ajd
Active Member
- Joined
- Jan 17, 2014
- Posts
- 568
- Qantas
- Silver
- Virgin
- Red
From 33c3, the 33rd Chaos Communication Congress, presented by a couple of guys from a German information security research firm. Aimed at techies but reasonably understandable nonetheless.
https://www.youtube.com/watch?v=n8WVo-YLyAg
I'm sure many AFFers are aware of the basic issues with the security of travel reservation systems (requiring nothing more than a PNR and a surname to login to MMB, for example), but there's plenty of stuff in this talk that's rather disturbing. In particular, it turns out that even if everyone followed good practice in shredding boarding passes, not posting them on Instagram, and so on... if you don't need to target a specific individual, it's actually not that hard to simply guess random PNRs until you find one that looks interesting and use it to steal a ticket...
https://www.youtube.com/watch?v=n8WVo-YLyAg
I'm sure many AFFers are aware of the basic issues with the security of travel reservation systems (requiring nothing more than a PNR and a surname to login to MMB, for example), but there's plenty of stuff in this talk that's rather disturbing. In particular, it turns out that even if everyone followed good practice in shredding boarding passes, not posting them on Instagram, and so on... if you don't need to target a specific individual, it's actually not that hard to simply guess random PNRs until you find one that looks interesting and use it to steal a ticket...