logical consequence: if the jury really can make independent decisions, then nullification is necessarily one of those possible decisions.

Re: Bypassing airport security via SQL injection

#427
post #192

Earlier quoted context omitted.

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

Which countries make Jury Nullification a constitutional right for defendants? I looked at the wikipedia article (US section), and it only refers to it as power possessed by a jury.

Impliedly all countries that have jury trials. But most of those deny this explicitly somewhere, typically in statutes or convention.

Re: Bypassing airport security via SQL injection

#428

Earlier quoted context omitted.

Overt U.S. meddling began (and in a very significant way) in 1956 with the Suez Crisis. The US had nothing to do with Israel forming beyond being part of the UN vote True for the U.S. at the government -- but not for the U.S. as a country. One of the earliest major Zionist associations (the Federation of Zionist Societies - a forerunner of the modern ZOA) was formed in New York in 1897. The movement would continue to…

[flagged]

The US intervened AGAINST Israel, Britain, and France during the Suez crisis, in favor of the Arabs.

Not against Israel (and certainly not in favor of the Arabs) - but rather against Dayan and Ben-Gurion's strategy of calculated provocations against Syria and Egypt. Dulles had actually decided in favor of providing arms to Israel by the end of late 1955. But his hand was tipped by Israel's severely destabilizing actions (most notably Operation Olive Leaves), and most decisively by Ben-Gurion's calculated decision to also conceal these plans from Washington.

The other narratives that you're presenting above are similarly problematic. You aren't even using the term Zionism correctly. It isn't about the geographic origins of the Jewish people; but rather specifically about the idea of setting up a 19th century-style nation-state in their interest (and of resettling large numbers of people to a place where their ancestors had not set foot in for well over a millenium) -- by definition (and in every dictionary and encyclopedia definition you will find) an intrinsically modern concept. Nor is it "core" to Jewish people in general, only to some.

I wish we could explore these topics further. Unfortunately, you are attributing statements to me that I simply didn't make (I never said that the American Zionists were "the center of the movement", or even remotely implied as much), which, on top of the multiplicity of broken narratives you are presenting here, suggests that continued discussion is unlikely to be productive.

Re: Bypassing airport security via SQL injection

#429
post #370

Earlier quoted context omitted.

I find it amusing (actually more tragic than amusing) that the same politicians who tell us all day that corporations can't be trusted because they are run by people with character flaws (greed, lying, laziness, etc.); will turn around and tell us that handing more power and influence over to a government agency is a good idea. They make it sound like the job pool between the public and private sector is completely s…

What mythical private sector accountability are we talking about? A government agency didn’t build the software, it was a one man, private sector company. Maybe the moral is not outsourcing every last thing in existence?

Not always, but often the marketplace will punish you if you screw up royally as a private company or employee. It seems that nearly every government snafu results in a promotion.

Re: Bypassing airport security via SQL injection

#430

Earlier quoted context omitted.

[flagged]

The US intervened AGAINST Israel, Britain, and France during the Suez crisis, in favor of the Arabs. Not against Israel (and certainly not in favor of the Arabs) - but rather against Dayan and Ben-Gurion's strategy of calculated provocations against Syria and Egypt. Dulles had actually decided in favor of providing arms to Israel by the end of late 1955. But his hand was tipped by Israel's severely destabilizing acti…

> You aren't even using the term Zionism correctly.

Many active zionists use the term this way, and not in the way you do. Secular Zionism of Hertzl was indeed more prominent, but already in 1902, Mizrahi organisation already saw a completely different concept of zionism, which didn't identify itself with European nation-state nationalism of 19th century. Ironically, both of these views are still Ashkenazi inventions. But most of israelis are not Ashkenazi, but Mizrahim. Role of Jerusalem in these communities, desire to live in historical Israel and restoration of Jewish state of Palestine is something which is completely forgotten.

And while zionism as state-building was not the focus of the jews, zionism as resettling to Israel was always a thing. My own family has been dispersed after expultion from Spain, and while most moved to Italy, some people (I forget the name) decided to move to Jerusalem instead. There always were sizable Jewish communities in the area, and immigrating there was a decision that people did take sometimes.

Post reply on HN