Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

451–459 of 459 posts

Re: Bypassing airport security via SQL injection

#451
post #82

Earlier quoted context omitted.

> hiding in Ukraine Huh. Uh, weird choice, given, well, you know…

Maybe not. If you claim to be living in an active warzone and go missing who would look for you? Flee to Western Europe under an assumed identity, get taken in as a refugee?

Assuming you can fluently speak in a language expected of a refugee and are not from a country that has your prints on file...

Re: Bypassing airport security via SQL injection

#452
post #410

Earlier quoted context omitted.

It was the most humongous deal if we talk about IT security. SQL injection shouldn't be a thing in today's IT landscapes. And here we are giving everyone and their mother admin access to a database where the attackers can literally get not only on a plane but also in the fucking Cockpit. So yes, big big deal.

> where the attackers can literally get not only on a plane but also in the fucking Cockpit. You can easily get on a plane, you buy a ticket to board it. People try and succeed to get weapons through TSA checkpoints. I don't know what the idea is though. If you want to shoot and kill someone, do it at the security checkpoint, as happened at Domodedovo. People hijacked planes because the media covered it. You could al…

TSA spends $6.3 billion per year on screening operations. Someone being able to bypass the entire apparatus of airport screening using a SQL injection attack is a really big deal.

Re: Bypassing airport security via SQL injection

#453

Earlier quoted context omitted.

It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…

Part of being a good manager is knowing how to get good folks to give you advice on things you don't understand, and knowing how to follow that advice. Yeah, its hard- but that's a huge part of the whole dang job! No manager (or human) is perfect, mistakes happen- we need to be humble enough to listen and learn from mistakes.

Well said. One of my friends came to cyber management from a legal background. You'd better believe my buddy is calling the most respected nerd in the building when learning about a possible vulnerability. Knowing your technical limitations and where to go to get answers is an important skill for tech managers.

Re: Bypassing airport security via SQL injection

#454
post #90

Earlier quoted context omitted.

Is there any sort of assurance that this wouldn't turn into a prosecution, though? It's not obvious to me on that site. Perhaps the CISA doesn't want to deter researchers, but do they get to make the final call? The DoJ announced in 2022 that they would not prosecute "good faith" security researchers, but it's not binding, just internal policy: https://www.scmagazine.com/analysis/doj-wont-prosecute-good-... The polic…

> Is there any sort of assurance that this wouldn't turn into a prosecution, though? It's not obvious to me on that site. Perhaps the CISA doesn't want to deter researchers, but do they get to make the final call? I don't think any sort of absolute assurance is possible, and if it was given I wouldn't trust it to be permanently binding :-) This is my intuition from having interacted with CISA, and my impression from…

I generally agree with you, but I would worry that an overzealous agency would be fine with finding and reporting the SQL injection vulnerability but object to the author creating an obviously fake record. It's hard to know exactly where the line is.

Re: Bypassing airport security via SQL injection

#455

Earlier quoted context omitted.

That's not really how this works. TSA is maliciously incompetent, but there is a reporting pipeline and procedure for these things that's formalized and designed to protect exactly this kind of good-faith reporting[1]. (It's very easy to believe the worst possible thing about every corner of our government, since every corner of our government has something bad about it. But it's a fundamental error to think that eve…

the more safe way is to have a US congress member read the report into a hearing....as the funny thing is that US has a law and rule that a congress person is not breaking the law if reading something into a hearing...sort of US Congresses own SQL injection....

Even better, it's not a law, it's a provision of the Constitution. Article 1, Section 6 lets members of Congress say whatever they want on the floor.

Re: Bypassing airport security via SQL injection

#456
post #422

Earlier quoted context omitted.

There's also at least one case[1] where the locked door itself stopped someone from stopping the crash (the CA had flying experience and Mentor Pilot[2] showed that even someone with no flying experience could be instructed to autoland if they know how to use the radio. If the CA had entered earlier they might've been able to land, though most of the passengers would've still died unfortunately.) One of the more reas…

1> At 11:49, flight attendant Andreas Prodromou entered the cockpit and sat down in the captain's seat, having remained conscious by using a portable oxygen supply.

Yes, however it's not clear how they entered and why it took them so long (they entered a few minutes before the plane crashed due to fuel exhaustion -- the left engine shut down 50 seconds after he was seen entering the cockpit). It stands to reason that if the door was unlocked they may have been able to enter much earlier, which could've resulted in a very different outcome.

That's why I said "If the CA had entered earlier".

Re: Bypassing airport security via SQL injection

#457

Earlier quoted context omitted.

Not 100% sure how I feel about random companies being able to definitively identify me. I’m sure we’re drifting in that direction anyway, but it feels like it would negatively impact privacy online.

> Not 100% sure how I feel about random companies being able to definitively identify me. But that is not what we are talking about. It is not that you are browsing the web randomly and some random company identifies you as d1sxeyes. It is that you can identify yourself towards any company if you choose to. Then you can decide if that is in your best interest or not.

It also is not necessarily your actual ID. As far as the individual website needs to know, it could just be a random string of numbers and letters. As long as it's the same string each time they ask the authentication authority to confirm you.

Re: Bypassing airport security via SQL injection

#458

Earlier quoted context omitted.

Part of the reason why Crowdstrike have access, why MS wasn't allowed to shut them out with Vista was a regulatory decision, one where they argued that somebody needs to do the job of keeping Windows secure in a way that biased Microsoft can't. So, I guess you could have some sort of escrow third party that isn't Crowdstrike or MS to do this "audit"? Or see this for a much better write up: https://stratechery.com/202…

Replied in another comment, but I’m aware of the regulation that made msft give access. To my knowledge though, there’s nothing in the regulation that stops them from saying “you have to pass xyz (reasonable) tests before we allow you to distribute kernel level software to millions of people”

So, all companies must gatekeep like Apple? By law?

Re: Bypassing airport security via SQL injection

#459

Earlier quoted context omitted.

It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…

This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're exceptionally unqualified for their jobs. Edit: Fixed a double negative (previously: This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're not exceptionally unqualified for their jobs.)

Probably, they can and do understand it. They just have a deny/deflect culture.
Post reply on HN