15 ms·
Post a boarding pass on Facebook, get your account stolen
- dawnerd 9y agoNot the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df3 https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-hacker-fancy-airline-lounges/ https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws-in-the-tsa-pre-check-system-and-the-boarding-pass-check-system/ https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-security-flaws-in-airline-boarding-passes/2012/10/23/ed408c80-1d3c-11e2-b647-bb1668e64058_story.html http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/instagram-boarding-pass-security-problem-bad-idea https://www.theverge.com/2017/1/10/14226034/instagram-boardi... I don't see this changing anytime soon (although there are some tests to move towards facial recognition).
- keganunderwood 9y agoThe real problem is that once again someone treated what should simply be an identifier to look up data as something more. Why not store all this information on the server that an authorized person can see when they scan a uuid on the boarding pass? Would they allow boarding of the network was down?
- germanier 9y agoThere are procedures in place in case the network is down. I have flown with hand-written boarding passes multiple times in the past (they even had special cards for that situation laying around). On the other hand there were flights that were grounded as there was some network malfunction. I guess it depends on the specific problem they have.
- alanh 9y agoCan you imagine how slow boarding might be if the information needed retrieved from a distant mainframe by the scanner before it would emit its _beep_ of consent? (I agree with you, though)
- hsnewman 9y agoIs the problem the airline or the person posting it online?
- kumarm 9y agoBad server request. Maintaining your own server for personal blog is geeky as long you can manage to keep it up.
- woof 9y agoIt's currently at AWS, where was it 42 minutes ago?
- sebcat 9y ago33c3 talk related to this topic: https://www.youtube.com/watch?v=n8WVo-YLyAg https://www.youtube.com/watch?v=n8WVo-YLyAg - "Where in the World Is Carmen Sandiego?"
- fahrradflucht 9y agoOr in a lot of different formats and also for download on media.ccc.de: https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carmen_sandiego https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme...
- signa11 9y agothe risk digest: http://catless.ncl.ac.uk/Risks/ http://catless.ncl.ac.uk/Risks/ is also pretty cool resource for these kind of things :)
- fredley 9y agoIt's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used for return fraud in certain circumstances. Saying 'don't post barcodes online' is all well and good, but that message will never reach the general public.
- microcolonel 9y ago> Almost any barcode is assumed to be private information I don't think that's really the case, I've deliberately embedded QR codes in images on Facebook. Your feature would be very annoying if it could not be toggled off.
- sitkack 9y agoGotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.
- kalleboo 9y agoI’ve seen people and business pages post Snapchat and LINE QR codes
- jacquesm 9y agoFacebook has a billion users. To think that anything someone does there is the first or only time it happens is probably incorrect.
- oblio 9y agoIf something is a security issue for 99% of users, the 1% will have to just accept it. Case in point: app sandboxing. I, for one, don't want it, but it's everywhere.
- noobermin 9y agoI get it, be aware of what you post on facebook, but does this not rub anyone else the wrong way? Imagine you break into your friend's car, and rewrire the stereo system so the left speaker doesn't work. Then, you say, "yo, I broke into your car and rewired things. The locks on this car are faulty, better let the car manufacturer know. I should contact them myself and collect my bug bounty." And when your friend, a decent chap, thinks you're joking, and finds out you're not kidding, is his response supposed to be, "Oh shit, you're right. You could have just [rewired my speaker system]. This is crazy." or instead, would he no longer be your friend, and probably report you to the police?
- Kudos 9y agoAnalogies almost always make for tedious discussions.
- noobermin 9y agoI grant you that. I am trying to make a general point about whether you should do 'x' just because you can or to prove a point.
- Deestan 9y ago> Imagine you break into your friend's car Bad comparison. Breaking into a car is a locally constrained high-risk attack vector. This is a low-risk unconstrained attack vector. A bored person anywhere in the world could fuck their shit up with no risk or consequence.
- noobermin 9y agoAlright, say their car is unlocked and you rewire the stereo to teach your friend not to leave their car unlocked. Or a better example is surprising them with their car insurance card from the glove compartment to prove you got into their car. The act of intruding into someone's vehicle in and of itself is an unwelcome act, even if it is to teach good lessons. The same is true for this I think. I always feel that pointing out vulnerabilities is okay. Penetrating to point it out is another thing altogether. Continuing the analogy here would be pointing out to your friend that they shouldn't leave their car unlocked rather than entering and making a mess of things.[0] And sure, bored person anywhere can do lots of damage and may be your damage won't be as bad, but just the act of going through someone's belonging is unwelcome. [0] Also, there's a huge difference I feel from penetrating systems from orgs that have dedicated security teams...and picking on a private individual to make a point.
- sersi 9y agoAnd this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easily found information that people can just guess.
- djsumdog 9y ago"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.
- raverbashing 9y agoYes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
- jacquesm 9y agoI do this too, some phone number checks and email checks are surprisingly good.
- dredmorbius 9y agoThe search space for city names is tragically finite. There are ~35,000 cities and towns in the U.S., but if you start weighting those by populating (and birthing hospitals and centres), you're going to reduce that count considerably. https://www.reference.com/geography/many-cities-united-states-cfb3be08284e6a62 https://www.reference.com/geography/many-cities-united-state...
- cyphunk 9y agodo the barcodes in the authors examples, which they did not bother to fuzz and anonymize, do they also convey the details they did anonymize? I'm curious
- bonzini 9y agoThe blurring was done by the person who posted (not by the authors).
- franciscop 9y agoFun alternative: create a honeypot website that looks semi-legit and publish QR codes to social networks to analyze the traffic to those. For big-name corps, do the same to catch IPs of script kiddos who don't know/bother to mask those.
- babuskov 9y agoJust to clarify in case someone assumes the same thing I did from the headline: it isn't the Facebook account that gets stolen, but the airline website account.
- exodust 9y agoAnd really this has nothing to do with Facebook at all, it's not a good title.
- macintux 9y agoEh, Instagram is owned by Facebook, so I gave that a pass.
- exodust 9y agoI thought the point was about the risks of posting images of boarding passes on the internet. Where they happen to be posted seems irrelevant to me, but whatever.
- _asummers 9y agoI've seen that meme get passed around Facebook for several different airlines, several times. It's always so lazy too "this company that's been around for 60 years is turning 88! Wow get your free tickets because thats what companies do when they turn 88!"
- netsharc 9y agoIt seems the attacker/pen-tester got access to the guy's passport number. I wonder how easy it would be to do identify theft and gain entry into other accounts.
- babuskov 9y agoA much better title would be: Post a boarding pass online, get your identity stolen.
- cyberferret 9y agoI wonder just how much of the barcode should be obscured to render it unscannable? Is it enough to cover the check digit? (If indeed that symbology has a check digit verification). e.g. With QR Codes, is 25% obscuration enough, etc.?
- fbgugli 9y agoWho in they right mind would trust facebook about anything ? Please keep away from it..
- jackemupguy2 9y agoReal deal - DEFCON part about this. The research is deep for sure. https://www.youtube.com/watch?v=qnq0UfOUTlM https://www.youtube.com/watch?v=qnq0UfOUTlM
- KGIII 9y agoI am not a lawyer, but I think most of the author's actions would be considered illegal in the US. While he didn't do any harm, his actions were still probably a violation of at least the CFAA. Anyhow, Aztec code? It looks, the one on the watch, pretty much like a QR Code. I've never seen the Aztec code before today. It makes me wonder how many of these barcode things we really need. A quick Google didn't reveal any information demonstrating why this Aztec code is any better than the other options out there. It does make me grateful that I don't have to work on implementing all these things or, really, even deal with them. I know a bunch of you are developers and I hope you're not the ones stuck with dealing with all these different 'standards,'
- littlehood 9y agoAztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.
- cyphar 9y agoQR also has tunable error correction.
- KGIII 9y agoDoesn't the QR standard allow lowercase via hex and have a miniature version? I know it has error correction, but I'm not sure if it is tunable. I know it can embed kanji, so it seems odd that lowercase would be much of a problem? Thanks! I am pretty grateful I'm not tasked with implementing these.
- joering2 9y agoRemind me of my ex-gf I had on my Facebook for a while. She liked to be show off, which I think nowadays is not that big of as deal. But she would literally invite crime to her house! On her public Facebook profile she didn't post her address, BUT she had bunch of photos: her with the Living Complex sign, her next to her doors (with apartment number on it), photos of her inside house with beautiful 85" TV and other equipment including expensive bikes, then finally her photo with the car showing license plate (revealing her state name). I told her numerous times its not a good idea but she never listened! Then I told her publicly on her car photo that she should at least wipe out the plate number, which created a long trail of comments where basically all her friends thought I'm weird and creepy and why would I be warning her (perhaps I want to commit some crime??). No amount of explaining helped. Even telling cops will tell her the same thing got me bunch of her "friends" answering "you ain't a cop, bro". And then one fine Friday I saw her posting they leaving for another state to visit family. Boy it was a discovery when they come back Monday morning their house was cleaned out from every possible valuable belongings. And thieves must have came with a large enough truck to fit that 85" TV screen. Not long after she removed me from her FB even though I never told her "told you so". The bottom line is I don't believe people will learn not to give a clues online and I think in these days of age it should be an hour mandatory lesson at the school what NOT to post online.
- bogomipz 9y ago>"Users often publish data that they don't know what they mean. Because at first sight, it's not possible to see what's the data, or what the data is for" No its more like people are so obsessed with curating their "fabulous" lifestyle for social media that they don't care. The boarding passes are a carefully arranged prop in that picture, intended to reinforce the fact to social media that "yes I lead a fabulous life." If their intention had only been to communicate to others that they were going on vacation, an "On our way to ____" message would have sufficed.
- Spooky23 9y agoWhy would you do such a thing?
- TomMarius 9y agoBecause he's an information security expert.
- Spooky23 9y agoI mean the "post a boarding pass on Facebook" part.
- artursapek 9y agoThey were showing off their nice apple hardware and international plane tickets. It's the standard "my life is perfect" instagram user.
- Spooky23 9y agoWhat’s the bigger security threat in this scenario?
- bogomipz 9y ago>"I've known Petr Mára for few years now, he's a nice guy. He's a speaker, trainer, video blogger, and deploys iOS & macOS wherever possible." Why are any of these facts relevant? He deploys macOS? What? What does this have to do with anything? And then author makes the reference to his friend Petr a link to his personal website? Seriously? Incidentally, Petr's webiste is really entertaining as there are no less than 5 pictures of him that take up the entire background. Clicking on the Petr link, is the most entertaining part of the article.
- distances 9y ago> He deploys macOS? What? What does this have to do with anything? And what does that even mean? That he buys Apple stuff? Indeed the weirdest endorsement I've heard in a while.
- TomMarius 9y agoTo be fair, Petr himself uses these exact words (on his website) to describe him.
- deleted 9y ago[deleted]
- bogomipz 9y ago>"When you want to brag about your final destination, be careful of what you post on Facebook and Instagram. Leave your boarding passes (and other barcodes) for yourself (and get a shredder)." It's funny that for a piece intended to warn other's on identity security the author had no problem reproducing the the unredacted boarding pass picture in question, which incidentally also tells us that he is a member of the One World Club with Saphire status. They also go onto let us know their nationality and profession. The author also has no problem publishing his friend's full name and linking to their personal website which features 5 large high resolution pictures available of his friend's face as well as well as detailing exactly which Apple certifications they posses.
- stephen_g 9y agoThere isn’t a Oneworld club. With Oneworld you can only join individual airline’s loyalty program (I think he’s in the BA one judging by the BASILV). Then all the airline programs in the Oneworld alliance have a mapping between their tiers and the Oneworld set, so you can work out the equilivalence between airlines. So a Qantas Gold teir maps to BA’s silver tier and get the same perks on each other’s airlines (BA has Blue, Bronze, Silver, Gold and Qantas has Bronze to Platinum, hence the difference). ‘Club World’ is what BA call their business class. But your point still stands, be definitely should have at least obscured his frequent flyer membership number...
- bogomipz 9y agoSorry yes I meant alliance not club at any rate the ticket says Saphire for One World which lets you know their frequent flyer status: https://www.oneworld.com/ffp/my-oneworld-tier-status/-/tierstatus/british-airways/executive-club-silver https://www.oneworld.com/ffp/my-oneworld-tier-status/-/tiers...
- tribby 9y agopost a boarding pass on facebook, get your account stolen? there's an alternate title for this one. post about commandeering accounts on your blog, get the CFAA thrown at you and go to jail. this is anything but responsible.
- literallycancer 9y agoPresumably he's not located in the US.
- magoon 9y agoCould you imagine a neighbor going around checking everybody’s window and door locks?
- meric 9y agoNo but your mum might pick your phone off your pocket to remind you to be careful when it's hanging out while you two are travelling in a country overseas in a danger area.
- ff7c11 9y agoThe author needs to learn some responsibility himself.
- qrbLPHiKpiux 9y agoThe weakest link in infosec has fingers and thumbs that uses a device. This is nothing short of yelling sensitive information through a megaphone. USERFAIL
- henadzit 9y agoIt would also help if tickets had a "No photography" icon on them and a note about them having private information.
- Natanael_L 9y agoI think somebody should develop a standardized and open auto redaction flagging scheme for anything printed, where cameras and any software meant to share photos can offer the user to redact every sensitive field in a secure manner. Something like a Qr code saying "this stuff in that position relative to this code is sensitive", giving the user a prompt saying "this was redacted; undo?"
- YokoZar 9y agoAnd then camera-shy people will print it on their clothes.
- Natanael_L 9y agoThat's a feature
- Doxin 9y agoMaybe something similar to the EURion constellation[0]? [0] https://en.wikipedia.org/wiki/EURion_constellation https://en.wikipedia.org/wiki/EURion_constellation
- flyGuyOnTheSly 9y agoWith people taking pictures of their breakfast and posting it to Instagram these days... that's a great idea.
- kerouanton 9y agoI don't know if it's the case elsewhere but starting 2019 all invoice payments in Switzerland will use mandatory QR codes. https://www.paymentstandards.ch/en/home/softwarepartner/qr-bill.html https://www.paymentstandards.ch/en/home/softwarepartner/qr-b... That promises to be challenging too in terms of publication of sensitive data.
- s3nnyy 9y agoI can't see exactly where it says that it is mandatory?
- hsnewman 9y agoIf you post personally identifiable information online you can get your account stolen. Something new, no.
- bhldr 9y agoWhat's the purpose of your cynicism?
- DougWebb 9y agoIt's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails gave me the confirmation number, and a link directly to the page that would let me make changes to the reservation, with no security barrier at all. Granted, this most likely was caused by that other Doug providing my email address to the airline, but the airline is at fault too for assuming that access to a given email address is proof of identity. That's a very common mistake, often made intentionally to provide a more "user-friendly" experience. Had I been malicious, I could have caused that other Doug a lot of un-friendly grief. I was not able to see any contact information on the reservation, and I didn't have full access to his account. (I don't know if a "Forgot Password" request would have given me that, though it probably would have.) I contacted the airline customer support to tell them they had the wrong email address on the reservation and they should contact their customer through some other means if they could. I think I got a form-letter thank you and never heard from them again, but I did get a few more boarding passes for a while. I also get a lot of online shopping order/shipment confirmations, and plenty of personal correspondence. I try to tell the senders to fix their address books, and when I get a CC with the real address I contact the other Dougs too, but most of the time there's no response. I've had to set up a filter that puts all email with TO addresses that aren't the one I use into an "Other Dougs" folder, which I treat like spam.
- csours 9y agoYup, I get emails about Cassidy's kids, Conrad's car purchase, Clyde's Lion's Club meetings, etc.
- DougWebb 9y agoHa... I just checked my Other Dougs folder. On Aug 4, I got an email from myidentityassist.com saying that "I" reported a case of identity theft, and that "my" Royal Bank of Canada credit card has been blocked from further use. Then on Aug 5 I got an email confirming an order from a Pizza Hut in Kingston ON, Canada, using the same variation on my email address. This is one of my repeat-offenders. I see a lot of email out of Kingston with this same variation on my email address, and I've tried many times to reply and get people to tell him he's using the wrong email address, but to no avail. This has been going on for years.
- chockablock 9y agoRecently saw a viral tweet with a picture of a political mailing posted on twitter with the address blacked out, but the USPS bar code (https://en.m.wikipedia.org/wiki/Intelligent_Mail_barcode https://en.m.wikipedia.org/wiki/Intelligent_Mail_barcode) showing (looks like a comb with broken teeth). They obviously didn't know the barcode contained the precise house address of the recipient (presumably the user's home address). Anonymization is hard!
- jsymolon 9y agoLike SSNs (with a defined purpose), IMbs "use" is to help the USPS sort and deliver the mail without manual handling. Large mailers (billions of pieces per year) get a postage discount by applying such barcode to all the pieces. (edit: any mailer can get the discount. it just adds up for the larger mailers) Those pieces are delivered to USPS facilities, dumped into the auto-sorters and end up at the local post office with no human handling. It should not be used for anything else except handling mail.
- sitepodmatt 9y agoTo help increase security through action, whenever friends send me their flight details that include a PNR I logon to the airline website and book them a middle seat and special meal choice 'bland meal'. Just doing my part.
- kobeya 9y ago“friends”
- floatingatoll 9y agoWhy do Facebook and Twitter and etc. permit posting of airline QR codes and credit card photos without a safety warning and an option to safely blur out the sensitive bits?
- beambot 9y agoWhy do they permit it...? Because they aren't our parents and shouldn't be responsible for all the stupid shit that users could do. The real question: Perhaps we can politely convince these services to display safety warnings & blur the sensitive bits? Want to be proactive about it: Help develop a plug & play library for services to use to accomplish this feat.
- jsymolon 9y ago> aren't our parents ... Doesn't seem to stop them from trying to find naughty photos and block them. https://www.geek.com/apps/is-it-nude-algorithm-wants-to-find-out-whos-naked-on-the-net-1626678/ https://www.geek.com/apps/is-it-nude-algorithm-wants-to-find...
- sowbug 9y agoBecause it would be ridiculous to make Facebook and Twitter part of that security perimeter. Relevant xkcd: https://xkcd.com/463/ https://xkcd.com/463/ ("You're doing it wrong")
- orless 9y agoIf they'll do this for one case like QR codes on boarding passes, then the question and and expectation will arise, why don't they do it for every other possible case? This is not their job and not their responsibility, period.
- logingone 9y agoAnd still people make excuses to use Facebook.
- proksoup 9y agoIt's unfortunate that we must be this paranoid.
- deleted 9y ago[deleted]
- eridius 9y agoThere's no such thing as an iWatch. Why do people just make up product names like that?
- mulmen 9y agoUp next: post your bank statements online and lose your money!
- nanreh 9y agoHow about this: never post anything on Facebook. Just stop using it. Facebook causes cancer. You're better off without it.
- jackemupguy2 9y agoThe most notable information here is the dumpster diving at airports .. and what it can get you. Namely - people discarding their airline passes at airports. "Barcodes can also be found on “forgotten” boarding passes in aircraft or other locations." ... holy shit, I never thought about that ... wow.
- nine_k 9y agoDo a thoroughly stupid thing, reap the consequences. Post publicly a bunch of private info, like your complete contact details, get your account (or more of your identity) stolen. There is nothing surprising about that, nothing hard to understand. What is hard is actually thinking about what you are doing. Maybe, well, showing off your sophisticated and aesthetically perfect password is not such a good idea due to other considerations.
- vectorEQ 9y agohow about just don't post stuff like boarding pass online >.> don't need to share every detail on the PUBLIC INTERWEBZ. dm someone if u want to tell them. saves hastle of getting your shit stolen by some 12 year old. in holland we say 'voorkomen is beter dan genezen' -> to prevent is better than to cure. We all know these kind of weakeneses exist everywhere, yet we post our boarding pass on a public page on the internet... bit silly. you can say 'shit should be secure' but thats being said since the dawn of the interwebz and it never has been... so dont bank on it ever being secure is better than to assume it is and point fingers once you're a victim.
- jamiethompson 9y agoSomething I also do which guards against social engineering attacks is that I have a set of fake answers for common "secret questions". These exist nowhere but in my head. I figure it's a extra obfuscation step and could very well be a blocker if anyone was trying to get into any of my accounts.