Earlier quoted context omitted.
> hiding in Ukraine Huh. Uh, weird choice, given, well, you know…
Maybe not. If you claim to be living in an active warzone and go missing who would look for you? Flee to Western Europe under an assumed identity, get taken in as a refugee?
Bypassing airport security via SQL injection
451–459 of 459 posts
Re: Bypassing airport security via SQL injection
#452Earlier quoted context omitted.
It was the most humongous deal if we talk about IT security. SQL injection shouldn't be a thing in today's IT landscapes. And here we are giving everyone and their mother admin access to a database where the attackers can literally get not only on a plane but also in the fucking Cockpit. So yes, big big deal.
> where the attackers can literally get not only on a plane but also in the fucking Cockpit. You can easily get on a plane, you buy a ticket to board it. People try and succeed to get weapons through TSA checkpoints. I don't know what the idea is though. If you want to shoot and kill someone, do it at the security checkpoint, as happened at Domodedovo. People hijacked planes because the media covered it. You could al…
Re: Bypassing airport security via SQL injection
#453Earlier quoted context omitted.
It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…
Part of being a good manager is knowing how to get good folks to give you advice on things you don't understand, and knowing how to follow that advice. Yeah, its hard- but that's a huge part of the whole dang job! No manager (or human) is perfect, mistakes happen- we need to be humble enough to listen and learn from mistakes.
Re: Bypassing airport security via SQL injection
#454Earlier quoted context omitted.
Is there any sort of assurance that this wouldn't turn into a prosecution, though? It's not obvious to me on that site. Perhaps the CISA doesn't want to deter researchers, but do they get to make the final call? The DoJ announced in 2022 that they would not prosecute "good faith" security researchers, but it's not binding, just internal policy: https://www.scmagazine.com/analysis/doj-wont-prosecute-good-... The polic…
> Is there any sort of assurance that this wouldn't turn into a prosecution, though? It's not obvious to me on that site. Perhaps the CISA doesn't want to deter researchers, but do they get to make the final call? I don't think any sort of absolute assurance is possible, and if it was given I wouldn't trust it to be permanently binding :-) This is my intuition from having interacted with CISA, and my impression from…
Re: Bypassing airport security via SQL injection
#455Earlier quoted context omitted.
That's not really how this works. TSA is maliciously incompetent, but there is a reporting pipeline and procedure for these things that's formalized and designed to protect exactly this kind of good-faith reporting[1]. (It's very easy to believe the worst possible thing about every corner of our government, since every corner of our government has something bad about it. But it's a fundamental error to think that eve…
the more safe way is to have a US congress member read the report into a hearing....as the funny thing is that US has a law and rule that a congress person is not breaking the law if reading something into a hearing...sort of US Congresses own SQL injection....
Re: Bypassing airport security via SQL injection
#456Earlier quoted context omitted.
There's also at least one case[1] where the locked door itself stopped someone from stopping the crash (the CA had flying experience and Mentor Pilot[2] showed that even someone with no flying experience could be instructed to autoland if they know how to use the radio. If the CA had entered earlier they might've been able to land, though most of the passengers would've still died unfortunately.) One of the more reas…
1> At 11:49, flight attendant Andreas Prodromou entered the cockpit and sat down in the captain's seat, having remained conscious by using a portable oxygen supply.
That's why I said "If the CA had entered earlier".
Re: Bypassing airport security via SQL injection
#457Earlier quoted context omitted.
Not 100% sure how I feel about random companies being able to definitively identify me. I’m sure we’re drifting in that direction anyway, but it feels like it would negatively impact privacy online.
> Not 100% sure how I feel about random companies being able to definitively identify me. But that is not what we are talking about. It is not that you are browsing the web randomly and some random company identifies you as d1sxeyes. It is that you can identify yourself towards any company if you choose to. Then you can decide if that is in your best interest or not.
Re: Bypassing airport security via SQL injection
#458Earlier quoted context omitted.
Part of the reason why Crowdstrike have access, why MS wasn't allowed to shut them out with Vista was a regulatory decision, one where they argued that somebody needs to do the job of keeping Windows secure in a way that biased Microsoft can't. So, I guess you could have some sort of escrow third party that isn't Crowdstrike or MS to do this "audit"? Or see this for a much better write up: https://stratechery.com/202…
Replied in another comment, but I’m aware of the regulation that made msft give access. To my knowledge though, there’s nothing in the regulation that stops them from saying “you have to pass xyz (reasonable) tests before we allow you to distribute kernel level software to millions of people”
Re: Bypassing airport security via SQL injection
#459Earlier quoted context omitted.
It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…
This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're exceptionally unqualified for their jobs. Edit: Fixed a double negative (previously: This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're not exceptionally unqualified for their jobs.)