Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

61–70 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#61

Just to clarify in case someone assumes the same thing I did from the headline: it isn't the Facebook account that gets stolen, but the airline website account.

And really this has nothing to do with Facebook at all, it's not a good title.

Re: Post a boarding pass on Facebook, get your account stolen

#62
>"Users often publish data that they don't know what they mean. Because at first sight, it's not possible to see what's the data, or what the data is for"

No its more like people are so obsessed with curating their "fabulous" lifestyle for social media that they don't care.

The boarding passes are a carefully arranged prop in that picture, intended to reinforce the fact to social media that "yes I lead a fabulous life."

If their intention had only been to communicate to others that they were going on vacation, an "On our way to ____" message would have sufficed.

Re: Post a boarding pass on Facebook, get your account stolen

#63
post #50

I am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any…

Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.

QR also has tunable error correction.

Re: Post a boarding pass on Facebook, get your account stolen

#65
post #35
post #33

Earlier quoted context omitted.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

This is the case I've seen the most. It also really speaks to what is the ultimate security hole which is human error and social engineering. Granted your friend was not being malicious, the fact that it was that easy is scary.

Maybe this is not intentional social engineering but a former customer working in the micro credit market once told me that the people who's most difficult to get money back are friends, not strangers. Maybe he had an agenda (send your friends to me) but it matches my experience.

Re: Post a boarding pass on Facebook, get your account stolen

#66
post #50

I am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any…

Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.

Doesn't the QR standard allow lowercase via hex and have a miniature version? I know it has error correction, but I'm not sure if it is tunable. I know it can embed kanji, so it seems odd that lowercase would be much of a problem?

Thanks!

I am pretty grateful I'm not tasked with implementing these.

Re: Post a boarding pass on Facebook, get your account stolen

#67

Earlier quoted context omitted.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

The search space for city names is tragically finite. There are ~35,000 cities and towns in the U.S., but if you start weighting those by populating (and birthing hospitals and centres), you're going to reduce that count considerably. https://www.reference.com/geography/many-cities-united-state...

Yes but if a system allows you to bruteforce this you probably have bigger problems

Re: Post a boarding pass on Facebook, get your account stolen

#68
>"I've known Petr Mára for few years now, he's a nice guy. He's a speaker, trainer, video blogger, and deploys iOS & macOS wherever possible."

Why are any of these facts relevant? He deploys macOS? What? What does this have to do with anything?

And then author makes the reference to his friend Petr a link to his personal website? Seriously?

Incidentally, Petr's webiste is really entertaining as there are no less than 5 pictures of him that take up the entire background. Clicking on the Petr link, is the most entertaining part of the article.

Re: Post a boarding pass on Facebook, get your account stolen

#70
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

Yes, you often only need the 6-char conf code and last name to change or cancel a random reservation.

The system is not set for security only for convenience and assumes a world of 80-90s of regulated travel with never full planes and no change penalties. At the time (US) airlines were even honoring competitor tickets at gate (assuming they has space, which they almost always did) -- show up with AA ticked at a United gate and get it swapped for a United flight by agent on the spot. Gratis.

The system had lots of problems, but malicious changes were not one of them.

Post reply on HN