Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

1–10 of 459 posts

Re: Bypassing airport security via SQL injection

#5

Not surprised that they deny the severity of the issue, but I am quite surprised they didn't inform the FBI and/or try to have you arrested. Baby steps?

This should be news lol, I’m surprised a bored year 17 year old with a fake id hasn’t made a TikTok sneaking on board a plane. Sql injection ffs

Re: Bypassing airport security via SQL injection

#7
The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.

Re: Bypassing airport security via SQL injection

#8

Not surprised that they deny the severity of the issue, but I am quite surprised they didn't inform the FBI and/or try to have you arrested. Baby steps?

The author made the right move by doing this through FAA and CISA (via DHS), rather than directly via TSA. It's not inconceivable that a direct report to TSA would have resulted in legal threats and bluster.

Re: Bypassing airport security via SQL injection

#9
Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

Re: Bypassing airport security via SQL injection

#10
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

The statute of limitations is long and HSI often delays their indictment until the investigation is mostly wrapped up.
Post reply on HN