3 ms·
> I get that he was saying that the system is unsafe but a lot of it is only in relation to the web interfaces. I think that was the point though: when these s
by atomwaffel 10y ago
> I get that he was saying that the system is unsafe but a lot of it is only in relation to the web interfaces.
I think that was the point though: when these systems were being built in the 70s (i.e. pre-internet), the security measures they had – many of them based on trust – were perfectly reasonable. You'd need to have physical access to a machine connected to this closed network to even do so much as look at a reservation. And then the internet comes along and these companies (with no experience in web security) hook up their closed, tightly controlled network to an open, not-at-all controlled network with virtually no additional security. I guess it's fair to say that trust alone doesn't work too well on the internet.
> You can't get direct GDS access unless you're working directly for an airline or travel agency. Those people definitely need to see most of the information on the record.
Yes, but the researchers addressed this in their talk about 14 minutes in. The authentication isn't hard to crack: it consists of an agent ID and a password, often in a format like WS<DDMMYY> (where <DDMMYY> is the date of first access to the system). These credentials are shared by the same office at the very least, and I have a sneaky feeling that I might find a conspicuous post-it note on a computer screen if I visit a few of my local travel agents.
- germanier 10y agoIf I recall correctly, he said that travel agencies often have their own system (with individual passwords) hooked up to the GDS using a shared login which was set up once long time ago and then forgot.