Just to clarify in case someone assumes the same thing I did from the headline: it isn't the Facebook account that gets stolen, but the airline website account.
Post a boarding pass on Facebook, get your account stolen
61–70 of 313 posts
Re: Post a boarding pass on Facebook, get your account stolen
#62No its more like people are so obsessed with curating their "fabulous" lifestyle for social media that they don't care.
The boarding passes are a carefully arranged prop in that picture, intended to reinforce the fact to social media that "yes I lead a fabulous life."
If their intention had only been to communicate to others that they were going on vacation, an "On our way to ____" message would have sufficed.
Re: Post a boarding pass on Facebook, get your account stolen
#63I am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any…
Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.
Re: Post a boarding pass on Facebook, get your account stolen
#64Re: Post a boarding pass on Facebook, get your account stolen
#65Earlier quoted context omitted.
I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…
This is the case I've seen the most. It also really speaks to what is the ultimate security hole which is human error and social engineering. Granted your friend was not being malicious, the fact that it was that easy is scary.
Re: Post a boarding pass on Facebook, get your account stolen
#66I am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any…
Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.
Thanks!
I am pretty grateful I'm not tasked with implementing these.
Re: Post a boarding pass on Facebook, get your account stolen
#67Earlier quoted context omitted.
Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
The search space for city names is tragically finite. There are ~35,000 cities and towns in the U.S., but if you start weighting those by populating (and birthing hospitals and centres), you're going to reduce that count considerably. https://www.reference.com/geography/many-cities-united-state...
Re: Post a boarding pass on Facebook, get your account stolen
#68Why are any of these facts relevant? He deploys macOS? What? What does this have to do with anything?
And then author makes the reference to his friend Petr a link to his personal website? Seriously?
Incidentally, Petr's webiste is really entertaining as there are no less than 5 pictures of him that take up the entire background. Clicking on the Petr link, is the most entertaining part of the article.
Re: Post a boarding pass on Facebook, get your account stolen
#69Please keep away from it..
Re: Post a boarding pass on Facebook, get your account stolen
#70It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…
The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.
The system is not set for security only for convenience and assumes a world of 80-90s of regulated travel with never full planes and no change penalties. At the time (US) airlines were even honoring competitor tickets at gate (assuming they has space, which they almost always did) -- show up with AA ticked at a United gate and get it swapped for a United flight by agent on the spot. Gratis.
The system had lots of problems, but malicious changes were not one of them.