Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

51–60 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#51
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Doesn't matter if you give your real bday or not. I could easily google you, email one of your coworkers and ask for your birthday for a secret gift. Voila.

Re: Post a boarding pass on Facebook, get your account stolen

#52

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

Doesn't matter if you give your real bday or not. I could easily google you, email one of your coworkers and ask for your birthday for a secret gift. Voila.

Ignore my last comment. I didn't follow your logic of putting a fake birthday into the site haha. Doh!

Re: Post a boarding pass on Facebook, get your account stolen

#53
post #34

I get it, be aware of what you post on facebook, but does this not rub anyone else the wrong way? Imagine you break into your friend's car, and rewrire the stereo system so the left speaker doesn't work. Then, you say, "yo, I broke into your car and rewired things. The locks on this car are faulty, better let the car manufacturer know. I should contact them myself and collect my bug bounty." And when your friend, a d…

Analogies almost always make for tedious discussions.

I grant you that. I am trying to make a general point about whether you should do 'x' just because you can or to prove a point.

Re: Post a boarding pass on Facebook, get your account stolen

#54
post #47

I get it, be aware of what you post on facebook, but does this not rub anyone else the wrong way? Imagine you break into your friend's car, and rewrire the stereo system so the left speaker doesn't work. Then, you say, "yo, I broke into your car and rewired things. The locks on this car are faulty, better let the car manufacturer know. I should contact them myself and collect my bug bounty." And when your friend, a d…

> Imagine you break into your friend's car Bad comparison. Breaking into a car is a locally constrained high-risk attack vector. This is a low-risk unconstrained attack vector. A bored person anywhere in the world could fuck their shit up with no risk or consequence.

Alright, say their car is unlocked and you rewire the stereo to teach your friend not to leave their car unlocked. Or a better example is surprising them with their car insurance card from the glove compartment to prove you got into their car. The act of intruding into someone's vehicle in and of itself is an unwelcome act, even if it is to teach good lessons. The same is true for this I think.

I always feel that pointing out vulnerabilities is okay. Penetrating to point it out is another thing altogether. Continuing the analogy here would be pointing out to your friend that they shouldn't leave their car unlocked rather than entering and making a mess of things.[0]

And sure, bored person anywhere can do lots of damage and may be your damage won't be as bad, but just the act of going through someone's belonging is unwelcome.

[0] Also, there's a huge difference I feel from penetrating systems from orgs that have dedicated security teams...and picking on a private individual to make a point.

Re: Post a boarding pass on Facebook, get your account stolen

#55
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

When I was in high school, SWIM was stealing everybody's MSN's accounts. The technique got out, it was through these "security questions", then SWIM got his MSN stolen. Then people would recreate MSN accounts and get it stolen again. It became a funny war until some dude started asking for money to other people's contacts (via allopass, these things where you could just call a number to get charged and obtain some token).

Good times. Except some of my friends actually sent out some money. I'm pretty sure I know who did it.

Since then I enter garbage in these security questions. Better lose my account than that.

Re: Post a boarding pass on Facebook, get your account stolen

#56
Remind me of my ex-gf I had on my Facebook for a while. She liked to be show off, which I think nowadays is not that big of as deal. But she would literally invite crime to her house! On her public Facebook profile she didn't post her address, BUT she had bunch of photos: her with the Living Complex sign, her next to her doors (with apartment number on it), photos of her inside house with beautiful 85" TV and other equipment including expensive bikes, then finally her photo with the car showing license plate (revealing her state name).

I told her numerous times its not a good idea but she never listened! Then I told her publicly on her car photo that she should at least wipe out the plate number, which created a long trail of comments where basically all her friends thought I'm weird and creepy and why would I be warning her (perhaps I want to commit some crime??). No amount of explaining helped. Even telling cops will tell her the same thing got me bunch of her "friends" answering "you ain't a cop, bro". And then one fine Friday I saw her posting they leaving for another state to visit family. Boy it was a discovery when they come back Monday morning their house was cleaned out from every possible valuable belongings. And thieves must have came with a large enough truck to fit that 85" TV screen.

Not long after she removed me from her FB even though I never told her "told you so".

The bottom line is I don't believe people will learn not to give a clues online and I think in these days of age it should be an hour mandatory lesson at the school what NOT to post online.

Re: Post a boarding pass on Facebook, get your account stolen

#57
post #33

Earlier quoted context omitted.

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

If you booked the flights together, and paid together, it's probably pretty likely that you are travelling together.

If the flights were booked together, I don't think this is out of line.

Re: Post a boarding pass on Facebook, get your account stolen

#58
post #35
post #33

Earlier quoted context omitted.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

This is the case I've seen the most. It also really speaks to what is the ultimate security hole which is human error and social engineering. Granted your friend was not being malicious, the fact that it was that easy is scary.

Or it speaks to years of cost benefit analysis and outcome of someone doing this maliciously is so benign or so embedded within a trust chain that there's no benefit to closing that particular hole.

Not that I have any expertise in this particular situation, but not every 'threat' when armchair analysed in isolation is a threat when put into its correct domain and context.

Re: Post a boarding pass on Facebook, get your account stolen

#59
post #50

I am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any…

Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.

Re: Post a boarding pass on Facebook, get your account stolen

#60
post #33

Earlier quoted context omitted.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

So what's going to happen is that 2 of the same person show up to the plane... and the copy cat goes on the plane and then you check in, and they say, nope, not you. And then you pull your passport. And then they go get the other person off the plane.

And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.
Post reply on HN