Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

71–80 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#71
post #32
post #15

Earlier quoted context omitted.

Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.

Isn't embedding QR codes the reason they were created in the first place? It's an optical data format designed to be easy for computers to read. You're basically evaluating the cryptographic merits of CSV.

Yes, they were meant for efficient consumption. The 'Q" is for quick.

Re: Post a boarding pass on Facebook, get your account stolen

#72
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

>"It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security."

Do you really believe the problem here is FB? Do you really believe FB should be the arbiter of what incidental information their users's pictures can and can not convey?

And even if they did parse pictures for sensitive data do you believe that FB, given what we know about them would simply redact that information from photos and then discard that sensitive data? I think we can safely assume that FB doesn't discard data on individuals.

Re: Post a boarding pass on Facebook, get your account stolen

#73
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s. You don’t print a paper with all the information you need to hijack accounts. You don’t use ‘secret questions’. You don’t treat birthdays as secrets. You don’t use a number as a secret if it’s on the ticket.

>"The problem is not barcodes and it is not Facebook. The problem is airlines with security systems that went out of style in the 90’s."

No the problem as outlined in the post is people not thinking through what they are sharing on social media.

Re: Post a boarding pass on Facebook, get your account stolen

#74

>"I've known Petr Mára for few years now, he's a nice guy. He's a speaker, trainer, video blogger, and deploys iOS & macOS wherever possible." Why are any of these facts relevant? He deploys macOS? What? What does this have to do with anything? And then author makes the reference to his friend Petr a link to his personal website? Seriously? Incidentally, Petr's webiste is really entertaining as there are no less than…

> He deploys macOS? What? What does this have to do with anything?

And what does that even mean? That he buys Apple stuff? Indeed the weirdest endorsement I've heard in a while.

Re: Post a boarding pass on Facebook, get your account stolen

#75

Earlier quoted context omitted.

> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.

A nice feature would be for them to decode and display the barcode info when you're uploading. Something like “This image contains the following info: . Would you like us to blur that out? (Y/n)”

This image contains the following info: (long line of gibberish, the boarding pass ID)

User: srsly fb? OK

Re: Post a boarding pass on Facebook, get your account stolen

#76
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

>"It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security." Do you really believe the problem here is FB? Do you really believe FB should be the arbiter of what incidental information their users's pictures can and can not convey? And even if they did parse pictures for sensitive data do you believe that FB, gi…

No not at all! I'm just making a point that for a company that oversees an enormous proportion of all the user-uploaded images in the world could make a big impact with a relatively small extension to the processing they already do on uploaded photos. I'm not saying any blame is directed at Facebook. While a certain blame does lie with the airline industry, airline ticketing systems were designed and built way before the web and ubiquitous cameras. To change such a system is non-trivial, given that it operates in every(?) country in the World all the time, and is safety and security-critical.

Since there's no obvious single entity to blame (and even if there is, so what?), we should be working together to prevent and reduce attacks like this. Apart from anything, Facebook popping up a warning about a barcode would go a long way to making people realise that they contain easily readable, and potentially private information.

Also, given how well image classifiers work these days, how hard is it to do the same for photos of (physical) keys, bank cards, and other commonly posted things?

Re: Post a boarding pass on Facebook, get your account stolen

#77
post #6

It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…

>"It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security." Do you really believe the problem here is FB? Do you really believe FB should be the arbiter of what incidental information their users's pictures can and can not convey? And even if they did parse pictures for sensitive data do you believe that FB, gi…

> Do you really believe FB should be the arbiter of what incidental information their users's pictures can and can not convey?

Aren't they already do it for other stuff they don't want to see online ?

Surely a nipple isn't a barcode and legal implication aren't the same. And people sharing personal stuff ARE responsible for sharing those stuff.

So I guess it shows us again that FB is not our friend :)

Re: Post a boarding pass on Facebook, get your account stolen

#78
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

The first time (years ago...) I had to enter my birth date on a website that asked it to me for no valid reason, there was a default value. It's now my birthdate on every others !

Re: Post a boarding pass on Facebook, get your account stolen

#79
>"When you want to brag about your final destination, be careful of what you post on Facebook and Instagram. Leave your boarding passes (and other barcodes) for yourself (and get a shredder)."

It's funny that for a piece intended to warn other's on identity security the author had no problem reproducing the the unredacted boarding pass picture in question, which incidentally also tells us that he is a member of the One World Club with Saphire status. They also go onto let us know their nationality and profession.

The author also has no problem publishing his friend's full name and linking to their personal website which features 5 large high resolution pictures available of his friend's face as well as well as detailing exactly which Apple certifications they posses.

Post reply on HN