What’s in a Boarding Pass Barcode?
krebsonsecurity.com
krebsonsecurity.com
Interested in learning what’s in your boarding pass barcode?
Take a picture of the barcode with your phone, and upload it to this site.
Woah! We are talking about private information being easily accessed from our boarding passes and there is a passage on uploading it to some site online. Wouldn't that be ill-advised.(Try to submit bogus data to see the results :) )
1. If the app doesn't have permissions to use the internet (possibly Android only, although the Android 6 discussion seems to suggest that there's ways round this).
2. If you use the app while disconnected from the internet and ensure that it isn't running when you reconnect.
Neither of those is possible when you upload the image to be parsed online.
An app might upload the image to a remote server. A website might parse it locally through JS - maybe disabling your connection, submitting your image, parsing it, then wiping your cached website data would be just as "safe".
The problem is the knee-jerk reaction that "some random website" is dangerous while some random app is not. You have to assume both are equally risky in this situation.
> TPF evolved from the Airlines Control Program (ACP), a free package developed in the mid-1960s by IBM in association with major North American and European airlines. In 1979, IBM introduced TPF as a replacement for ACP — and as a priced software product.
Holy fuck. I don't want to be the poor guy maintaining code that is likely to be older than himself...
Disclaimer: I could be wrong about the number above, but afaik its in the ballpark.
"IBM designed the IMS with Rockwell and Caterpillar starting in 1966 for the Apollo program" "Vern Watts was IMS's chief architect for many years. Watts joined IBM in 1956 and worked at IBM's Silicon Valley development labs until his death on April 4, 2009. He had continuously worked on IMS since the 1960s." https://en.wikipedia.org/wiki/IBM_Information_Management_Sys...
I've come across IMS before, and I absolutely love this line. This is a database built for the Apollo program by a tractor company. That's a kind of old-school solidity we don't see much anymore (mostly for the better, but still).
A lot of these systems definitely predate SQL. Even with SQL, using parameters is the usual way to operate on large amounts of data with fixed queries, and it avoids escaping issues entirely.
You're right there's ways to do this properly, of course. But in practise, with huge systems, people end up hooking in things here and there and forget at some point eh?
"Not only could I see this one flight, but I could see ANY future flights that were booked to his frequent flyer number from the Star Alliance.”"
US-based airlines tend to require an actual password to access the account and see future flights, spend miles on redemptions, and so on (I have accounts, currently, with four different US-based carriers, and all of them require a password for account access).
The confirmation code and passenger name are enough to make changes to that reservation, though; if you know someone's code + name you can cancel the return segment of their journey, for example.
I'm wondering if the person being quoted was confused by seeing the return segments of a multi-segment trip (which are part of a single reservation, and would come up with just the information on the boarding pass), and thought it was actually full account access.
I'm wondering if the person being quoted was confused by seeing the return segments of a multi-segment trip
I wondered that too. I'm a Miles & More member via Swiss (which is part of the Lufthansa group) and you definitely need a password / pin to access your FF account.Accessing a specific booking via booking code / surname is a whole different issue.
Other schemes seem to assign only a tiny fraction of possible codes, which is why my Starwood number is twelve digits long.
I don't see any reason why they should do that.
Also oome people might tear the boarding pass into many pieces so that name, flight,... can't be associated. But the barcode is relatively small. It might still be readable in one piece.
I scanned a recent VA boarding pass with a PDF417 scanner, and amongst all the other stuff is 16 characters without an obvious meaning. The boarding pass in the article had a similar region, and another longer one. It would have been interesting for the article to have pulled those apart.
Of course there is an extra step of validation, because the airline has the passenger list, so you can't just add yourself to a flight.
The boarding pass data is still plaintext as explained, but a signature is appended to validate that the content has not been tempered with, and who generated it.
I think boarding pass signing is mandatory on all U.S. airlines at least but I have no source for that
[1] http://www.iata.org/whatwedo/stb/documents/bcbp_implementati...
Edit: Apparently it has something to do with VAT: http://www.telegraph.co.uk/travel/travelnews/11794109/The-re...
And even if they have a tax reason to collect boarding passes, I wonder if they are prohibited from doing their own analytics on it. Apparently merchants can with credit card numbers: https://www.quora.com/Can-businesses-use-credit-card-data-fo...
That's less likely to happen with a boarding pass on your phone.
(though in general, the problem of airlines requiring very little information -- all of which is on the boarding pass -- to be able to access an itinerary and make changes or cancel it is somewhat well-known among frequent flyers)
I can see how fraud can be prevented with this schema, but I wonder if it's implemented.