32 ms·
When you browse Instagram and find Tony Abbott's passport number
- Nextgrid 6y agoI don’t know if it’s just me or it’s the fact that I’m reading this on mobile on a small screen but I couldn’t stand the writing style. Curious to know if anyone else felt that way.
- codetrotter 6y agoI think it was funny and I liked it. Still didn’t read the whole thing though – maybe later, am not in shape right now. But did read quite a bit of it.
- steveklabnik 6y agoI read it on my phone and I love the writing style. Different people are different.
- starpilot 6y agoSame. Sounds like the author thinks he's way funnier than he is.
- mulmen 6y agoI laughed out loud multiple times reading this and sent it to some friends whose senses of humor I respect and the consensus is this is funny.
- ezluckyfree 6y agoI agree, kind of. I had to skim it, some of the jokes were funny, it just took up too much space.
- h0l0cube 6y agoThe writing style was irreverent, colloquial, and replete with cultural references, but also dense with information. I felt a constant tension of wanting to skim-read and actually parsing the content, but found it really entertaining all the while.
- gonzo41 6y agoIt reads like a travel diary. Which I really like because you get the things that are done and the thoughts and feelings along the way.
- CosmicShadow 6y agoI loved it, it helped me keep reading the whole way through an extremely long, yet engaging article. Different people like different writing styles and humour obviously.
- traverseda 6y agoYeah, it was a bit yikes.
- mindfulhack 6y agoYeah I thought the person to be quite young. But I understood, as I've been that young and written in almost exactly that writing style before. :) I skimmed through it feeling fondness for my youth.
- stordoff 6y agoI found myself rolling my eyes a few times, but the core content was good so I didn't find it all that off-putting. "Update: I have been arrested." did leave me slightly confused for a while though, probably due to the verbosity making me want to scan read.
- mulmen 6y agoIf you were scanning that would be an easy joke to miss. The giveaway is the previous paragraph ending mid-word like the authorities just busted in and hauled the author off to a CIA black site.
- netsharc 6y agoCouldn't stand it either, since I (probably like most of us here) know about the "scan the 2d barcode to get the booking number, use that and passenger last name to see their flight details" trick. The kid draws out that first bit for too long. Although he did get clever and used the developer tools (again here he goes into boring details) to find the actual passport number as some hidden JSON, and some other internal airline info...
- fireattack 6y agoI hate it. But I knew I'm never a fan of this kind of overly joking style (the same reason I can't stand famous YouTube Channel "half as interesting", despite I love his main channel.)
- Camas 6y agoFeels like I accidentally opened discord
- kayson 6y agoI couldn't either. It was absolutely terrible. I think you can achieve the style and voice he was going for without being completely over the top, which he very much was.
- C19is20 6y agoHumour, with a 'u'.
- 0xy 6y agoSurprisingly good experience, and even a call from the man himself. I'm actually impressed, I expected way more incompetence and fumbling from a government.
- deleted 6y ago[deleted]
- aahortwwy 6y ago> “You could drop me in the bush and I’d feel perfectly confident navigating my way out, looking at the sun and direction of rivers and figuring out where to go, but this! Hah!” I mean not to call him out but this did happen and he didn't navigate his way out (although that says nothing about his confidence). https://www.smh.com.au/national/tony-abbott-lost-in-the-outback-20100303-phd9.html https://www.smh.com.au/national/tony-abbott-lost-in-the-outb... EDIT: To be fair, it's been a decade. Maybe he's worked on his orienteering skills since having that experience?
- chris_wot 6y agoSure, this is the guy who knighted a prince and ate a raw onion. What did you expect? Abbott was Australia's Trump. Thankfully he lasted in office an even shorter time than the people he replaced.
- bmarquez 6y agoI don't get it, is there something noteworthy about eating a raw onion?
- nicwilson 6y agoWhen you use it to hide the breath of an alcoholic, yes.
- boyter 6y agoYes and no. It was the pinnacle in a series of bizzare behaviour from Tony while he was the Prime Minister. Certainly its the one people most remember of him. Keep in mind he ate it with the skin on as well. I think its also something people look out for, with the previous PM Kevin Rudd being somewhat infamous for eating his own ear wax on live TV. When I was working on an archive project for the ABC, "tony eating onion" or some variation was the most common thing people searched for in the system when they first started using it.
- JadeNB 6y ago
- sellyme 6y agoThe contact form on Abbott's website 403ing is impressively on-brand.
- coagmano 6y agoI wouldn't be surprised if the staff deliberately sabotaged it. I've worked for a party before and the emails are horrendous
- Polylactic_acid 6y agoThere are so many website that will automate spamming every politician contact form with prewritten content about an issue so I'm surprised if those contact forms route anywhere other than /dev/null.
- iso947 6y agoMy MP had several death threats last year - including in the post to her home address inside an otherwise normal looking birthday card.
- thomasfromcdnjs 6y agoaha amazing read, quality content.
- carrolldunham 6y agoclickbait. no "passport" is found. very long winded insufferable hooting about finding the passport number from an instagrammed boarding pass booking number. is that still a big security hole? i guess. could have been one tweet though
- juancampa 6y agoI found the writing style to be very entertaining. Maybe someone else would've stopped at a tweet but in the end he managed get on the phone with Tony Abbott himself and got himself a cool story to tell.
- sellyme 6y agoWhen a (former) head of Government is calling your personal phone number I think you're entitled to want more than 280 characters to tell the story of how the hell that happened.
- h0l0cube 6y ago> very long winded insufferable hooting about finding the passport number Did you read the whole thing? Also included were phone number, notes from airline staff. > is that still a big security hole? To quote the article: > Just having the information on the passport is not quite as powerful as a photo of the full physical passport, with your photo and everything. > With your passport number, someone could: > - Book an international flight as you > - Apply for anything that requires proof of identity documentation with the government, e.g. Working with children check > - Activate a SIM card (and so get an internet connection that’s traceable to you, not them, hiding them from the government) .. and then it had a couple more points. > could have been one tweet though And then you'd miss the whole story about informing government security and Qantas of the flaws (difficult apparently), tracking down the staff of the ex-Prime Minister of Australia, and then finally getting a call from the man himself. Might not be your cup of tea, but not 'click-bait'. The author put a lot of effort, and told a really interesting story.
- parksy 6y agoThe full title is "When you browse Instagram and find former Australian Prime Minister Tony Abbott's passport number" not sure why the title here omits "number" but it is there on the actual post. Also as someone that hasn't ever done anything like this before, it was interesting to read the journey from end to end, specifically the steps taken to try and responsibly disclose a security breach and the hoops he jumped through which might seem obvious for someone who does it on the regular, but was somewhat enlightening to someone who has never encountered something like this in life.
- rvz 6y agoWe blame these social networks for collecting vast amounts of our private data (yes we should), yet these folk have no problem of posting already sensitive information under a hashtag - creating an Aladdin's cave of identities waiting to be stolen for fraud as this blog-post has demonstrated. 'If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place' - Eric Schmidt I guess they will learn the hard way given that they aren't really 'tech savvy' or internet wise these days.
- Polylactic_acid 6y agoThe problem is people have no idea what is sensitive. Until just now I would have thought a boarding pass was safe to share. Its more the airlines fault for making this info so easy to access with what looks like unsensitive info.
- bjoli 6y agoI have told people at airports to not friggin post their boarding passes or documents containing their booking refeeence on Instagram. Back when I was 20 I didn't lot of stupid things. One was to change tine obnoxious details about their reservations. When they were in air (and presumably had their phones off) I sent them a text message. "Never put booking information on asocial media". I could probably have gotten in a lot of trouble.
- ClumsyPilot 6y agoBoarding pass clearly should not allow tgis lwvel of access to yiur personal infornatiob- it has one job, boarding a plane.
- cobookman 6y agoIt's also used in the customs process.
- POiNTx 6y agoApart from the really interesting content, this is an extremely good read, strikes me as the right kind of balance of information and keeping you entertained. I really enjoyed this writing style!
- anon9001 6y agoThis was really a delight to read. I wonder if the author was raised on 2600. Fantastic stuff. Also visited his page. Does not disappoint: https://mango.pdf.zone/ https://mango.pdf.zone/
- SamBam 6y agoFigured the least I could do after reading the article was crack the puzzle, and felt good that I did since I usually fail at these kinds of things.
- exikyut 6y agoOh, that was indeed fun. "Uhh... how many layers deep is this going to g-- oh, ok. Nice :D"
- airstrike 6y agoHard mode is an absolute delight
- CPLX 6y agoI was pretty sure after a few paragraphs he was getting his style inspiration from Douglas Adams, but when I got to his line saying “this is widely regarded as a bad move” I became certain. It is an excellent stylistic choice for documenting interactions with commonwealth bureaucracy, of course.
- dwd 6y agoSomething Adams incorporated a lot into his stories: "But look, you found the notice, didn’t you?" "Yes," said Arthur, "yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard'." I did chuckle out loud when I read "For security reasons, we try to change our Prime Minister every six months".
- starpilot 6y agoThe tl;dr: > Your boarding pass for a flight can sometimes be used to get your passport number. Don’t post your boarding pass or baggage receipt online, keep it as secret as your passport. > How it works: The Booking Reference on the boarding pass can be used to log in to the airline’s “Manage Booking” page, which sometimes contains the passport number, depending on the airline. I saw that Tony Abbott had posted a photo of his boarding pass on Instagram, and used it to get his passport details, phone number, and internal messages between Qantas flight staff about his flight booking.
- gkanai 6y agoThis was a great read! Highly recommended.
- kccqzy 6y agoNice. Here's a similar personal story with a PSA that sometimes blurring is NOT sufficient. A friend of mine posted on Instagram a picture of a U.S. visa (or something similar; it was probably five years ago) to announce her trip to the U.S., and she took care to blur out sensitive information such as her passport number. But a Gaussian blur is easy to reverse and I successfully unblurred it and told her my discovery. I didn't use any specialized software; it was just Mathematica with its built-in ImageDeconvolve function with guessed parameters for the Gaussian kernel. I personally recommend blacking out (add a black rectangle) instead of blurring, and if it is a PDF, convert to an image afterwards because too many PDF editors use non-destructive operations to add a new object instead of changing what's underneath.
- function_seven 6y agoYour advice is good, and I agree that you didn't use specialized software to reverse the blur, but this > I didn't use any specialized software; it was just Mathematica with its built-in ImageDeconvolve function with guessed parameters for the Gaussian kernel. is one of the most HN comments I've come across recently :)
- mroche 6y ago> is one of the most HN comments I've come across recently :) That gave me a laugh. I don't have any experience with Mathematica, but everytime I see it mentioned (usually on HN) I'm amazed at the sheer breadth the system is capable of. The amount of use cases and possibilities blows my mind.
- iamshs 6y agoI loved the writing style. That "hard mode" effect had me wheezing though.
- nl 6y agoInterestingly (and strangely) some frequent flyer numbers are treated by Australian airlines as confidential information.
- fphhotchips 6y agoI feel like this buries the lede massively: Qantas' system was run by Amadeus, who also run the booking system for some 200 other airlines [0]. If you could do this with Qantas and get all those notes, you could probably do it to any other airline and get them too. That would be bad enough, but it also appears that this issue (or one very much like it) has been reported widely at least back in early 2019. So, either Amadeus didn't fix the issue until it was disclosed here (very very bad) or Qantas didn't update their booking system for a security patch (also very bad). [0] https://techcrunch.com/2019/01/15/amadeus-airline-booking-vulnerability-passenger-records/ https://techcrunch.com/2019/01/15/amadeus-airline-booking-vu...
- robjan 6y agoThe issue isn't Amadeus, it's that some airlines don't bother to use accounts with lower levels of privileges for operations which don't need full access. There are a number of different levels which are intended to be used for different purposes: for example, the credit card numbers are not visible to booking agents but can be accessed by the anti fraud department. Some airlines just use a single "god mode" account for their whole e-commerce platform because it's cheaper / more convenient for their developers / vendors.
- saberdancer 6y agoCould you explain how returning all data to the frontend is connected with "god mode" usage? Is the Amadeus system such that it created/masks different fields in the data depending on the access level you have? In this case, "hacker" logged in a customer facing portal, this is probably not even an user account in the strict sense of the word. I am asking as I fail to see how it is not a development issue. If they returned only the data that was needed on the page, it wouldn't expose internal comments or passport IDs.
- robjan 6y agoThere are of course two errors that the developer of the backend made. The first is not filtering what came back from the Amadeus API, but the second one - the one I am referring to - is using an Amadeus API key with too much access. Amadeus filters the booking record depending on the level of access that the user accessing it has (the user being the backend in this case). In a previous life for another airline, I have experienced this problem before when a vendor tried to get something through to production which was retuning credit card numbers and expiry dates to the frontend (but not the CV3). This was all because the vendor tried to use the highest privilege API key rather than the one with access to the specific info they needed. It never got past UAT thanks to thorough security review in this case.
- inoffensivename 6y agoThis was a thoroughly entertaining read, thank you!
- dayjobpork 6y agoIt's nice to live in a country where not only do various parts of the government actively try to help someone with a really bizarre issue, but no one got arrested (or shot) for bullshit trumped-up hacking charges. I can't think of many other countries responding well to 'hi I'm some random person and I used the PM's boarding pass and found out all this secret stuff'
- soulofmischief 6y agoWhen your simple blog page is crashing Spice and virt-viewer, there is a serious bloat problem. I can't even view this blog because it immediately crashes.
- tschwimmer 6y agoThis is one the of the funniest things I've read in recent memory. He made an Instagram post 30 second check of Chrome's dev tools into a narrative I couldn't stop reading. Thanks for brightening my day author!
- rootsudo 6y agoNarrative is cute, but too much.
- btilly 6y agoThe following line confuses me, because it contradicts a lot in the post. Update: I have been arrested. Is that just an obvious mistake? Or is there a news flash that we would like to hear more on?
- beatrobot 6y agoI like that there was such a good response to the disclosure from all the different parties, compared to this: https://research.digitalinterruption.com/2020/09/10/giggle-laughable-security/ https://research.digitalinterruption.com/2020/09/10/giggle-l...
- jeffbee 6y agoAre passport numbers secrets?
- macintux 6y agoYes. The bottom of the post covers some of the things you can do with the number.
- zbrozek 6y agoYet good luck traveling without actually surrendering them to all kinds of places you'd rather not. Like hotel clerks basically everywhere.
- andreareina 6y agoI'd say sensitive at the very least. Like social security numbers they shouldn't be, but when places use them for identification without checking authenticity and authorization...
- ObsoleteNerd 6y agoThey're a form of Government-issued photo ID, so not "secret" but definitely "sensitive". At least in Australia, a passport can be used as your primary ID for a lot of stuff such as renting houses, buying mobile phones, connecting services to your home, booking flights, renting cars, etc etc etc.
- iandanforth 6y agoThis is a long read, but trust me, keep reading it's great.
- mulmen 6y agoThis was a great read but I'm a bit disappointed there are no easter eggs in the page source. Or maybe I'm just not finding them.
- hayyyyydos 6y agoThere is one, but it's on the homepage - take a look under the "about" heading at the bottom and go from there.... (assuming that's the puzzle that ASD figured out)
- alottafunchata 6y agoThis was a great read--thanks!
- dmje 6y agoBloody love the way this guy writes...
- WrtCdEvrydy 6y agoFor anyone who wants to do this easier... ZAP Proxy has a HUD display that will allow you to see the data flying on a page after you load it. No need to do funky Inspect Element magic. Works wonders for reverse engineering how your fancy UI talks to the fancy API to do the fancy things. If you can't figure out ZAP with HUD, you can alternatively use the Network tab on Chrome and switch to AJAX (if it's something that happens without the page loading)
- bigiain 6y ago> funky Inspect Element magic Are you sure you're on the right website?
- ibudiallo 6y agoThe power of Inspect Element. This is exactly how I found out I was underpaid[1]. A company I worked for used a software called erecruit to manage my contracts. When you click on a clients name, it makes an ajax request to fetch the data. Being a web developer, I inspected the data returned. I'm pretty sure all the developer did was: echo json_encode($queryResult); I saw how much I was getting paid vs how much they were charging clients. I quickly changed my prices after that. [1]: https://idiallo.com/blog/how-much-do-you-charge-for-your-work https://idiallo.com/blog/how-much-do-you-charge-for-your-wor...
- dylan604 6y agoI think this is a lesson lots of early AJAX/client-side coders should be forced to learn. When you do a `SELECT * FROM` and return the entire result, that data is visible on the client end in full detail (if you're familiar with how to use the browser's dev tools that is). Maybe you only make some of that data visible to the user in the UI, but the data you didn't use is still part of that AJAX return. Only send to the browser the data you actually need!
- bagacrap 6y agoEvery consulting firm pays their employees way less than the hourly rate they bill clients. That's how the firm exists. Good for you that you were in a situation to dictate your compensation.
- michaelsitver 6y agoOne of the better blog posts I’ve read
- Lorin 6y ago"Unblending the smoothie" is such a great line.
- gouggoug 6y agoOut of curiosity a few months back I spent a few hours looking at this exact hashtag (#boardingpass) and other travel related hashtags. I ended up thinking that Instagram was actively removing pictures of boarding passes because I could only find a surprisingly low amount of pictures containing valid Lastname/BookingRef. As for the few pictures available, the references were often either too old, or partially covered. I'm still wondering if Instagram does remove such photos.
- spyke112 6y agoI even get a 501 Not Implemented for https://www.instagram.com/explore/tags/boardingpass/ https://www.instagram.com/explore/tags/boardingpass/ on desktop. May be related?
- sorum 6y agoSome Grade A zingers in there: > The man in question is Tony Abbott, one of Australia’s many former Prime Ministers. > For security reasons, we try to change our Prime Minister every six months, and to never use the same Prime Minister on multiple websites. > Harold Holt was another former Prime Minster and we… lost him? He disappeared while going for a swim one morning. This is not a joke. We named Harold Holt Memorial Swim Centre after him. I repeat, this is not a joke.
- danieltrembath 6y ago"...I called up and was all like “yeah bloody g’day, day for it ay, hot enough for ya?”. Once the formalities were out of the way..."
- ralphael 6y agoI couldn't stop laughing. His skills at hacking are only matched by his wit at writing.
- fergie 6y ago"(Instagram, in case you don’t know it, is an app you can open up on your phone any time to look at ads)."
- Dragonai 6y agoThis was the line that made me audibly laugh. Couldn't not finish the article after that. Great read.
- tomerico 6y agoI found his advice to Tony on how to get better with computers remarkably insightful: > I said there probably was a book out there about “the basics of IT”, but it wouldn’t help much. I didn’t learn from a book. 13 year old TikTok influencers don’t learn from a book. They just vibe. > My mum always said when I was growing up that: > There were “too many buttons” She was afraid to press the buttons, because she didn’t know what they did I can understand that, since grown ups don’t have the sheer dumb hubris of a child, and that’s what makes them afraid of the buttons. > Like, when a toddler uses a spoon for the first time, they don’t know what a spoon is, where they are, or who the current Prime Minister is. But they see the spoon, and they see the cereal, and their dumb baby brain is just like “yeA” and they have a red hot go. And like, they get it wrong the first few times, but it doesn’t matter, because they don’t know to be afraid of getting it wrong. So eventually, they get it right. > Okay so I didn’t tell the spoon thing to Tony Abbott, but I did tell him what I always told my mum, which was: “Mum you just gotta press all the buttons, to find out what they do”.
- jhealy 6y agoA similar anecdote from my family. My uncle (a sheep farmer) and I discovered that: 1. I was afraid to touch anything in a car engine, but happy to muddle through unfamiliar computer issues 2. He was afraid to click unknown buttons on a computer screen, but comfortable pulling apart and rebuilding an unfamiliar car engine. In both cases, we were confident because we knew whatever mistake we made we'd be able to reverse it. And in both cases, we were afraid of making a mistake that we couldn't reverse.
- dorkwood 6y agoThat's basically how I taught my father to use a computer. It came down to two things: 1. He was terrified of breaking it, so I told him that there was nothing he could possibly do to it that I couldn't fix. I made sure to sound overly confident -- almost like I was challenging him to break it. That gave him the confidence to do whatever. 2. Every time there was a problem with it, I would Google the answer in front of him, and he'd watch me figure it out in real time. Eventually, he got the confidence to start Googling things himself. The tech support calls dropped off pretty steeply after that.
- pretendgeneer 6y agoGreat read. I really like the bit about learn "the IT", there's no book or anything to be good at computers you just gotta fuck around and find out a bunch. > Like, when a toddler uses a spoon for the first time, they don’t know what a spoon is, where they are, or who the current Prime Minister is. But they see the spoon, and they see the cereal, and their dumb baby brain is just like “yeA” and they have a red hot go. And like, they get it wrong the first few times, but it doesn’t matter, because they don’t know to be afraid of getting it wrong. So eventually, they get it right.
- Cthulhu_ 6y agoThe problem is that there are a LOT of books, but what is relevant just changes every couple years. I mean the IT books section of the charity shops is a good example of this, there's so many there for older versions of Office, operating systems, etc. That said, I had a school book (Structured Computer Organization by Tanenbaum) that explains a lot of the basics of computers. Sure, it's about the Pentium architecture and early JVM and doesn't cover multi-core architecture or using GPU's to crunch numbers, but it goes through a lot of the basics.
- The_Amp_Walrus 6y agoThe hacker known as "Alex" also gave a really fun talk at PyCon AU in 2018: https://www.youtube.com/watch?v=ZlNkIFipKZ4 https://www.youtube.com/watch?v=ZlNkIFipKZ4
- mproud 6y agoGiven how fun this post was to read, I can only imagine he is equally as funny in person!
- adamjb 6y agoAssociated blog post https://mango.pdf.zone/operation-luigi-how-i-hacked-my-friend-without-her-noticing https://mango.pdf.zone/operation-luigi-how-i-hacked-my-frien... and salty hacker news comments (his words) https://news.ycombinator.com/item?id=14919845 https://news.ycombinator.com/item?id=14919845
- zamfi 6y agoI am very impressed by this piece. Something about how “Alex” manages to blend the kind of humor not typically associated with compassion or competence, with a story that is most spectacular because of the very compassionate and competent actions of its protagonist...I literally couldn’t stop reading. So well done.
- kabacha 6y agoReal question here is: should the passport number have any expectations of privacy? It seems like such an easy thing to expose as you literally put it down on every document like hotel check ins etc. AFAIK it's not even a random number and instead it's generated from basic info like birth year/place/gender. That being said it was a really good blog!
- rswail 6y agoIt depends where you are from. Our (Australian) passports have a "series" letter at the start and then a set of numbers. Not sure whether they are random or incremental or derived. YMMV based on nation that issues yours.
- vishnugupta 6y agoI accidentally discovered a way to get hold of passport details of random people by applying for Visa on arrival to Vietnam. There are these online portals which do some document pre processing which is legit. And on landing in Vietnam we are expected to show that we have already applied for Visa. It so happens that these portals do batch processing. Which means my application is processed along with a half a dozen or so other random applicants. And so I applied for one. And when I received the confirmation document I received the entire batch file. It included passport number, expiry date and other PII of ten random people which would be super valuable in the hands of criminals and such. And conversely ten random people know my PII
- hdi8534 6y agoThe same when you apply to give up vietnamese citizenship, all your info are public on the goverment website (pdf files with name, birthday, current addresss...)
- rntksi 6y agowith the way how the government over there works, even if you have those information... there's really nothing much to do with it.
- mannykannot 6y agoIf you are applying to give up Vietnamese citizenship, I would guess that you are no longer living in Viet Nam, so this information might serve as a starter kit for someone to steal your identity?
- city41 6y agoI recently bought a used phone on ebay. When I turned it on it had the previous owner's data in tact and no passcode. I opened Gmail and was in their account. I immediately factory reset the phone. My point being sensitive data leaks all over the place in many ways in today's world.
- jwong_ 6y ago
- philliphaydon 6y agoI still find it strange you can manage a booking with just a reference and name. About ~5 years ago someone I follow on twitter posted their boarding pass and I replied to them with a screen shot asking if I should cancel the booking. They removed their post and I removed mine. But all it took was the reference on the boarding pass and their last name...
- Cthulhu_ 6y agoWhat I've gathered left and right wrt the airline industry is that it was one of the earliest industries that went digital, and / but they have a lot of legacy going on. I mean in this particular case, they could have Abbott create an account on their website first, but then, someone else booked the ticket for him so that makes things more complicated (because they don't have an e-mail address), and then there's tickets being booked all over the world, and then loads of people don't have computers or e-mail. It escalates quickly.
- howlgarnish 6y agoThe amount of pain still caused by things like somebody back in the sixties deciding that two characters is plenty to encode every single airline ever is still felt to this day. Witness the majesty of the "controlled duplicate": https://en.wikipedia.org/wiki/Airline_codes https://en.wikipedia.org/wiki/Airline_codes
- astura 6y agoI understand why... A lot of business travelers have a third party book their flights, so there isn't always a username/password. Airlines and travel agencies don't make it clear that it's sensitive information though.
- orisho 6y agoThis post was very amusing! It always bordered on silly meme-style writing, but never doing too much of it at once which I find annoying. The story itself was also very interesting!
- half-kh-hacker 6y agoI love Alex's stuff.
- Lerain 6y agoThat was extremely entertaining and so much fun to read, thanks!
- Zealotux 6y ago>I personally recommend blacking out (add a black rectangle) instead of blurring This can be reversed as well, if you do black things out this way: please make sure you're using 100% opacity black. I've managed to retrieve data from plenty "blacked-out" documents simply by playing with contrast and exposure filters in Photoshop because the opacity wasn't set correctly.
- cricalix 6y agoBlack it out, print it to paper, scan it back in, embed the image in a Word document, and print to PDF. Wait, that's just how "most" people do it anyway..
- jslakro 6y agoMost hilarious techie post I've read ever
- thdrdt 6y agoLately I am thinking about building a framework for web APIs where the database stores the owner, group and other's rights for each entity. The framework will then fetch data based on the user and fills the models based on the rights set for each field. Exactly for the reason shown in the article. I believe right now it is still too difficult to do this in any framework. That's why developers take shortcuts and just expose all entity data or just make a mistake and forget about it. Does anyone know if such a framework already exists? So per field rights, not per entity rights.
- throwawaynothx 6y agoor... GraphQL.
- thdrdt 6y agoHow does GraphQL fix the problem of showing different fields depending on rights?
- mulmen 6y agoTake a look at Postgres roles, I think they are similar to what you describe. This should allow you to set row level permissions per user. Not sure how well that scales. I know postgrest uses it. https://www.postgresql.org/docs/12/user-manag.html https://www.postgresql.org/docs/12/user-manag.html
- efreak 6y agoI think the Windows registry has this, doesn't it? Not really applicable to this use case, and do far as I know it's world-readable (acls are applied for writing, not reading) but it does have per-key ACLs (not sure about per-field).
- andrewnicolalde 6y agoThis has to be the funniest and most gratifying thing I’ve ever read on Hacker News. Great job!
- gregjw 6y agoMost entertaining post-morterm I've ever read, Australian through and through.
- pachico 6y agoWhat a fun article to read! Congratulations!
- lanevorockz 6y agoWe are trying to fix this in the language ... It's just hard to convince people around that the change is worth it, I guess that I found the perfect use case.
- chrismorgan 6y agoA few years back when I was looking to buy a house, I was interested in how long the property had been on the market. (I was looking in country towns and their outskirts, where six months is a typical time for a property to be on the market; I even saw one or two blocks of land that seemed to have been for sale for at least five or six years.) Few real estate agents tell you this on their websites (though if you ask, they may), and aggregators like domain.com.au and realestate.com.au don’t either. Except sometimes they do, in the markup. My vague recollection (I don’t have the scraping scripts I wrote handy right now, they’re just on my old laptop and backups) is that I found a JSON blob in the realestate.com.au mobile website containing two dates, and that the domain.com.au desktop website fetched a JSON response from an API which happened to contain one date. I ended up deciding that REA’s dates were when the listing was first seen and last updated, and the Domain one was one of those. Neither of these sites were actually displaying this date, but the data was there for me to take and feed into my research. Careless or unwitting information disclosure from APIs—sometimes sensitive, sometimes not—is a real problem.
- strange_aeons 6y agoThat's interesting. The time on market is always listed on Danish real estate websites. And the aggregator sites also have previous listings.
- cottsak 6y agoAlex, you are so funny!
- reillyse 6y agoWhat a well written article. Really enjoyed that. If the hacking doesn't work out get a job writing about hacking...wait.
- ironfootnz 6y agoThat’s the best funny post about “CVE” I’ve ever read.
- sellyme 6y agoHow about this one: http://tom7.org/chess/cve.pdf http://tom7.org/chess/cve.pdf Sarcastic PDFs never stop being amusing to me.
- mrg2k8 6y agoImagine doing something similar to a government application of an EU country and in 15 minutes finding a way to expose all citizen requests for an EORI number ever (some tens of thousands), with all personal details there for you to take. This was last year and in the meantime they updated their application from an ancient 2003 Oracle one to one that's more modern. Thinking in perspective now, I regret not going out with it because that ancient application probably cost millions of euro from taxes.
- JoachimS 6y agoHighly entertaining reading.
- bassie2 6y agoClicking Inspect Element in this post results in some fun as well (NSA Tracking cookies). A true Droste effect.
- tdy721 6y agoThis write up... irreverent and dumb. Did you study any Dave Barry? <3 I would love to buy a book. I mean probably not me, but if you need any moneys
- FerretFred 6y agoThis is a great read!
- brlnwest 6y agothis is such a great story. Love the way he writes!
- juststeve 6y agoAustralian here, he’s doing the best he can
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- ChrisRR 6y agoThat's a long read, has anyone got a blurb so I know what I'm getting myself into?
- seesawtron 6y ago>> Instagram, in case you don’t know it, is an app you can open up on your phone any time to look at ads). Nailed it.
- BoredomHeights 6y agoI can't believe I read this whole thing only to find out at the end that this dumbass thinks the earth revolves around the sun. I wish I'd known we were dealing with a wacko from the start so I could have saved 20 minutes of my life.
- abanayev 6y agoDid anyone notice the line, “Update: I have been arrested”? Chekhov’s gun is just hanging there.
- abhiminator 6y agoGreat post, thoroughly enjoyed reading it. BTW, on a side note, when you try and visit the blog's homepage[0] and scroll down to the bottom, you find a link to an actual (password protected) PDF file called Mango.pdf[1]. The author 'Alex' says the password for the PDF has been embedded in the page and it didn't take me a lot of time to figure the password out from the HTML source[2]. But when I opened the PDF, I was hit with this random string of characters: cGJhdGVuZ2h5bmd2YmFmLCBsYmggZmJ5aXJxIHpsIHlodnR2IGNobW15ci4gQCB6ci BiYSBnanZnZ3JlIGp2Z3UgbGJoZSBzbmliaGV2Z3IgcXJmZnJlZyBnYiB0cmcgbGJo ZSBlcmpuZXEuIFZnJ2YgeXZ4ciwgYWJnIG4gaXJlbCB0YmJxIGVyam5lcSBmYiBodQ o= I tried to decode this using every available decoder, but it only throws up random result. Was wondering if any of you smart people here had any idea about this code. [0] https://mango.pdf.zone/ https://mango.pdf.zone/ [1] https://mango.pdf.zone/mango.pdf https://mango.pdf.zone/mango.pdf [2] view-source:https://mango.pdf.zone/ https://mango.pdf.zone/ EDIT: SOLVED IT! As the commenters who replied to me mentioned, this puzzle is double-encoded. I think the trick is to figure out which decoder to use first.
- nbgl 6y agoHint: try ROT13.
- abhiminator 6y agoThank you. Tried that as well, still throws up a string of letters and numbers. But the frequency this time seemed a bit more consistent, so the trick is to apply some sort of frequency analysis, I guess. Still on it. BTW, are there any more of such 'puzzle hunt' websites where you could play around and sharpen your decoding skills? Thanks!
- rbinv 6y agoHere's a list: https://gist.github.com/numberwhun/d85075f4f63411bafa1c6e40e15e4c4b https://gist.github.com/numberwhun/d85075f4f63411bafa1c6e40e...
- barbs 6y agoQuick posix shell rot13 tip: pipe it into: tr '[A-Za-z]' '[N-ZA-Mn-za-m]'
- p49k 6y agoI would encourage anyone interested in this article to read it thoroughly to the end. This is one of the most satisfying articles I’ve read recently and I really enjoy the author’s unique sense of humor.
- rocqua 6y agoTry some of james mickens articles: https://mickens.seas.harvard.edu/wisdom-james-mickens https://mickens.seas.harvard.edu/wisdom-james-mickens They are written in a similar style, I really love them.
- lpa22 6y agoI thoroughly enjoyed reading this as well. It’s very rare I read blog posts of this length to the end but I was hooked
- razki 6y agoReally enjoyed reading this. Thanks for redirecting my time brotheeeRRRR
- kdtsh 6y agoThis is certifiably grouse.
- xyzal 6y agoIs it just me, or did anyone else try to clean up their monitor from dust, realizing eventually the "dust" is the websites background image?
- sygma 6y agoGreat talk [0] given during the 2016 congress touching on the Amadeus flight booking system and the danger of posting your boarding pass on social media [0]: https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carmen_sandiego https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme...
- aneutron 6y agoThis was an amazing watch. Thank you very much for the link.
- jezze 6y agoA friendly advice to the author of this article. Even though I enjoyed reading the whole thing, if you are gonna have a tl;dr in your article; put it at the start, not at the end. Almost felt lika a mockery.
- tunnuz 6y agoThis entertained me a lot.
- marvinblum 6y agoWhat a brilliant blog post. Thank you for posting it!
- fahrradflucht 6y agoGreat read. If somebody is interest in another great talk about boarding pass data security, there is this one from 33c3: https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carmen_sandiego https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme...
- philipdavis 6y agoQuestion: do you think you will be arrested for doing the same thing if it was in your country? (A from myself: yes absolutely)
- logifail 6y agoIn some countries, identity documents are in relatively frequent use. The number of authorised strangers who would have access to one's identity document might be significantly higher in these jurisdictions than, say, the number who would be able to view Tony Abbott's passport number. I'm thinking of - for instance - the 'personnummer' in Sweden (I've heard friends recite theirs in public when asked for them). Q: Should (merely) the number from your passport really be considered a secret?
- toyg 6y agoIn theory no, but in practice yes. It's the same for a lot of metadata about our lives that routinely doubles up as authentication factor, e.g. "to verify your identity, can you please confirm the first line of your address and your postcode?"... Most of my neighbours know that!
- extraduder_ire 6y agoAs an example of metadata revealing a lot about you: Ireland got a postcode system in 2015 (the last time they considered implementing postcodes to improve autosorting, they were so late to the party that "an post" (Irish postal service) had OCR machines good enough to just read the whole address) which assigns each residence in the country a 7-digit alphanumerical code. Called an "Eircode" [1] It is purported to be a solution to packages getting lost or delayed, and an unambiguous way of giving someone a building's address. An Eircode can be resolved into a full postal address, and GPS co-ordinates for the address. e.g, here's some Eircodes; Facebook's headquarters: D02 Y098 President's house: D08 E1W3 Data protection commission: D02 RD28 To get the info for any of these, check out: https://finder.eircode.ie/ https://finder.eircode.ie/ Personal note: I'm not too jazzed on the specifics of the implementation, but it sure is handy when you're shitfaced and can trivially explain exactly where you live to a food-delivery driver over the phone. [1]: https://en.wikipedia.org/wiki/Postal_addresses_in_the_Republic_of_Ireland#Eircode https://en.wikipedia.org/wiki/Postal_addresses_in_the_Republ...
- mikeappell 6y ago> If you laid all the people I contacted end to end along the equator, they would die, and you would be arrested. Possibly the best line in an article full of really fantastic lines.
- seapunk 6y agoThat is one of the best blog post I read for a long time.
- spyder 6y agoIt would've been faster and easier to report it to Instagram but this way it made a better story and educated the user better than instagram just removing the picture.
- XCSme 6y agoAmazingly written post, really enjoyable to read! It's amazing that we have all those security protocols (HTTPS, e2e encryption, secure log-in, etc.) but in the end most of the "hacks" are just people being stupid or manipulated through social engineering.
- pietroppeter 6y agois there a book about basics of IT? https://news.ycombinator.com/item?id=24492554 https://news.ycombinator.com/item?id=24492554
- dependenttypes 6y agoIs the passport number supposed to be secret? You show them when you buy alcohol in some countries as well to the police if they ask for it - all of these people can copy the number if they so wish.
- nmeofthestate 6y agoLooked interesting, but as an old fogey I just couldn't get past the "omg u guise yikes jklsflsfdjfds" style.
- beervirus 6y agoWell now I feel compelled to read everything this person has ever written.
- dis-sys 6y agoWhat is the big deal of knowing Tony Abbott's diplomatic passport number?
- deleted 6y ago[deleted]
- fardeem 6y agoThis is easily top 1% of all writing on the internet
- pragmaticpandy 6y ago> I’ve been practicing every morning at sunrise, but still can’t scan barcodes with my eyes. rofl. Great writer.
- pragmaticpandy 6y agoTIL McAfee® Gamer Security is a thing...
- kulesh 6y agoEnjoyed the read very much, thanks.
- AFlyingBoom 6y agoI find it incredible that Abbott being openly vulnerable about his lack of competency with computers, has been more effective in making me like him than anything he has ever done in his political career. Teams of media advisors and a very favorable alliance with the Murdock press have paled in comparison to this one blog post that didn't even have that as an aim.
- jasomill 6y agoReminds me of the time I learned Jim Morrison's social security number from a framed form hanging on the wall next to my table at a Hard Rock Café, written in ballpoint pen, "redacted" with a magic marker that did nothing, obviously, to obfuscate the impression made by the pen in the paper. While I have no idea how the SSN of a long-dead rock star could ever be useful, I'm certain I still have a copy saved around here somewhere...
- imwm 6y agoI can't believe how funny this writer is
- ddiddu 6y agoit is easy to figure out passport number in a picture of ticket posted on Instagram
- Aeolun 6y agoTo be honest, I find it ridiculous (just like with social security numbers) how much you can apparently do just by virtue of knowing a passport number. It shouldn’t work like that.
- ztgasdf 6y agoReally entertaining read. I'm amazed how much information they were able to get from the airline website.
- maxden 6y agoThis got picked up by the news in Australia [0], they also interviewed the author [1]. [0] https://www.abc.net.au/news/2020-09-19/tony-abbott-boarding-pass-online-cyber-safety-mistake/12678776 https://www.abc.net.au/news/2020-09-19/tony-abbott-boarding-... [1] https://www.abc.net.au/radio/melbourne/programs/drive/alex-hope-hacking-tony-abbott-boarding-pass/12675504 https://www.abc.net.au/radio/melbourne/programs/drive/alex-h...
- lilfatbitch 6y agoAnyone else really annoyed at the way this is written? Like the author thinks they're funny and cute adding nonsensical commentary on the side but really I just wanna read what happened.