TSA Now Investigating Boarding Pass Hacker
An anonymous reader writes "A week after the Justice Department cleared him of any wrongdoing, Chris Soghoian, the Indiana University PhD student who created an online boarding pass generator for Northwest Airlines to highlight security holes is on the government's 'no-fly' list. The Transportation Security Administration has now launched its own investigation, says Wired blog 27strokeB. The TSA is claiming that Soghoian 'attempted to circumvent an established civil aviation security program established in the Transportation Security Regulations,' violations of which carry fines of up to $11,000 per violation. That could be a steep fine, says Washingtonpost.com's Security Fix blog: 'Something like 35,000 people viewed and possibly used the boarding pass generator during the less than 72 hours that it was live on his site in November. Soghoian told WaPo: "If they decide that the only safe way for me to leave the country is by boat, then that's pretty much the end of my career here in the States. It's one thing to harass researchers, but if they can chase them out of the country, then that's a real chilling effect."'"
Nothing for you to see here. Move along.
I wonder how many of those were Slashdot users. Shame on us! Shame!!
I could probably smuggle a bomb into a packed sporting event, but would I do it to show it can be done? No. This is no different.
What's the fine for making TSA look stupid?
That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
Enjoy your stay.
Technology -- No Place For Wimps! Grateful Dead and Jerry Garcia Chatroom -- http://www.wemissjerry.org
The people responsible within the TSA need to be dealt with. These fuckheads have some nerve harrassing a researcher for bringing their errors to wider attention.
The fine seems reasonable, will they accept cash?
There are no karma whores, only moderation johns
WTF was Congress (not) thinking when they created the Dept. of Homeland Security?
From what I've been seeing over the last few years, they can do pretty much anything they want and unless you have a Whitehouse contact or are a Senator, you have to bend over and take it.
And it's a "Brazil" reference, of course, which is nicely appropriate in this context...
you had me at #!
As long as they don't fix the flaw, he can still exploit it and circumvent any extra scrutiny they try and put on him.
-- Don't Tase me, bro!
I may cynical, but what this guy did was WRONG.
The difference between a black hat and a white hat is one simple thing: PERMISSION. He wrote a tool to exploit a federal system, and he used it without permission. He is not a hero, he is not the good guy, he is a criminal. I'm sorry, but you need signed permission to do stuff like that.
This guy is a criminal, plain and simple. His intentions are meaningless without permission.
There is no reasonable defense against an idiot with an agenda
:wq
So, what's the message these kind of reactions from the authorities send? To me it seems: "We don't really care if the system is really secure, there are always some friends might need to sneak in, one day. You just let yourself be searched and stay well put during the flight, cause if you don't we call you a terrorist. Trust us or else."
---- MISSING MISCELLANEOUS DATA SEGMENT --- [sigdash] trolololol
because they CHASE THEM AWAY!!
0 7/0419259
http://science.slashdot.org/article.pl?sid=06/12/
Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
What is the actual value and goals of his research? A responsible researcher could have created a proof-of-concept, and raised awareness through media channels, research paper, blog etc. He should have also presented his research to the TSA and the airlines. Instead what he did was not research. He created a website to create fake boarding passes and released it to the public. There was no academic benefit. If I created forged passport software and released it, that's not research. Let's call this for what it is: trouble-making, not research.
Airport security is a joke, and all he did is point that out. I will point something else out. When I was waiting in the immensely long line for United Domestic Check-In, I noticed they controlled access to the door behind the ticket counter with a simple mechanical combination lock. I observed several United Airlines employees entering and every time I could clearly see the code being entered. I felt very secure.
If these people think that they're making air travel safer by suing/investigating someone who makes a blatant security hole public, they're diminishing my trust in their methods. Jail time doesn't scare a suicide bomber.
>The blog is "27B Stroke 6"
>And it's a "Brazil" reference, of course, which is nicely appropriate in this context...
Suggestion for Rule #1 in LUO: No good deed shall go unpunished.
His blog (http://slightparanoia.blogspot.com/) has scans of the letter.
Reading the letter makes it sound much like the case the FBI was workign on against him (and subsequently droped).
All of the legalease (as well as I can read it) states is that you can't make these or higher some one else to make them.
Well, he didn't, he just created a program that COULD. In this case (as with the FBI one) it all seems about intent...
Do Or Do Not, There Is No Spoon, There Is Only Zuul. Everything in the above post is probably opinion.
This is the same problem with all kinds of security systems/programs. How does one point out the error/flaws in said system without falling afoul of the law(s)?
In this case, he would have been better off just telling people it could be done IMO. Just the same, if Kazaa isn't guilty, how can this guy be held responsible for what people did with his demonstration? If he personally used the fake boarding passes to fly and thus circumvent TSA rules, then he's guilty, should be punished. To demonstrate that its possible doesn't make him guilty. Even making it possible for others to do so doesn't make him guilty of anything except making the TSA look stupid.
Printing counterfeit money is not illegal... using it is. Normally, nobody would print it without the intent of using it, but in this case, the whole effort was to prove that it could be done and show that a fake boarding pass ruins security measures. If he can print fake boarding passes, any reasonably savvy group can. The manner used to demonstrate this flaw surely makes it impossible to not fix the problem?
I hope that he is not slapped with huge fines...
Support NYCountryLawyer RIAA vs People
"$11,000 per violation is ludicrous... he can't be held responsible for all those downloads by others."
Follow this recent thread on Slashdot and replace 'Kazaa customer' with 'Chris Soghoian'.
Wired doesn't mention it, but in the kid's blog, he links to a re-implementation of his boarding pass generator, this time using html & java.
. tar.gz
Coralized Archive of the mirror: http://geocities.com.nyud.net:8080/j0hn4dm5/forge
The mirror:
-http://j0hn4d4m5.bravehost.com/
(Coral CDN didn't seem to work on it)
Maybe now the TSA will actually do something about their security hole.
Actually, I doubt it, but we can hope.
[Fuck Beta]
o0t!
"Homeland Security: We can't secure any of our borders, but we'll inconvenience hijackers by making sure they can't brush their teeth!"
This whole airline TSA thing is a crock of BS. Over Kill.
... expected.
So, a bunch of terrorists captured a couple of airplanes and flew them into buildings. Yeah, a bunch of people died, which is tragic. And the Economy Burped, which is
However, we've learned our lesson, and have secured the airplanes better. In addition, I doubt, HIGHLY DOUBT, that they could get anywhere close to doing the same thing, given the same circumstances, mainly because the passengers wouldn't stand for it.
Screening 80 year old grandmas of their knitting needles is stupid. Taking off shoes is stupid. Banning Liquids is stupid. For all the inconvenience of it all, it will not prevent someone from trying to by-pass whatever security is setup, and eventually they will succeed.
I know for a fact that I could bring a knife on board a plane even today, even passing through all the security. They can't stop me if they can't see it. And there are such knives available.
The point is, all this "security" isn't really designed to prevent hi-jackers, it is designed to placate the masses. See my sig for more info
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
The thing is, Americans cannot understand how someone could possibly just "want to help" and not "want to make money". If such a thing happens, then surely they must be up to something, they are probably a terrorist and should be locked up anyway.
It seems to me that the whole point of terrorism is to disrupt the normal lifestyle of those who are terrorized. The US government has often stated that they don't negotiate with terrorists. That's apparently true - they don't negotiate - they just capitulate and let them completely destroy the American way of life. BTW - I'm posting this anonymously so that I don't wind up on the no-fly list :-)
Is that their latest pre-emptive penalty, sticking people they don't like on the no-fly list? While not legally in the same category as house arrest, by infringing on his right to travel, have they or have they not already imposed a civil penalty?
I didn't actually see a citation of where he'd been placed on the no-fly list, can anyone find one and post it? Probably not, since the list doesn't even technically "exist" except as an abstract concept... sorta.
I have to strongly disagree with the dude above who insists that what CS did was "wrong." He neither invented the method of subverting a broken access control system (it had been possible to alter boarding passes with a $50 scanner and a cheap inkjet printer for who-knows-how-long) nor did he encourage anyone to break the law. Worse, TSA's head-in-anus response only even more strongly points up the problem with DHS overall: we can't fix our problems, but we CAN harrass people who point the problems out to the world in the hope we might actually do something.
They're too busy making old ladies take off their shoes.
---------------------------------------
Rotate the pod, please, HAL....
This may fall under double jeopardy
Heil Cheney!
project faceS a set [th3os.com] on his
Although you might need some grizzly bear rifles and a big sign that says, "I do not want to marry a homosexual man!"
The TSA will not bring any real charges against Soghoian. This entire exercise is pure simcurity, simulated security. The TSA runs a hollywood show for its political stakeholders, in Congress, the White House and in the media, to generate PR showing they're "tough on terrorists, strong on security". Without making us safer. In fact, putting us in danger, by ignoring real security requirements, creating security holes, suppressing serious research, and wasting time on this whole charade, when there isn't enough time, money, people, or actual resources to work on the real security work.
Soghoian is being sacrificed to this simcurity charade. As is the confidence of the public, ironically the only worthwhile product of simcurity.
The whole fake, yet lethal Bush simcurity apparatus has to be ripped out by the roots. We need more security than on 9/10/2001, not less. Congress should grab hold of the BS TSA next year and remake it according to our ranks of real security experts. Along with the rest of the leviathan Homeland Security Department, with its flagship FEMA. When Bush stands in the way, that will be even more reason to rip that terrorist incompetent, and his designated successors, out of the path of securing America.
--
make install -not war
I didn't actually see the site while it was up, so maybe the guy actually DID this, but.
To avoid being arrested, why not make the boarding pass have VOID VOID VOID printed all over it in such a way as it exposes the problem, but doesn't actually create a valid boarding pass. Then he would have violated no laws, AND exposed the poor security procedure at the same time.
Once the story broke he could create a boarding pass that's given to someone that's authorized to test the fake boarding pass, or others others could independently confirm that the fake pass would work by comparing it to a real boarding pass.
Anyone know if the site did anything to show that the pass was actually invalid?
It seems a bit foolish to put up a working system and not expect the government to go all apeshit.
AccountKiller
so wait, He makes it so anyone can get a boarding pass.. aka, get through security.. etc etc..
basicly gives terrorists boarding passes and now he's the victim? wtf?
They're just not going to leave the poor guy alone. He embarrassed them, and they're going to make him pay and pay and pay. It looks a lot like getting on the wrong side of the RIAA. They can be entirely wrong, but it costs you a fortune and year(s) of your life to win, and then they only pay a pittance for all their unwarranted grief at best.
"It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
Does that mean he is grounded for being naughty?
That's unfair. Obviously he did his homework.
"Hannibal's plans never work right. They just work." Amy/A-Team
I'll probably be on the no-fly list soon for this, but it's worth pointing out that what Chris did to NWA's boaring passes could be duplicated by just about anyone without special software. While I don't agree with how he exposed the issue (he should have used a fake airline/pass to show the risk), it is worth exposing some very very bad software design. The real criminals here are the coders who developed the boaring pass system for NWA.
The NWA online boarding pass generator uses HTML to render the boarding passes. There's no image processing or anything special involved in changing values on these. Just save it to your desktop, open it in your favorite text editor, and change the text. Bingo. You're flying first class.
There's no reason to believe he even might endanger any airplane that he boards. There's not even the thread of suspicion you'd get from guilt by association. There's no allegation that he has violent tendencies or has threatened violence.
He's there because the no-fly list is a tool for control and coercion at the whim of the authorities without the restraint of statute or jury.
I'm not saying that what the TSA is doing to this guy (or any of us) is right. I think it's blatant sour grapes! But, I don't condone Chris Soghoian's actions either. He should have "done the right thing" and approached the TSA *BEFORE* he made his findings public, and he certainly *NEVER* should have made his web app public. What he did was dumb and irresponsible, period. Was it illegal, ummm, that's up to the courts to decide.
that's pretty much the end of my career here in the States.
So what?
Most Americans who have never lived anywhere else, or who immigrated from third-world countries, think the USA is the best place in the world to live.
But if you travel to any pleasant country, you will find that lots of Americans have chosen to live there.
YMMV, of course. But living in a country where the language is different from the one you grew up with is one of the most educational experiences there is, and you might eventually be grateful for the event which prompted you to leave the USA.
You seem to be forgetting that that had already been done, up to and including having the information on how to create a fake boarding pass published on a congressman's web site for a year or so prior to his arrest. And yes, there had already be newspaper articles on it, and the TSA was either well aware of it and doing nothing or unaware of it even though it had been reported to them multiple times.
Ok, fine. It was trouble making. But for whom? It didn't lower airport security one iota. Anyone who cared about it already new how to do it. What it did do, though, was make trouble for the fake "security" providers at the TSA, and point out the fact that they are ripping us (the taxpayers) off.
We saw the same sort of misleading argument come up when people started pointing out that US Military personnel were being given ineffective bulletproof vests; somehow the people who were trying to raise awareness of the issue were supposedly "helping the terrorists." Which is just nuts. What they were doing is making things uncomfortable for the crooks selling the defective jackets, and having zero impact on the people wearing them unless and until they could raise enough awareness of the issue to get things changed--in which case their actions would have helped the roops, not hurt them.
--MarkusQ
...it's illegal to make the TSA look stupid?
The enemy is RADICAL MUSLIMS*
/N ???
*Possible redundancy detected, please confirm. Y
(-1, bigoted asshole)
http://www.wired.com/news/columns/0,72045-0.html
Because they couldn't take down the big fish, that's why.
i suspect this is a locally initiated effort, not driven by hq.
I found a security hole in a "secrue" system used against pedophiles. I documented the system and submitted it thru channels to the proper authorities. I had to jump up a couple of levels before they could pay attention, but tha tis the way it is done.
What this guy did is not research, but *IS* criminal.
This is a little bit frightening to me, not because they're prosecuting him and all, because I've come to expect that, but because of where it could lead. We all know that security is never permanent. If there is a way to stop someone from doing something, there is a way around it. What happens when the government realizes this? Some of the cases that get pushed through, like this one (IMHO, anyways) are ridiculous, but what happens when the government realizes that it's just the tip of the iceberg? It sounds kinda funny now, but after seeing the ways in which the government has evolved over the last few years, I would believe anything of them. What happens when they start bringing cases against people who make a proof of concept? Once we know something can be done, the rest is relatively easy, right? So proving that something can be done is like telling the terrorists how to do it, right? Of course, once you think of an idea of how to do something, you've taken your first step on the road to making a proof of concept, am I right? I look at those last few sentences and it makes me shudder, how absurd the logic is, but it's all too familiar to me. It's very like certain justifications to get a hold on certain domestic phone records, or even records from your local library. I've always been of the opinion that America is the best place to live (for me, at least), but if thought processes like this continue to spread and grow, I don't know that America will continue to be a good place to live for very much longer. I like my freedom, and I am not willing to give up personal freedoms in order to lead a life filled with a false sense of security, under a tyrannical government that is unwilling to admit that it can and does make mistakes.
Okay, so it's not research. But he's also not at the center of some vast terrorist conspiracy to forge boarding passes and blow up the US. The trouble he made was not a serious threat to US security, and if it was we are in some deep fucking trouble because it's clear that the gatekeepers are asleep at the switch.
No, he has already been treated to the "troublemaker" gauntlet, had his brush with the government and his future almost turned upside down. He's still a kid, and kids will do things without thinking (yes, you can be 25 and childish - they guy has probably never lived outside of academia). The TSA is now practicing a little mafia style justice for losing face to this guy.
Is it just my observation, or are there way too many stupid people in the world?
was never convicted in criminal court. The IRS got him in tax court for not paying taxes.
So justice had there try. Now its TSA's turn. Next the IRS will look over his finances looking for undeclared paypal donations for his defence, student loan fraud, etc. Next the army will conscript him under some secret law, and send him to Iraq. If they still can't get him there is always the RIAA & MPAA.
Yep. Gave me the willies, too. But that was nothing compared to my shock that the whole country didn't rise up and shout their own horror.
We're surrounded by people who don't learn from history, or from reading at all. Presumably because their lips get too tired.
All you need is a couple of Christmas presents.
...Rob
The American Dream isn't an SUV and a house in the suburbs; it's Don't Tread On Me.
That's the United States today, unfortunately. If I had the financial resources I'd move to Europe, Russia, Asia, Australia, anywhere other than here. Anything is better than the $@&^ed-up crap our government is getting away with now. They are a bunch of psychopaths that can't stand to have anyone smarter than they are (which is any non-government employee) point out their flaws. I'll be glad when the common people of this once great nation are fed up and take it back. Terrorist attacks on the United States and abroad have brought out the worst in our government . . . so much so that we're hated around the world by everyone not a government scumbag. Losers!
They put the guy who can forge boarding passes on the no-fly list? does anybody else find that kinda... i don't know... retarded?
How about giving him a call and talking to him about this situation...
James A. Roberts
(317) 390-6916
1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcf
I was reading Feyman's memoirs just before I read this, so please excuse it did affected me a little. What may be perfectly easy to understand to a game theorist and can be summed up in one dilemma can easily take a few dozen pages to describe to the uninitiated. Similarly there are years of courses to understand the basic foundation upon which theoretical mathematicians don't even have to think of consciously. And finally what to a hacker may be plain as day may be completely counterintuitive to the way the rest of the world thinks. (In this case, any output can be converted to input, and fed back out again.)
Further, because the concept is known by a vendor as a "possible" problem, doesn't mean they will address it. By creating an interface for even those unfamiliar with the theory, the concept became a reality. On top of which, there is innate skepticism from the part of the vendor (for the most part) that their product could be broken in such a "trivial" manner; or put another way big head smackers sometimes take simple examples.
Does NOBODY see the irony here?
The government is putting him on the No-Fly list, BECAUSE HE RELEASED A PROGRAM THAT ALLOWS PEOPLE TO CIRCUMVENT THE NO-FLY LIST.
So this helps, how?
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
Shame on us! Shame!!
I'm ashamed to live in a country where so many idiots are in positions of authority.
(que up the "then leave" remarks in 3... 2... 1...)
--Phillip
Can you say BIRTH TAX
Victimless crime
Victimless crime
Victimless crime
Or maybe he can dig a tunnel to Mexico. He can't use an existing Mexican tunnel, due to all the oncoming traffic...
Excuse me, but please get off my Pennisetum Clandestinum, eh!
One of my favorite Archie-isms.
My mom says I'm cool.
Too Stupid for Arby's (USA fast food joint)
Too stupid to work there, so they're TSA instead. These folks are the lowest form of law enforcement, unable to even qualify as rent-a-cops. Don't you *feel* safer, citizen?
Seems to me this is all not about security. If it were, they would welcome the guy. This is really about dominating the population. ''You have an inconvenient opinion? Sorry, our software says you are a potential security risk. No airtravel for you....''
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Don't fuck with us, because we'll fuck with you.
It's disappointing how far things have gone off-track.
--
Don't like it? Respond with words, not karma.
The TSA guy aren't idiot. They do not want to investigate the kid to make the problem go away, they want to send a STRONG message to other kid , or heck, security researcher : "do the same stunt and we will make sure you will sooooo buried in shit that you can say goodbye to your carrier, flying/travel freedom, and peace of mind". In other word they are trying to implement self-censorship through fear.
C. Sagan : A demon haunted world:
http://www.amazon.com/gp/product/0345409469/
visit randi.org
It goes without saying that for anyone gullible enough to think that they can get away with doing something like this under their real identity... (fill in the blanks)
This is the one time where I would categorically have advised to consult with an attorney beforehand, so that he could have understood the type of trouble he might be in for pointing this out the way he did, and releasing the software in the wild.
It really doesn't seem very smart to go about it headfirst like this, and he is paying for it now.
Maybe we need 'whistle-blower lawyers', or at least courses in responsible and perfectly safe whistle-blowing?
There has to be a better way to force the TSA to fix their flaws.
Z.
<conspearacy theory>
I know this is an extreme comparison, but how'd that sort of thing work out for Karen Silkwood? She went old-school public and got killed! Perhaps the immediate notoriety offered by the web is "safer".
</conspearacy theory>
It must have been something you assimilated. . . .
Well at least they are doing something proactive to catch kids wanting to see mom/dad at the gate.
I always thought they were strictly reactionary and look for things that have already happened?
When the only tool you have is a hammer, every problem looks like a nail
Certanly the act of embarassing the emperor has to be punished..
FRA: STFU GTFO
Yeah, I'm sure none of the terrorism in Ireland was due to radical Christians. And terrorism may have originated with the Zealots, a Jewish group, back in the first century.