8 ms·
TripIt insecurely broadcasts sensitive travel details in calendar feeds
- colinbartlett 12y agoI wonder if we can ever look forward to a day when unencrypted http just doesn't exist. When the only option is https?
- userbinator 12y agoI'm in favour of encryption for protecting sensitive data (TripIt is violating this principle), but don't think it should be needed for publicly accessible information. The centralised CA model is probably one of my biggest gripes about using HTTPS.
- fabulist 12y agoCAs are unfortunate, but the reality is that all data is sensitive to some degree. TripIt's data is more sensitive than, say, which Wikipedia article I'm reading, but that still gives away a huge amount of information about what my current thought process is and where its going. The only way to avoid the dragnet surveillance we're currently experiencing is to take away the opportunity.
- MichaelGG 12y agoAnd an attack can also modify data. Even "public" data, like Wikipedia info, could be valuable to modify. You can attack a user that way by providing misleading information. Or carry out XSS-like attacks. Or just insert spammy links or redirections all over the page.
- daigoba66 12y agoTLS is more than just encryption; it's also a mechanism that enables you to, in theory, verify that the content is from the source it says it's from.
- CWuestefeld 12y agoAs I see it, that is actually the problem here. As things stand, if you don't have the resources to go through the process for proving your identity (or have other reasons for not wanting to do so) to establish the certificate, then you are unable to have encryption, or at least not without raising an error message in your users' browsers.
- nknighthb 12y agoThe cheap certificates are domain-controlled, meaning that "proving your identity" is just "proving control of the domain name", such as by clicking a link in an email sent to a listed whois contact address. If you can't prove control of the domain, you absolutely should not be issued a certificate for it under any circumstances.
- blueskin_ 12y agoOnly if the CAs relinquish their monopoly position.
- michaelrshannon 12y agoWow - I've been a huge advocate for TripIt in the past - definitely need to pause using it though until they get this sorted :/
- mseebach 12y agoJust don't use the "export" feature, or use it securely, eg. by exporting to Google Calendar.
- nodata 12y agoThe other pages on this site are pretty good: Little Snitch, Scribd, PGP..
- fabulist 12y agoIts important to note that they're pointing the finger at the MIT PGP keyserver, which has long been notorious for being poor in the security department. This is not even the worst of their crimes; for a long time (perhaps still?) they were ignoring key revocations. Meaning, if your key was stolen and you sent out a message declaring it void, people using pgp.mit.edu would never get the message. >.< tl;dr don't use pgp.mit.edu .
- tonywebster 12y agoAuthor here. If you let me know some sources for the above, I'd love to add them. Contact info in profile. Thanks!
- fabulist 12y agoI believe I originally heard that here: https://we.riseup.net/riseuplabs+paow/openpgp-best-practices https://we.riseup.net/riseuplabs+paow/openpgp-best-practices
- toyg 12y agoThe good side of it is that this hole doesn't seem to be actively exploited on a significant scale. Feed urls cannot be harvested without sniffing traffic for each and every user, and profit is very indirect. The bad side of it is that TripIt/Concur don't seem very responsive on the issue. It often feels like TripIt is on life support, really, which is a shame -- I use it extensively because of its wonderful "just forward to plans@tripit.com" feature.
- colinbartlett 12y agoKayak has the same feature and seems pretty stable (it's now owned by Priceline).
- bergie 12y agoI'm still a TripIt user, but it seems Google Now is replacing that feature more and more (if you allow it to scan your email). The flight cards I got to my smartwatch when flying back from Finland last week were pretty handy with the gate info and everything...
- christop 12y agoUnfortunately, you need to have a Gmail account to get all the various automated hotel/car/flight reservation and parcel tracking notification stuff. It would be nice if there was an API into Google Now (or even a Tripit-style email to selectively forward to) to insert such events, for those who can't use or choose not to use Gmail.
- mvid 12y agoMuch of the value from TripIt is also in collaborative travel planning, which google now doesn't seem to have an interest in.
- donkeyd 12y agoThe case of using the info at a hotel to get your room key is pretty reasonable. On the home break-in story however there's a lot of evidence that this hardly ever happens if it happens at all. There are plenty analog ways in which criminals scout for homes where the occupants are on vacation. These ways are often much more efficient than their digital counterparts. I'm not saying this article should be disregarded, however if you're on holiday and you used TripIt's feed on public WiFi, the chance that you're house was broken into because of this is negligible.
- onion2k 12y agoOn the home break-in story however there's a lot of evidence that this hardly ever happens if it happens at all. What evidence would/could there be? Someone sophisticated enough to be wifi sniffing HTTP calls on open networks for details of when people are travelling is unlikely to then just do a straightforward smash and grab burglary. Even just the fact they're bothering with information gathering in the first place points to a criminal who's bit cleverer than your typical housebreaker. I'm not saying you're wrong, just questioning whether there'd be enough data points to suggest one way or the other. It could be a 'common' method of scouting places to burgle among criminals who manage to not get caught.
- riquito 12y agoAn evil organization may build a CAAS (crime as a service, TM since now :-p) and the little burglars may buy a 1.99$ app to know if there is a free house nearby. Mmm, this may work...
- onion2k 12y agoCrime As A Service is essentially what Moriarty does in the Sherlock Holmes novels. Make you wonder if it's ever been done for real...
- FedRegister 12y agoMurder for hire would be CAAS.
- mjs 12y agoThe "http" calendar URLs (now?) actually redirect to "https" URLs, but this doesn't help retrospectively, since the only thing that needs to be kept secret is the URL, and that's redirected in plain text… TripIt's web UI actually present the "private" calendar URL with a "webcal" scheme--is that typically secure? (You can replace "webcal" with "https" and things work just fine, though.)
- nodata 12y agoIs TripIt referencing these http urls? If yes, then you have the same problem (the eavedropper just has an extra step to follow the URL).
- toddn 12y agoFWIW, both Google Calendar and the subscribed calendar on iOS attempt to access webcal:// URIs over SSL on port 443. I'm not sure at what point they would fall back to http; if they do, I haven't seen it.
- plg 12y agoWhat's the big impediment to just making all websites https, all the time? Technical? Financial? Honest question.
- monort 12y agoFor small sites it's mostly certificate and dedicated IP price. Wildcard certificates price is especially egregious. For big sites - probably their load balancers can't handle the https load.
- lorenzhs 12y agoDedicated IP? I thought SNI was supported just about everywhere by now. Also, if all you need is a certificate for one subdomain (or maybe a couple of certificates for one subdomain each), a StartSSL certificate is free. It's not SuperDuperSign Extra Validation Plus Platinum, but it's accepted by all major browsers ;) EDIT: Wikipedia tells me "As of November 2012, the only major user bases whose browsers do not support SNI appear to be users of Android 2.x (default browser), Internet Explorer on Windows XP and versions of Java before 1.7 on any operating system." - a small company should be fine.
- Perseids 12y agoRemember that this is not about browsers, but about the TLS libraries the calendar software uses. For instance Java only supports SNI since version 7.
- _delirium 12y agoThe Python SNI situation was also cleared up very recently, with commits to some of the widely used libraries only happening in mid-2013. I wouldn't be surprised if many installations haven't yet upgraded to those post-2013 versions. See e.g.: https://github.com/shazow/urllib3/pull/156 https://github.com/shazow/urllib3/pull/156
- sbarre 12y agoA wildcard SSL certificate is $250 per year. You can't tell me that this is a prohibitive cost for someone operating a serious business.
- martingordon 12y agoHmm, I guess it's a good thing I proxy through Google Calendar then, huh? The Google/TripIt connection may be unencrypted, but I'm assuming (and hoping) that Google Calendar feeds are sent over HTTPS.
- deleted 12y ago[deleted]
- jqueryin 12y agoThis is a nicely detailed post of uncovering the flaw (Thanks Wireshark!) and explaining the implications. My biggest concern with this post and the entirety of the blog is that I'm not sure as to whether you're performing full disclosures before the shaming. It'd be irresponsible not to give the team time to respond and remedy. It'd be a quick addition to the footer to blanket that you do full disclosures and give an adequate amount of time before posting. Edit: not sure if this post in particular had the disclosure statement added after my comment, but most of the other blog posts are devoid of disclosures.
- sandy12 12y agoDid you even read the entire post? > Only my own information was accessed in these screenshots, and I manually changed the name from mine to John Doe. I contacted TripIt / Concur Technologies about this issue via e-mail and Twitter NINE MONTHS AGO and never heard back. A similar TripIt calendar feed security issue was brought up on the TripIt-maintained Get Satisfaction website OVER SIX YEARS AGO, with no resolution.
- jqueryin 12y agoIf you browse through other posts on the blog, you'll notice a recurring pattern of no mention of disclosure.
- JoeAltmaier 12y agoStrawman? Has anybody ever been robbed due to a high-tech criminal intercepting their calendar data? Keep in mind that most breakins are by local teenagers looking for a thrill. And they are much more likely to know you're going on vacation because they're your neighbors.
- joshdance 12y agoHe's not talking about getting robbed, he is talking about someone changing or canceling your airline reservation.
- JoeAltmaier 12y agoWha? The article changed after my comment? Strange.
- NDizzle 12y agoThat's HN for you. Seeing what they want us to see.
- JoeAltmaier 12y agoHN has nothing to do with the original article?
- joshdance 12y agoWeird. Maybe he saw those comments and changed it.
- drglitch 12y agoAs OP and many others have said, airline confirmation numbers are a pretty big personal security risk - an international itinerary always carries passport #, address, emergency info, et. A very bad practice I've seen over and over are people doing boarding-pass-selfies in airports, inadvertently exposing their confirmation numbers to entirety of their twitter/instagram/facebook feed. At best, you can move your buddy's girlfriend to be next to you on a flight instead, at worst, you can cancel their flight or move them to an earlier/later one. At very worst, you can use the plethora of PI data for ID theft.
- cV6WB 12y agoWow – this is terrible. FWIW you can choose to disable "Include detailed items in your calendar feed" from Settings > Publishing Your Data.
- rdl 12y agoThe concept behind httpshaming is great, although it would be nice if there were a softer/more positive initial request to the sites to add https. However, it's not like https is new; even post-Snowden is over a year now. I love TripIt, but they really need to fix this for me to keep using it.
- ismaelc 12y agoHi guys, Chris here, Developer Evangelist at Concur. I just got word from the TripIt team that they are aware of the issue and working to get it fixed. Feel free to email me at chris.ismael@concur.com if you have questions. Thanks!