4 ms·
Seems very just. BA clearly had no controls to understand the code running in production was the code they had deployed. I hope this serves as a wake up call to
by planetjones 7y ago
Seems very just. BA clearly had no controls to understand the code running in production was the code they had deployed. I hope this serves as a wake up call to other companies who have a blatant negligence for infosec.
- buro9 7y ago> clearly had no controls to understand the code running in production This applies to everyone who has advertising or third party anything on their page, no?
- raesene9 7y agoYep pretty much :) Actually it's worse than that. Even without 3rd party JS, most major websites these days run on large piles of open source libraries that have never been security reviewed (e.g. code from npm, rubygems, PyPi, NuGet) and attackers are increasingly targeting those underlying libraries for compromise...
- jeltz 7y agoBasically, yeah. You can specify a hash for third party JS and audit it at that version and you can sandbox JS in iframes, but most people do not do that.
- isostatic 7y agoIf they choose to import some code from elsewhere sure. They could run their own advert by hosting "advert.jpg" on their server and wrapping it in an anchor tag. BA however are a company selling their own product, no need for them to have adverts. If they want to dilute their product with adverts then they take the risk of fines (as well as losing custom)
- ginko 7y agoWhy does an airline even need to show advertising on their page in the first place. You'd think they would be most concerned about selling their own product.
- isostatic 7y agoGenerally the flip side of service cutting is aggressive monetization
- donaltroddyn 7y agoMany of them show ads for partners to generate ancillary revenue, which is a large source of profits for airlines. In addition, if they themselves _advertise_, they'll need to add tags to track attribution, conversions, etc.
- isostatic 7y agoFunny how people advertised for decades on tv, in newspapers, and with leaflets through the door, without invasive tracking
- donaltroddyn 7y agoFair enough, but if you're advertising online with any of the major companies today, there's no way to do so effectively without instrumenting at least your landing pages and conversion pages with advertising tagging.
- M2Ys4U 7y ago> This applies to everyone who has advertising or third party anything on their page, no? Yes. Which is why you shouldn't run third-party advertising.
- ddalex 7y agoAt my company, we used fixed dependency version numbers for external libraries. The libraries are tested and we do take sample traffic snapshots from browsers using automation to see what our users see. But this approach only takes care of simple, entry level attacks. A highly targeted attack, that lies dormant in a compromised library for ears, and it's engineered to avoid detection, e.g hiding for certain IPs or self-removing the code when the debug console is open - this is impossible to defend against, to my knowledge. How would you defend yourself?
- planetjones 7y agoI would daily compare the file running on the website that I deployed matched the file on the server verbatim. I think this would have been enough with BA. Secondly I would run a daily test in production which verifies the requests the browser makes match those expected. This would only need doing on the pages which capture payment information. Neither solution is particularly difficult. BA clearly did nothing. Hence the negligence and huge fine.