6 ms·
This was a fantastic talk. Both the content and the quality of the talk itself exceeded my expectations. I knew that bar codes on boarding passes are PDF-417 an
by jc4p 10y ago
This was a fantastic talk. Both the content and the quality of the talk itself exceeded my expectations. I knew that bar codes on boarding passes are PDF-417 and have lots of info embedded, but the attack vectors they discuss are NUTS.
I tried posting this earlier in the week and it didn't get any traction, but user sleavey posted a great summary of the talk in that thread in case you don't have an hour, which is worth reading: https://news.ycombinator.com/item?id=13273314 https://news.ycombinator.com/item?id=13273314
I'm pretty sure the attack vector they discuss about finding boarding passes and changing the frequent flyer number attached to the itinerary is what the people who sell flights for 20-30% the cost[0] do. I've been wondering who that scam hurts for a while, the common thought is that they're using stolen credit cards but from what I understand the "services" are way too reliable to be based off stolen cards.
[0] http://krebsonsecurity.com/2012/01/flying-the-fraudster-skies/ http://krebsonsecurity.com/2012/01/flying-the-fraudster-skie...
- dublinben 10y agoIt's hard to get a clear picture of what's going on from the heavily biased coverage on Krebs's site, but based on the services being offered (flights, hotels, car rentals) they would appear to be purchased with stolen rewards points. If they weren't limited to spending these points, it seems obvious that they'd sell a greater range of services/products.
- cryptarch 10y agoI'm not seeing the "heavy bias" in Kreb's coverage, could you elaborate on that? I've always had a good impression of his work, and I don't get what you're implying. A bias for what?
- ryanlol 10y agoIMO the quality of his reporting occasionally suffers because of his strong personal feelings on the people he's reporting on. That particular article doesn't seem like a good example of such, though.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- ryanlol 10y ago>I'm pretty sure the attack vector they discuss about finding boarding passes and changing the frequent flyer number attached to the itinerary is what the people who sell flights for 20-30% the cost[0] do That scheme wouldn't work, name on tickets needs to match your ff# for you to get the points on basically every single airline. Those services are mostly based on stolen points from bruteforced accounts. VBV cards make credit card fraud a very reliable option too, but it'd have significantly lower profit margins.
- dogma1138 10y agoYou can add any ff number to a ticket purchase, you can also change it during checkout and even after taking the flight.
- ryanlol 10y agoSo? You aren't gonna get the miles. Otherwise, why aren't you already calling through all of your friends and adding your FF# on all of their old flights? Because the airlines aren't completely stupid and you aren't the first person to want free flights.
- dogma1138 10y agoYes you will get miles for those flights.
- ryanlol 10y agoYou must live in an alternate universe with different airline loyalty programs, because that's simply not how they work in the real world. Take a moment of your time and search this on flyertalk or something.
- dogma1138 10y agoWorks with BA, Miles and More and a few others for me. At my previous work we constantly did the swap to reach the needed miles to maintain status or to get a free upgrade / lounge access. I still add my brother on BA since he has an insane status with them and I only fly with them once or twice a year for the upgrade and lounge...
- eigenvector 10y agoThe scammers you cite are generally using stolen points, or more precisely, points from compromised accounts. Generally, with regard to flights, points can only be accrued in the name of the person travelling and can't easily be transferred or aggregated between accounts, so changing the FF# on an active reservation doesn't really help you. You couldn't accrue all your stolen points to one account - you'd end up with a few points in hundreds of different accounts which doesn't have any value. On the other hand, phishing credentials for accounts with hundreds of thousands of points already in them could be quite lucrative.
- foxylion 10y agoAt the end of the talk he said that the point thing is already beeing exploited and that those people change the account name on every transaction to the owner of the flight ticket. And that they are able to collect a massive amount of points without beeing detected.