Circumventing the No-Fly list in thirty seconds
blog.rodneyfolz.com
blog.rodneyfolz.com
[1] http://arstechnica.com/security/news/2008/06/tsa-defiant-pas...
Edit: The Soghoian blog post about the raid: http://paranoia.dubfire.net/2006/10/fbi-visit-2.html
10 year olds at this point have never known a world that was otherwise.
In another 15 years, almost all adults will be completely used to it, and the idea that we don't need the TSA will sound as absurd to them, as to most of us it seems "absurd" that in fact in the past you could fly in the USA while carrying a rifle or shotgun aboard, with ammo. The flight attendants would offer to stow it for you in a coat locker, but otherwise wouldn't bat an eye.
Even today you can fly with firearms (in checked baggage) but a lot of people think that this idea is completely absurd because they've never seen it... and they've been conditioned to being disarmed and the idea that you can't have a gun in an airport. (you walk in and check it at the counter, before going thru security.)
It takes 2 generations to completely change the nature of a society. As long as those born before 2000 are still around all hope is not lost. Do not give up.
One of the best talks I've ever seen http://youtu.be/5gnpCqsXE8g?t=8m40s
There's another purpose, politicians must be able to stand up (on the TV, press releases etc.) and say they are doing something. Other people/newspapers/tv shows will ask "Why aren't you doing anything about $TOPIC?" ($TOPIC in this case is 'terrorists', and '$NAME doesn't care about terrorists' is not soemthing politicos want to see)
http://www.aclu.org/technology-and-liberty/watch-lists
I am actually a little bit afraid to fly now because of numerous comments I have made about the US involvement in forcing the Afghani people to produce heroin etc. I expect I may actually be on this "terrorist watch list" just based on my comments online.
If you can read PDF417 (Zebra Crossing, the barcode reader for Android, can do it somewhat unreliably if you make your own build and have a good phone camera - otherwise, there are online services that can extract PDF417 from an image) you can see the info for yourself.
And, more importantly, if you can read PDF417, you can make your own!
To connect those machines to a database would both involve a lot of infrastructure build-out (imagine the chaos if that system went down nationwide!) and a lot of information sharing and standardization between airlines and the government. Signing the barcodes is smart, and is how "mobile boarding passes" work, but because paper passes were standardized so long ago, there's no security in place.
I also suspect the current TSA checkpoint barcode readers aren't smart enough to actually check the signature in a mobile boarding pass, but I don't want to find out myself.
But then again, they threw down millions per unit for those back-scatter machines, so all bets are off.....
I'm hoping that the airline industry implementing the smart way to do this (signed information in barcodes) for mobile barcodes means that the eventual rework of paper boarding passes will be intelligent as well, but as you say, all bets really are off...
That won't make a difference until they add the requirement to paper boarding passes (or phase out the paper boarding passes).
And this all begs the question of whether checking IDs does anything for security.
http://shaun.net/2011/05/whats-contained-in-a-boarding-pass-...
http://www.flickr.com/photos/kalleboo/6197243200/
[Update: iNate2000 says cell phone ones are signed. That would make modifying it much more difficult. It also implies printed ones are not signed, which makes that form the the attack vector.]
The bug has been closed as WONTFIX by the director of the TSA.
A few years ago I was adventurous, and frustrated -- there were no seats left on the flight that it would let me reserve online. Yet for this particular airline, it showed that the exit row seats were available, but clicking on them lead to an alert that you could not book them online: You had to do so at the airport.
I decided to look at the code making the seat selection calls, submitted my seat selection for that seat anyway -- and wallah! I was granted a ticket with that exit row seat. Had no problem going through security or boarding. Haven't tried it since - as most airlines now charge extra for those seats, and its not such an easy hack.
and - truly, I swear by God I am not making this up - I was granted a ticket with that exit row seat
In English, it's an old-fashioned idiom that a Robert Louis Stevenson character might have used. But English-speakers tend not to swear by God much these days - indeed, "swearing" usually means profanity.
First, security here is everywhere.
Second, security here is pointless.
I have had to walk through security to get to supermarkets, discount stores (think Walmart), high-end shopping malls, temples, mosques, movie theaters, national monuments, airports, hotels, you name it. You can't walk into a large building and not walk through a metal detector. The ACLU would probably go ballistic if the US had even 1% of the number of pat-downs that I have had to go through daily here.
Unfortunately, it's entirely pointless. Generally, I don't take my belt/jewelry/phone off when going through the metal detector, and most of the time, it doesn't even detect that. Whether or not I set off the detector, the process is the same: they (occasionally) wave a wand over, and then send me to a second person who briefly pats me down (<5 seconds in all). Keep in mind, the exact same process is applied to those who do and do not set off the metal detector. A few times, I've set it off and they just wave me through without even checking me further. It's mind-boggling.
I can't say I'm a fan of ubiquitous security, but the only thing that's worse than ubiquitous ineffective security. Anybody who really wants to cause trouble can bypass it in their sleep - all you manage to do is disrupt the lives of everybody else, all the while accomplishing literally nothing.
It's just like the US - the problem isn't that people don't care about security, or that they don't recognize it's a concern. The problem is that the existing measures (like the TSA) don't seem to be paying proper attention to the problem.
After that, I realised that the TSA was not only annoying and a waste of time and money, it was completely pointless as well.
I disagree with that statement. "It could" is hard to measure. We spend 100s of billions of $ on something based on this unproven hypothesis.
Keep in mind, TSA was created to catch terrorists red-handed as they are just about to board a plane. As in "Hey look a bomb in the x-ray machine, arrest this guy!". That is their purpose. They have not yet done that, once, in 10 years!
Govt. intelligence work and regular citizens have prevented and stopped attempts. There is some track record there. TSA doesn't have one.
By your metric one could have just as well re-defined TSA's mission as "Protect the citizens of the United States of America against Evil Pink Elephants from Neptune". Chances are very high that TSA's track record with that task would have been exactly what it is with their current mission. AND you could have still made your argument "See no Pink Elephants from Neptune have attacked us, so they must be doing their job."
Or think about it another way: How many airliners were blown up in US airspace before 9/11? Was it a monthly occurrence? Yearly? Now if was a yearly thing, and then TSA came along and it suddenly stopped, you could have made a correlation based argument saying, that it is probably because of fear of TSA that we didn't have any more attacks.
Yet another way to look at it. As a terrorist you are trying to instill terror and kill as many people as possible. A large gathering of people would maximize your impact. I wonder what places and events consistently create large queues of people waiting in line? What about also a place that would cripple and disrupt the economy and travel? I'll leave that as a rhetorical question.
It's precisely because it's unproven that we cannot say that the TSA has never caught a terrorist. That's all I was saying. The TSA may or may not have caught a potential terrorist at some point, it's pretty much impossible to say. You can't have it both ways. Either the TSA's effectiveness is unknown (meaning they may or may not have caught terrorists), or it's known to be 100% useless (meaning 0 terrorists were caught).
In regards to occurrences of terrorists prior to 9/11, you're correct that there weren't many (any?) incidences of using a plane for a terrorist attack, but hijackings were certainly not uncommon prior to 9/11. In fact, come to think of it, incidences of hijackings are almost certainly down since 9/11. I don't think this can be entirely attributed to increased security, but I wouldn't be surprised to see it as a contributing factor.
But why? I am sure any such catch would have been paraded in front of media for months. Are you saying they caught a terrorist with a bomb red-handed but hid it and instead shipped the guy secretly to a prison in another country? If not, that then I think we can say most definitely that they have not caught a single terrorist. Would you agree?
> but hijackings were certainly not uncommon prior to 9/11
Obviously hijackings were not that bad. That is the reason the first two planes ended up being used as projectiles, because people thought it was a regular hijacking. Within hours everyone in the country including passengers of the plane that went down in PA learned to not think about hijackings anymore in the same way. So the problems basically "fixed" itself immediately.
You are right the # of hijackings is now lower. TSA presence might have a part to play, that's plausible. But because of the previous paragraph it also becomes irrelevant. So the reasons for having the TSA evaporate away again.
Catching terrorists is likely to be one of the lower priorities.
Personally I think that random thorough screening and randomly distributed flight marshals is a better deterrent than poorly screening everyone. It's always harder to evade a security threat when you don't know what it is or looks like.
Another thing that annoys me is that people push for more railways on the basis that it is safe than flying. Railway in the last 10 years has had more crashes and more terrorist incidents than flying, and a determined terrorist can create massive havoc, fear and deaths from targeting trains, as was tragically displayed several times.
But for some reason, you can still hop on a train with no screening. Go figure.
Found it when I get back from my travels... was hidden in one of the folds of my bag.
It's much the same in the states.
I went through eleventy-dozen checkpoints on the Mall, and elsewhere. All the guards searched my backpack at every check point.
On the way home I found I had left a charged magazine (8 .45 rounds) in the bottom of my backpack. Not especially well-hidden, just snugged under my spare socks.
D.C. seems to have the highest per-capita police presences in the US. And it's all useless and dumb and ineffective.
1. You could fit a gun inside a zippered/covered binder or expanding file folder and the backpack does nothing.
2. The school already has metal detectors, so the backpacks aren't actually adding any detection.
3. They don't even know if the edge case where their current security failed even involved backpacks.
[1] http://www.chron.com/news/houston-texas/article/Teen-shot-at...
1) boast about how they were proactive and did something quick (so it looks good on their resumes).
2) protect themselves against the expected criticisms that they didn't do anything.
3) it was an easy policy to implement (they just wrote down a new rule). no need for new equipment, training or anything so it doesn't affect the budget.
Not saying that it isn't stupid. It is very stupid. But in their position they seem to act rationally. Now if another incident occurs they will get a backlash about how transparent backpacks didn't work, to which the response would be we need to outlaw binders. _But_ if they hadn't done anything and another incident occurred the backlash would have been a lot worse -- they would have been blamed and possibly sued because they took no action to prevent it after a history of past incidents.
When you board the plane they check the codes to see if you have been through special screening, they check the markings to the boarding pass codes.
I've made it to the flight a few times only to be turned around and accompanied back to security for the full security theater experience. At this point they will check the list and you will be arrested if they find a problem in the paperwork.
Your best bet is to change your name slightly William --> Bill etc. and play around with a middle/first initial. Computers are dumb. TSA agents are friendly when you are friendly to them and have tendency to not pay attention to their work. Social engineering is a lot more effective than computer hacking.
And what codes are these? the pen-squiggle? the highlighter-check-mark?
Is it your hobby to try to sneak past TSA checkpoints? Are you successful often enough that you have been turned away at the gate for not having the proper 'codes'?
There are codes that indicate the level of screening you should get along with codes that have "Special screening" indicated on them. And then the TSA is supposed to squiggle in response. Buying a one way ticket usually means you get special screening, I hope the terrorists don't figure this one out.
>Is it your hobby to try to sneak past TSA checkpoints?
In a way yes. It is my hobby to get through these things as quickly as possible. Sometimes I go through the staff/express line, you get a long way by being friendly to TSA agents.
>Are you successful often enough that you have been turned away at the gate for not having the proper 'codes'?
Yes. TSA agents make mistakes and don't always check the passes properly. I swear with half the agents I could give them an ID for someone completely different, all they do is check that it "looks" real.
One time I almost missed a flight. One of the gate agents was nice enough to run back to security with me and hurry them along. Someone else watched my bag rather than wait and get it searched properly. Security theater at its finest.
http://en.wikipedia.org/wiki/Secondary_Security_Screening_Se...
Hey ho.
You can of course also edit these out while you're busy changing the name. It's all a joke.
The the gate agents definitely always check ID with the boarding pass.
> when you board a flight to/from Canada, you have
> to show the boarding pass and photo ID
They are looking to make sure that you have your passport more than looking for 'photo ID.' I flew into Canada over Xmas and they were specifically looking for your passport. Probably to make sure that there won't be any obvious gaffs once you land.That said, on the domestic flight I took the TSA was at the boarding gate 'randomly' checking people as they were getting on the flight. So not everyone got checked for photo ID, but some people did.
And of course, neither Ecuador nor any of the other South American countries with the same formal rule ever asked us for the return ticket. Why would they?! Most people travel on buses between countries anyway. But Canada does not care, it sticks to the rule.
I've not only had my passport, but visas, checked at check-in, flying into Canada from the US.
Looking at the web for a citation, it seems this may just be a Canadian regulation: http://www.passengerprotect.gc.ca/home.html
This triggered 3 days of dealing with the US embassy in Abu Dhabi, but that's another story. :)
Why would the US embassy be involved? This seemed like a matter between you, the airline and Australia.
FYI, I was traveling on a 457 visa as part of my new job.
It's been this way for over 100 years. If someone was denied entry at say Ellis Island, it would be the steamship co.'s responsibility to get them back at no cost to the passenger.
I hope it'd be illegal in the US to require it, not sure though.
I'm told by people who know that it possibly would have worked to lie and say I didn't have ID on me, but I didn't have the guts to try lying to federal agents.
Surprisingly, the key card that let her board was her Costco card as it had her photo on it and that was an acceptable form of ID.
Not sure how I would have renewed my license from out of state, if they didn't let me on the plane. I'm pretty sure I couldn't rent a car and drive home!
tl;dr: You can alter a boarding pass and circumvent the entire watch list process.
--------
A is on the no-fly list. He is trying to fly.
B is not. The airline Computer expects B.
-
A brings the following things with him to the airport: ID A, Ticket A, Ticket B
Security: Ticket A vs ID A
Boarding (America): Ticket B vs Computer (B)
Boarding (Canada): Ticket B vs Computer (B)... vs ID A
Probably not - I wouldn't expect them to, anyway.
It's too bad, though, about how impossible it is to make a fake ID.
"My opponent supported the SODOM Act! Need I say more?"
But even aside from the fact that this is obviously and trivially forgeable, I don't think the person who scans your boarding pass at the gate even looks for the scribble, as I've used a different boarding pass to get on the plane than I did at the security checkpoint before (because I had printed one out at home and also printed another copy at the self-service check-in machine, and just happened to use different copies each time I needed to show it).
I've actually gone through TSA with one boarding pass on one flight, and boarded a completely different flight before (not just a separate piece of paper) - back when I could book flights for free on JetBlue and had already booked another flight that night. I merely decided once I was in the terminal that I'd hop on a different flight I had also checked in to.
I do a lot of flying and have long though about this. It's total theatre. They could fix it by implementing some cryptographic code that's scanned at TSA entry points, verifying the actual document (boarding passes are a far cry from a verifyable document).
Yeah, I tend to believe that they really aren't serious about it. It seems trivial to include a data matrix barcode that encodes the traveller's name and flight data.
(But then they know that response would be really asymmetrical).
The 'terrorists' in this case were holding Beslan School to ransom. No one expected that the Russians (fascists in every sense of the word) would put all their effort into securing a Pyrrhic victory.
Sorry this is so off-topic, but someone had to stand up for Chechnya - one of the most damaged, brutalized, traumatized, forgotten countries on Earth, a blight on the 'ideals' of every 'civilized' nation.
The point is that this accident demonstrates that terrorists have low-tech and high-casualty methods available at their disposal which they choose not to employ for whatever reasons.
Include a QR code on the printed boarding pass that holds the details of the passenger and flight along with a hash of the data, the hash being salted with a secret known only to TSA. The TSA agent then scans the QR code, computer verifies the hash and displays the data on screen for the agent to check against the printed boarding pass and ID. No database look up is needed, just a PC and webcam.
Danger is someone works out or leaks the hash secret.
Never mind that the solution itself is far from 'easy'. Somehow linking every ticket printer to a central TSA-QR service in a reliable and secure way sounds like, uh, fun...
1. All existing hardware and software magically vanishes
2. The government is put in charge of implementing its replacement.
3. The whole system is a dead-weight loss which exists to serve the whims of government oversight rather than facilitate commerce.
> Give the ticket with your friend’s name to the gate agent who lets you board. It will match the flight information and you’ll be allowed to board.
I fly 4 times a month and each time I have to present a piece of photo ID at the gate to the flight attendant that has to match the name on the ticket, ticketing computer and ofcourse me.
The above advice would seem to fail this test.
I've often had the situation of having an "extra" flight ticket for some reason. I've always thought that there is no way I can give the ticket away to a friend, but it seems like this could be a way to do it.
Those who sacrifice liberty for security deserve neither.
(Former employee of ITA Software - does airline flight stuff - not sure how much more I can say, so I'll stop there)