United Airlines awards hackers millions of miles for revealing risks
reuters.com
reuters.com
(I used my last lot on two first class tickets to Tokyo which would have cost a lot more than $12k each if bought for cash.)
I can totally see the appeal of flying in an almost empty 747, but at least according to this source[1] that makes a truly shocking 1MPG between the five of you. I can't help thinking the world would be a bit better off if they'd just apologised, and put you on the next flight.
[1] http://science.howstuffworks.com/transport/flight/modern/que...
Sometimes the sizes of the passenger streams between two destinations aren't perfectly in balance. This is most clearly visible on shuttle services between a small and a large city - busy going to the large city in the morning and to the small city in the evening, and semi empty in the opposite directions.
Also seasonal flights - the first flight of the season to depart the destination (and the last to arrive) will often be pretty lightly loaded.
When that situation arises, you will need to reposition a less-than-full aircraft, otherwise your operations obviously falls apart. The GP clearly experienced an extreme case of this, but most likely that aircraft was being filled up at its next departure, and so needed to be there.
This is obviously expensive for airlines, so they try all they can to fill up these flights - which explains that the cheapest tickets are often on times that will be slightly odd or inconvenient, at least to business travellers.
Also, schedules are built around keeping the plane in the air as much of the time as possible, which sometimes means there's a mostly-empty "positioning" flight to get a plane to where it needs to be to carry a full load. I know with US Airways, for example, you can sometimes randomly snag a seat on a widebody international plane between Philadelphia and Charlotte (usually coming out of maintenance and onto transatlantic service, or switching which hub the plane operates from), and on Delta you can occasionally fly a 747 domestically between Atlanta and Detroit (to get the 747 in position to fly from Detroit to destinations in Asia).
I wanted to try first class on the 777 when it first came out, so I just connected in DFW for a PHX-ORD trip, and did the DFW-ORD segment on a 777.
As it turns out, domestic flights are GREAT in big aircraft. (Though I do like the smaller A321Ts too. International-class accommodations, but a really small feeling, like a private plane.)
(I know they're in the same group) I would take LX (Swiss) over LH any day.
When trying to help them in a bad situation on their end, they'll snap at you. (I.e. when they had a plane downgrade in FRA, I offered to be transferred to a UA metal flight on my way back to ORD.. their reaction "WHO TOLD YOU THIS!" [I was trying to help the person avoid involuntary bumping, worse.. I and my travel companion was on an award ticket.. even if it matter anyways]
Back when US Airways (which is where I have my status) was in Star, that was a consistent complaint. Now we're in oneworld with the AA merger, the complaint is British Airways' ridiculous "fuel surcharge" which makes a premium-class mileage-award ticket still cost the same amount of cash as an actual economy-class ticket.
Can this be sold?
Especially with United's latest performance report indicating less than 1/3 of flights operate on time now.
(granted, I still have to avoid AA's hubs like the plague since they shut down for days whenever there's a hint of rain within 500 miles, but at least US Airways is still plenty reliable)
Which is kind of like saying that Ebola isn't any worse than any other hemorrhagic fever.
(FWIW, I've flown >800k miles. Every one of my "top 5 worst flights" was on an American airline, bar one that involved a planeload of drunken Irish football hooligans and a seatmate who was both lecherous and morbidly obese.)
Of course, this is unhelpful if you don't want to go somewhere far away and expensive in a premium cabin. I've always found the value in frequent flyer miles to be in redeeming tickets that I could never afford with money. Using frequent flyer miles to fly from Chicago to Minneapolis is not getting you much value.
I used to love flying United (note: I mostly flown transatlantic flights with them; only one domestic US flight and the difference was stark), for a simple reason:
While basic economy in United isn't all that great, their frequent flyer program is (or used to be, been a few years) very good in terms of ease of getting upgrades or perks. Getting up in the tiers enough to always get free upgrades to Premium Economy didn't take much, and the top tiers are actually possible to reach if you travel a bit for business, unlike e.g. British Airlines where you practically have to live in the air to get to their higher tiers.
Business on United did not match business on e.g. BA or Virgin, but on the other hand upgrades to business on United was as reliable as clockwork - I got upgrades ca. every 3rd leg once I'd gotten to one of their upper tiers (which includes a multiplier on miles).
If you fly now and again for leisure, base it on what you'll pay for, sure. But if travelling for business, how the upgrades stack up makes a huge difference.
http://www.united.com/web/en-US/content/account/lifetime.asp...
Although it was different in the past, all the US carriers now differentiate between miles earned by actually flying (in the industry and the frequent-flyer community referred to as "BIS", or "butt-in-seat" miles), and miles earned from all other associated programs (credit cards, affiliate shopping, etc. etc.).
Only the mileage from actual flying counts toward frequent-flyer status, lifetime benefit thresholds and so on.
Attempting any of the following will result in permanent disqualification from the bug bounty program and possible criminal and/or legal investigation. We do not allow any actions that could negatively impact the experience on our websites, apps or online portals for other United customers.
.. Brute-force attacks
.. Code injection on live systems
.. Disruption or denial-of-service attacks
.. The compromise or testing of MileagePlus accounts that are not your own
.. Any testing on aircraft or aircraft systems such as inflight entertainment or inflight Wi-Fi
.. Any threats, attempts at coercion or extortion of United employees, Star Alliance member airline employees, other partner airline employees, or customers
.. Physical attacks against United employees, Star Alliance member airline employees, other partner airline employees, or customers
.. Vulnerability scans or automated scans on United servers (including scans using tools such as Acunetix, Core Impact or Nessus)
One can hope that the bad guys are similarly polite. And, as you would expect, the United security folks did not see the irony of their restrictions when it was pointed out to them.
I think this one and the "live system" one is due to legal regulations - they obviously do not want you to attempt to actually take control of a plane.
[1]: https://what.thedailywtf.com/t/plane-not-actually-commandeered-by-wi-fi-that-was-not-actually-hacked/47922Something to remember about every company that offers a bounty: they aren't just offering to pay for findings, but also implicitly granting permission to attack them, waiving many of their rights in the process. It makes sense that an airline would do that carefully.
The last bullet addresses a problem everyone has with bounties and scanners, which is that (a) they don't work and (b) they generate loads of bogus findings that the people who pirate the scanners then demand bounties for.
Just deduct the price of the sandwiches from the bounty reward?
"The hardest part - responsible disclosure. Support guy honestly answered there’s absolutely no way to get in touch with technical department and he’s sorry I feel this way. Emailing InformationSecurityServices@starbucks.com on March 23 was futile (and it only was answered on Apr 29). After trying really hard to find anyone who cares, I managed to get this bug fixed in like 10 days.
The unpleasant part is a guy from Starbucks calling me with nothing like “thanks” but mentioning “fraud” and “malicious actions” instead. Sweet!" http://sakurity.com/blog/2015/05/21/starbucks.html
Also, be careful what you wish for. A bug bounty that doesn't come with rules of engagement for a staging site to test is one that gives you permission to test the company's real properties. A bug bounty with staging server rules of engagement is one that doesn't, and you can be sued or even prosecuted for hitting the real servers in that case.
As a rule, big companies with bug bounties are never relying on those bounty programs. When a giant company announces a bug bounty in 2015, they're outing themselves as early adopters (relative to the F500); they'll have been spending buttloads of money on pentesting already.
The rules of engagement would obviously limit you from testing the real properties and restrict you to said servers that are completely isolated from the working production environment. DDOS attacks would be things that hang the application, or database, not simply flooding it with bot requests. Then they could do code injection, etc.
There was no correlation between how savvy the target was and how likely they were to have staging environments for us. The modal organization that gave us a complete staging environment tended to be back-office IT for some huge company. Smart startups virtually never did.
One reason for this is that the environment a pentester needs is different from the one a developer needs. Large portions of the production environment can be stubbed out for a developer, and they can still get testing work done by focusing on their own component. Virtually every part of the environment needs to work, the way it does in prod, for a tester to do their job.
I'm still unclear on why code injection is such a big deal. The company isn't saying you can't test for vulnerabilities that lead to code injection. They're saying you can't actually inject code. There are two reasons you might, as a tester, want to do that: first, to "pivot" through the target to find more vulnerabilities, and second, to confirm a sev:hi flaw.
Neither of those goals are important here, as long as the company is good about acknowledging prospective sev:hi flaws.
Having a secondary 'test' environment isn't as easy as 'oh just clone the VMs'.
1. Don't do attacks all systems are vulnerable to. (DDOS, Brute force)
2. Don't fuck with our customers.
3. Don't fuck with our employees.
Sounds very fair for a company with hundreds of people hanging in the middle of the air at any given point in time.
It is not an audit or internal code review. This is bug bounty program. If you get to a position from where you can directly or indirectly affect live systems, you should stop there and report.
A million frequent flier miles via a major alliance airline is a very, very sweet prize. That's enough for a person to fly themselves and their spouse to basically anywhere on the planet in business class five times, round trip.
A good rule of thumb for the floor value of miles is a $0.01 per mile (i.e. a penny). From a value perspective, you usually get a better exchange for business and first. Of course, you may or may not normally pay for those upgraded seats if it were your own cash so imputing the actual value is difficult in that case.
Some airlines are moving to systems that tie reward miles more explicitly to both cost of tickets paid for and value of tickets being redeemed for but the above scenario is how it's generally been done to date.
It's probably ten times cheaper when you consider the per mile cost to the airline. United could hardly be getting a better deal.
(Again I doubt that this is actually an NSA backed scheme.)
However, if we learned anything from Snowden it is err on the side of assuming that if it is possible then the NSA will eventually try to do it - and this definitely includes forcing US companies to act on their behalf. So post-Snowden the derogatory slur of "obscure conspiracy" doesn't carry so much weight.
$ ./cipherscan united.com
prio ciphersuite protocols pfs curves
1 RC4-SHA TLSv1,TLSv1.1,TLSv1.2 None NoneThe threat model for bugs in United is primarily non-governmental thieves.
Hmm, makes me wonder: could the glitches have been caused by some "hackers" doing testing?
https://www.reddit.com/r/networking/comments/3cme3b/a_route_...
Previously the IRS more or less said that they weren't going to pursue any enforcement of frequent flyer miles obtained in the usual manner. http://www.journalofaccountancy.com/issues/2012/aug/20125796...
British Airways is also notorious for applying "fuel surcharge" fees (payable in cash only) to mileage award tickets, running into the hundreds-of-dollars range when redeeming miles for business-class or first-class tickets.
How? They didn't dump a list of who is participating but Jordan Wiens was named and has a public profile and has published security research. I don't think black hat hackers are decloaking from tor to take a stab at some airline miles.
I wouldn't say the people are outright dumb; maybe they enjoy it and have a vacation lined up. Obviously, it isn't as financially rewarding as other BB programs, but outside of the compensation it doesn't seem overtly malicious. What rubs you the wrong way here?
Paying out with miles is a fun idea, but the strategy seems fatally flawed to me.
I can't even remember a single submission from an American in the bounty I'm involved with.
So in conclusion: if you limit yourself to just that audience, and tempt them with only miles, most americans who are competent enough to obtain bug bounty rewards are making enough money that miles is kind of a dubious incentive. So sure- you save money, but you get fewer submissions, and you get less return on investment than a bounty that pays out.