Bypassing airport security via SQL injection
(ian.sh)
from jaromil@fed.dyne.org to technology@lemmy.ml on 30 Aug 2024 01:37
https://fed.dyne.org/post/228238
from jaromil@fed.dyne.org to technology@lemmy.ml on 30 Aug 2024 01:37
https://fed.dyne.org/post/228238
cross-posted from: fed.dyne.org/post/228188
threaded - newest
TSA: lalala i can’t hear you, everything is fine, no issue here
If Security through Obscurity isn’t working, consider Security through Stupidity, I guess.
I worked with some oilfield SCADS folks in the early 2000’s who used open IP for their valves, who were very convinced no one would use their equipment because “no one knew they were there.” At some point, it’s no longer trust in good actors.
Compliments to the authors, someone owes these guys challenge coins.
Good ol’ hanlon’s razor.
TSA is such a joke. And now we’ll never be rid of them. Thanks Al Quaida, you have successfully achieved your goal of inconveniencing the infidel travelers for decades now. I hope you are happy with yourselves.
They were created for the purpose of security theater. That intent won’t to away with time
It seems also harmful to our humanity of Amendments treating disabled, brown, and black people without suspicion and abuse.
100% not true.
A bar code is required for KCM. Has been for a while now. Manual entries have not been allowed for quite some time.
WOW.
I can understand making a mistake in the website design, leaving such a vulnerability; but to shove it under the rug and ghost the people that reported it???
The TSA and DHS are begging for an incident.
Glad Ian Carroll+Sam Curry made the info public. Maybe that’ll be the push needed to actually fix this.
I would be shocked if they don’t get enhanced screening every time now… or placed on the do not fly list.
Ahhh, the classic “shoot the messengers” defense.
Fucking hell. Where’s the incentive for responsible disclosure, if that’s the sort of (non) response you get?
I’m sorry, but WTF is
They are the company, running the thing. You are going to alarm them a whole lot more by going to the damn DHS. Like, I think DHS and TSA probably do need to know about this, but why not start with the actual intimately responsible party?
I also didn’t understand the logic here. Why did they “did not want to alarm them”? Is it because a one person company can simply fix the issue and not report to any other authority? What is the rationale behind it?
This story is hilarious. TSA is comically incompetent.
It seems also harmful to our humanity of Amendments treating disabled, brown, and black people without suspicion and abuse.