6 ms·
This has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.
by jaywalk 4y ago
This has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.
- Cupertino95014 4y agoThis has to do with being on a public network (an airplane), does it not? Maybe your outrage is over-the-top.
- petschge 4y agoAbsolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.
- Cupertino95014 4y ago> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't get their credit card number or security code. You don't get access information on any of their web accounts. Correct? If you spy on their internet activity during the flight, it's all encrypted. You won't learn anything. However, you do have the ability to change their password, so they can't get into their own account anymore. You could also bill all your own activity to their account. I don't know if you can bill other things to the account. You could get access to whatever data was stored in that account. I don't know what that would be, other than when & how much you used it in the past. Is this a complete summary of the potential damage? Since there's no Reply button for the two answers to this: Neither of them answer my last question ("is this a complete summary..."). Should I assume it is? And I never said "oh but the data leak isn't really that bad of a vulnerability" -- you did.
- jaywalk 4y agoYou completely missed what this vulnerability is. It has nothing to do with intercepting another user's traffic. The checkout page in question actually uses SSL anyway, so it's not even possible absent some sort of MITM attack. This has to do with API endpoints that exposed customer information and allowed password changes without checking that the request was coming from the customer. The customer didn't have to be logged in to the account, or even on the flight in the first place. If they had an account, it was exposed.
- Cupertino95014 4y agoQuite right. But as I said, "intercepting another user's traffic" would be an additional vulnerability, but not if you're on VPN. Maybe you could just admit that and end the argument. This doesn't require you to minimize the seriousness of the bug.
- petschge 4y agoNone of the impact of having your data leaked from your account is in any way modified by using a VPN for your data traffic while you are on the airplane. Hence the initial reply of that your suggestions of a VPN is irrelevant. Don't try to change this into a "oh but the data leak isn't really that bad of a vulnerability" after having lost that argument.
- Cupertino95014 4y agoWhere do I say "oh but the data leak isn't really that bad of a vulnerability"? I tried to summarize what the vulnerability is. Why are you so upset about that?
- Mogzol 4y ago> Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? Going by the same logic, what can a black hat exploiting this bug do if the target ISN'T using a VPN? Using or not using a VPN in the context of this bug is totally irrelevant.