TSA Now Investigating Boarding Pass Hacker
An anonymous reader writes "A week after the Justice Department cleared him of any wrongdoing, Chris Soghoian, the Indiana University PhD student who created an online boarding pass generator for Northwest Airlines to highlight security holes is on the government's 'no-fly' list. The Transportation Security Administration has now launched its own investigation, says Wired blog 27strokeB. The TSA is claiming that Soghoian 'attempted to circumvent an established civil aviation security program established in the Transportation Security Regulations,' violations of which carry fines of up to $11,000 per violation. That could be a steep fine, says Washingtonpost.com's Security Fix blog: 'Something like 35,000 people viewed and possibly used the boarding pass generator during the less than 72 hours that it was live on his site in November. Soghoian told WaPo: "If they decide that the only safe way for me to leave the country is by boat, then that's pretty much the end of my career here in the States. It's one thing to harass researchers, but if they can chase them out of the country, then that's a real chilling effect."'"
I wonder how many of those were Slashdot users. Shame on us! Shame!!
What's the fine for making TSA look stupid?
That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
Enjoy your stay.
Technology -- No Place For Wimps! Grateful Dead and Jerry Garcia Chatroom -- http://www.wemissjerry.org
The people responsible within the TSA need to be dealt with. These fuckheads have some nerve harrassing a researcher for bringing their errors to wider attention.
The fine seems reasonable, will they accept cash?
There are no karma whores, only moderation johns
WTF was Congress (not) thinking when they created the Dept. of Homeland Security?
From what I've been seeing over the last few years, they can do pretty much anything they want and unless you have a Whitehouse contact or are a Senator, you have to bend over and take it.
And it's a "Brazil" reference, of course, which is nicely appropriate in this context...
you had me at #!
As long as they don't fix the flaw, he can still exploit it and circumvent any extra scrutiny they try and put on him.
-- Don't Tase me, bro!
So, what's the message these kind of reactions from the authorities send? To me it seems: "We don't really care if the system is really secure, there are always some friends might need to sneak in, one day. You just let yourself be searched and stay well put during the flight, cause if you don't we call you a terrorist. Trust us or else."
---- MISSING MISCELLANEOUS DATA SEGMENT --- [sigdash] trolololol
because they CHASE THEM AWAY!!
0 7/0419259
http://science.slashdot.org/article.pl?sid=06/12/
Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
What is the actual value and goals of his research? A responsible researcher could have created a proof-of-concept, and raised awareness through media channels, research paper, blog etc. He should have also presented his research to the TSA and the airlines. Instead what he did was not research. He created a website to create fake boarding passes and released it to the public. There was no academic benefit. If I created forged passport software and released it, that's not research. Let's call this for what it is: trouble-making, not research.
Airport security is a joke, and all he did is point that out. I will point something else out. When I was waiting in the immensely long line for United Domestic Check-In, I noticed they controlled access to the door behind the ticket counter with a simple mechanical combination lock. I observed several United Airlines employees entering and every time I could clearly see the code being entered. I felt very secure.
Suggestion for Rule #1 in LUO: No good deed shall go unpunished.
His blog (http://slightparanoia.blogspot.com/) has scans of the letter.
Reading the letter makes it sound much like the case the FBI was workign on against him (and subsequently droped).
All of the legalease (as well as I can read it) states is that you can't make these or higher some one else to make them.
Well, he didn't, he just created a program that COULD. In this case (as with the FBI one) it all seems about intent...
Do Or Do Not, There Is No Spoon, There Is Only Zuul. Everything in the above post is probably opinion.
This is the same problem with all kinds of security systems/programs. How does one point out the error/flaws in said system without falling afoul of the law(s)?
In this case, he would have been better off just telling people it could be done IMO. Just the same, if Kazaa isn't guilty, how can this guy be held responsible for what people did with his demonstration? If he personally used the fake boarding passes to fly and thus circumvent TSA rules, then he's guilty, should be punished. To demonstrate that its possible doesn't make him guilty. Even making it possible for others to do so doesn't make him guilty of anything except making the TSA look stupid.
Printing counterfeit money is not illegal... using it is. Normally, nobody would print it without the intent of using it, but in this case, the whole effort was to prove that it could be done and show that a fake boarding pass ruins security measures. If he can print fake boarding passes, any reasonably savvy group can. The manner used to demonstrate this flaw surely makes it impossible to not fix the problem?
I hope that he is not slapped with huge fines...
Support NYCountryLawyer RIAA vs People
I *so* wanted to mod this post "troll," but that is unfitting - your ideas are not meant to provoke, but to unprovoke, and breed grudging contentment with the sad status quo. So no troll moderation for you. Sadly, there is no "defeatist fucktard lemming" moderation available. That would be fitting.
Eloi are stupid, throw morlocks at them!
Exactly, of course this is against the law.
I'd also say it's deserving of a fine of around $100 or so, nothing more.
And immediate job loss without privileges for several of the highest ranking managers responsible for letting the insanely lacking security system live for so long.
I believe posters are recognized by their sig. So I made one.
Wired doesn't mention it, but in the kid's blog, he links to a re-implementation of his boarding pass generator, this time using html & java.
. tar.gz
Coralized Archive of the mirror: http://geocities.com.nyud.net:8080/j0hn4dm5/forge
The mirror:
-http://j0hn4d4m5.bravehost.com/
(Coral CDN didn't seem to work on it)
Maybe now the TSA will actually do something about their security hole.
Actually, I doubt it, but we can hope.
[Fuck Beta]
o0t!
"Homeland Security: We can't secure any of our borders, but we'll inconvenience hijackers by making sure they can't brush their teeth!"
This whole airline TSA thing is a crock of BS. Over Kill.
... expected.
So, a bunch of terrorists captured a couple of airplanes and flew them into buildings. Yeah, a bunch of people died, which is tragic. And the Economy Burped, which is
However, we've learned our lesson, and have secured the airplanes better. In addition, I doubt, HIGHLY DOUBT, that they could get anywhere close to doing the same thing, given the same circumstances, mainly because the passengers wouldn't stand for it.
Screening 80 year old grandmas of their knitting needles is stupid. Taking off shoes is stupid. Banning Liquids is stupid. For all the inconvenience of it all, it will not prevent someone from trying to by-pass whatever security is setup, and eventually they will succeed.
I know for a fact that I could bring a knife on board a plane even today, even passing through all the security. They can't stop me if they can't see it. And there are such knives available.
The point is, all this "security" isn't really designed to prevent hi-jackers, it is designed to placate the masses. See my sig for more info
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
The thing is, Americans cannot understand how someone could possibly just "want to help" and not "want to make money". If such a thing happens, then surely they must be up to something, they are probably a terrorist and should be locked up anyway.
No, if he was a criminal he'd have kept it quiet and sold it. How do we know a criminal's version of this scheme wasn't already running? We don't, but we know that now it won't work. For every security researcher there are 3 self-serving fiscally-motivated elitist assholes and it is the security researcher's moral obligation to practice full disclosure (after giving the company notice and time to fix the hole).
I am one of many. My idea is not unique, nor do I expect my voice alone to sway you. I speak in a chorus of opinion.
Like how ABC news had permission when they showed that they could sneak box cutters onto a plane, just 1 year after 911?
Molog
So Linus, what are we going to do tonight?
The same thing we do every night Tux. Try to take over the world!
Is that their latest pre-emptive penalty, sticking people they don't like on the no-fly list? While not legally in the same category as house arrest, by infringing on his right to travel, have they or have they not already imposed a civil penalty?
I didn't actually see a citation of where he'd been placed on the no-fly list, can anyone find one and post it? Probably not, since the list doesn't even technically "exist" except as an abstract concept... sorta.
I have to strongly disagree with the dude above who insists that what CS did was "wrong." He neither invented the method of subverting a broken access control system (it had been possible to alter boarding passes with a $50 scanner and a cheap inkjet printer for who-knows-how-long) nor did he encourage anyone to break the law. Worse, TSA's head-in-anus response only even more strongly points up the problem with DHS overall: we can't fix our problems, but we CAN harrass people who point the problems out to the world in the hope we might actually do something.
They're too busy making old ladies take off their shoes.
---------------------------------------
Rotate the pod, please, HAL....
This may fall under double jeopardy
Hm I could swear I once heard something along the lines of government of the people, by the people, for the people.
It's our obligation to watch the government, question it, and try to fix it when it's not doing its job. The airlines and the government were clearly aware of this problem as it had been "exploited" by a congressman a couple years back. This is a case of government employees covering their asses instead of fixing the problem. Soghoian publicized the problem because no one was doing anything about it.
I'm glad to know there are some people who won't roll over saying the government always knows what's best for us. WE run the government and write their checks. Don't forget it.
Do you think the flaw ever would have been brought to attention had he gone through the proper channels? I for one am happy he did this and brought it to everyone's attention, once it's out like this it's hard to down play and ignore.
So when normal attempts at bringing a problem to light fail because they are to lazy to fix what is found he should just drop it till someone with malicious intent finds it and then start screaming "I TOLD YOU SO!!!". Great idea, I'm sure that would console everyone who was hurt or lost friends and family because of the problem. Pardon him for not wanting people to get hurt first.
You mad
Nice Flaimbait...But i'll bite.
Your argument is simply foolish. The TSA is inept at running a dept, so they are also inept at hiring researchers or security folk to check up on their stuff. This is a government agency. This person committed no actual crime -- he didnt use one, and didnt even print one.
The criminal would have kept this secret, and used it to his/her benefit by selling it to terrorists, criminals, or whatever. Those types of actions should be punished, SEVERELY!
What did he do? He made us all safer. He did it by exposing how ridiculous the TSA is, and gave them all the knowledge to fix the problem. He did not personally gain from this experience. If anything, he has suffered already for it much more than he ever should have. I would feel differently if this was a private company and not a public-oriented service (like AIRLINE travel), to which my tax dollars go (both to bail out airline bankruptcy, as well as to operating the TSA).
IU needs to stick up for their researchers, and foot the legal bill. I doubt they will, however, having been a past student, the administration at IU is pretty much inept equivalent to the TSA in my eyes.
God forbid someone try to HELP the world...
The difference between a black hat and a white hat is one simple thing: PERMISSION. He wrote a tool to exploit a federal system, and he used it without permission. He is not a hero, he is not the good guy, he is a criminal. I'm sorry, but you need signed permission to do stuff like that.
Wouldn't asking permission defeat the purpose?
Ever heard of whistleblower laws to protect people who serve the common good?
Don't you think we should be free to examine the system on our own?
When nobody listens, soemtimes you ahve to make a stronger statement. Thats what he did and should be commended for it. I would guess that you think Dieboold's e-voting machines are a good thing as well...
I hear and I forget. I see and I remember. I do and I understand. -Confucius
It's Twenty Seven B Stroke Six YIC
cat
Well, his intentions were obviously meaningless, since I can apparently still print out my own boarding passes, legit or not.
It's a shame the TSA people think just like you, if people would quit trying to kill the messengers, we might start seeing something that looked more like security and less like cronies securing contracts.
If I have been able to see further than others, it is because I bought a pair of binoculars.
I didn't actually see the site while it was up, so maybe the guy actually DID this, but.
To avoid being arrested, why not make the boarding pass have VOID VOID VOID printed all over it in such a way as it exposes the problem, but doesn't actually create a valid boarding pass. Then he would have violated no laws, AND exposed the poor security procedure at the same time.
Once the story broke he could create a boarding pass that's given to someone that's authorized to test the fake boarding pass, or others others could independently confirm that the fake pass would work by comparing it to a real boarding pass.
Anyone know if the site did anything to show that the pass was actually invalid?
It seems a bit foolish to put up a working system and not expect the government to go all apeshit.
AccountKiller
Uh, why should he pay a fine? He wasn't attempting to circumvent anything. If he's guilty of anything it's violating the airline's copyright on their logo.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
They're just not going to leave the poor guy alone. He embarrassed them, and they're going to make him pay and pay and pay. It looks a lot like getting on the wrong side of the RIAA. They can be entirely wrong, but it costs you a fortune and year(s) of your life to win, and then they only pay a pittance for all their unwarranted grief at best.
"It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
Does that mean he is grounded for being naughty?
That's unfair. Obviously he did his homework.
"Hannibal's plans never work right. They just work." Amy/A-Team
No, I strongly disagree. The DOJ has already decided he is not a criminal, or at least decided not to procescute. TSA seems to be getting their panties in a wad because he pointed out that the system is flawed, and did it in such a way as to force them to fix it. However, he didn't defraud anyone. He didn't use the tool to fly or to even bypass security. Seems to me, that after 4 years of TSA "Security" (more actually, but lets count from 9/11) stupid holes like that one should have been fixed.
A positive attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
I'll probably be on the no-fly list soon for this, but it's worth pointing out that what Chris did to NWA's boaring passes could be duplicated by just about anyone without special software. While I don't agree with how he exposed the issue (he should have used a fake airline/pass to show the risk), it is worth exposing some very very bad software design. The real criminals here are the coders who developed the boaring pass system for NWA.
The NWA online boarding pass generator uses HTML to render the boarding passes. There's no image processing or anything special involved in changing values on these. Just save it to your desktop, open it in your favorite text editor, and change the text. Bingo. You're flying first class.
There's no reason to believe he even might endanger any airplane that he boards. There's not even the thread of suspicion you'd get from guilt by association. There's no allegation that he has violent tendencies or has threatened violence.
He's there because the no-fly list is a tool for control and coercion at the whim of the authorities without the restraint of statute or jury.
I'm not saying that what the TSA is doing to this guy (or any of us) is right. I think it's blatant sour grapes! But, I don't condone Chris Soghoian's actions either. He should have "done the right thing" and approached the TSA *BEFORE* he made his findings public, and he certainly *NEVER* should have made his web app public. What he did was dumb and irresponsible, period. Was it illegal, ummm, that's up to the courts to decide.
BS.
White hat hackers do things like this pro bono all the time. Perhaps you might recall when a security researcher found a critical flaw in the Cisco OS that could have potentially been exploited to bring down half the internet's backbone infrastructure? Or perhaps you might recall the time that a security pro found a rootkit on a Sony CD? If I went up to you and told you your fly was down, that is a white hat hacker exploit report. If I went up to you and stuck a red hot pocker through your open fly, that is a black hat exploit.
Though, I'm tempted to do that to you anyway, despite the color of hat I wear.
This guy didn't exploit the issue, he immediately made the responsible party aware of the problem. I don't recall him ever flying on a bogus boarding pass. Learn the difference and stop preaching blindly.
Raging in an online forum won't do anything for the world around you. To see change, you must take action.
Avoid Missing Ball for High Score
You seem to be forgetting that that had already been done, up to and including having the information on how to create a fake boarding pass published on a congressman's web site for a year or so prior to his arrest. And yes, there had already be newspaper articles on it, and the TSA was either well aware of it and doing nothing or unaware of it even though it had been reported to them multiple times.
Ok, fine. It was trouble making. But for whom? It didn't lower airport security one iota. Anyone who cared about it already new how to do it. What it did do, though, was make trouble for the fake "security" providers at the TSA, and point out the fact that they are ripping us (the taxpayers) off.
We saw the same sort of misleading argument come up when people started pointing out that US Military personnel were being given ineffective bulletproof vests; somehow the people who were trying to raise awareness of the issue were supposedly "helping the terrorists." Which is just nuts. What they were doing is making things uncomfortable for the crooks selling the defective jackets, and having zero impact on the people wearing them unless and until they could raise enough awareness of the issue to get things changed--in which case their actions would have helped the roops, not hurt them.
--MarkusQ
Really? The story made headlines for a day or two at most. Then nothing. It's very easy to ignore and that's exactly what the government, TSA, and airlines appear to have done. And I for one am glad that was the reaction.
...it's illegal to make the TSA look stupid?
I may add to this that it's citizens' responsibility to keep the country secure - this job shouldn't just be handed out to specialists. I'd not be averse to six months to a year of mandatory military training for all able-bodied citizens between 20 and 40 years old, with those wanting to choose the military or Guard as a career path being allowed to do so. Furthermore, unneeded obstacles should not be put in the way of citizens of good character acquiring guns - basically, a lot more states should be "shall issue" or even "issue by default" like Vermont and Alaska.
-b.
Nor would a suicide bomber have publicized the security hole (if it *was* a security hole, since the only true security is physical security - metal/explosives detectory, x-ray machines, and armed pilots/sky marshals - having to show ID is just something to make the sheeple more comfortable). The suicide bomber would have used the hole if he could have and kept his mouth shut. So, the guy actually did the USA a service by publicizing the hole before it was exploited.
Could it be that the airline management is pissed about possible loss of revenue due to fake boarding passes, so they pressure the TSA into doing something in the name of "security" (the Boogeyman of the Day).
-b.
I agree.
The U.S. is a country of laws: we believe in the rule of law (before anyone comments, this is a standard question covered in Texas police training under the TCLEOSE module "The History of Policing"). Whether it was right or not, it was against the law. It is up to governmental authority whether or not to punish the individual.
They have to weigh the fact that a) it was illegal, it was known by the individual that his actions were illegal, and he intentionally violated the law, and b) his actions publicized a major flaw in national security and personal safety, exemplifying how security could be circumvented even when the flaw was previously known.
In hindsight, what he should have done was got in touch with the entity responsible for security of the airport and presented his evidence. This is analogous to the scientist that invents some "cure", skips FDA approval, injects himself, and it ends up harming himself and others. It also reminds me of the ST:TNG episode Force of Nature.
While what he did was "noble" or "right", he went about it the wrong way.
I don't reply to Anonymous posts; if you have something to say to me, identify yourself or I won't reply.
People have been saying it for years. Last I checked, with E-tickets, you didn't even need a boarding pass---a printout of an email message was enough. (This should be changed if it hasn't already been.) The proper channels have repeatedly ignored complaints about this. As such, this guy should be protected by something akin to whistleblower laws, but I don't think there are any at the federal level except between employers and employees, sadly.
The way I see it is this: the TSA gave the public their new clothes. All this guy did was take the blindfold off so they knew they were naked.
Check out my sci-fi/humor trilogy at PatriotsBooks.
Well, it would be both. Any artwork you create is automatically covered by copyright. Now that you mention it though, fair use is probably a defense - he was constructing criticism which falls under fair use law. Trademark, on the other hand, would likely nail him.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
http://www.wired.com/news/columns/0,72045-0.html
Because they couldn't take down the big fish, that's why.
I found a security hole in a "secrue" system used against pedophiles. I documented the system and submitted it thru channels to the proper authorities. I had to jump up a couple of levels before they could pay attention, but tha tis the way it is done.
What this guy did is not research, but *IS* criminal.
accountability, lol.
1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcf
This is a little bit frightening to me, not because they're prosecuting him and all, because I've come to expect that, but because of where it could lead. We all know that security is never permanent. If there is a way to stop someone from doing something, there is a way around it. What happens when the government realizes this? Some of the cases that get pushed through, like this one (IMHO, anyways) are ridiculous, but what happens when the government realizes that it's just the tip of the iceberg? It sounds kinda funny now, but after seeing the ways in which the government has evolved over the last few years, I would believe anything of them. What happens when they start bringing cases against people who make a proof of concept? Once we know something can be done, the rest is relatively easy, right? So proving that something can be done is like telling the terrorists how to do it, right? Of course, once you think of an idea of how to do something, you've taken your first step on the road to making a proof of concept, am I right? I look at those last few sentences and it makes me shudder, how absurd the logic is, but it's all too familiar to me. It's very like certain justifications to get a hold on certain domestic phone records, or even records from your local library. I've always been of the opinion that America is the best place to live (for me, at least), but if thought processes like this continue to spread and grow, I don't know that America will continue to be a good place to live for very much longer. I like my freedom, and I am not willing to give up personal freedoms in order to lead a life filled with a false sense of security, under a tyrannical government that is unwilling to admit that it can and does make mistakes.
Okay, so it's not research. But he's also not at the center of some vast terrorist conspiracy to forge boarding passes and blow up the US. The trouble he made was not a serious threat to US security, and if it was we are in some deep fucking trouble because it's clear that the gatekeepers are asleep at the switch.
No, he has already been treated to the "troublemaker" gauntlet, had his brush with the government and his future almost turned upside down. He's still a kid, and kids will do things without thinking (yes, you can be 25 and childish - they guy has probably never lived outside of academia). The TSA is now practicing a little mafia style justice for losing face to this guy.
Is it just my observation, or are there way too many stupid people in the world?
Bigoted? Asshole?
Okay, I'll feed the troll. WHY? Are you a muslim? You gonna kill me for suggesting such a thing? You gonna stab me and leave me dead with a note attached? You gonna threaten me and my family with death or dismemberment if I don't convert?
Koran 5:33
The Punishment for those who oppose Allah and his messenger is : Execution or Crucifixion or the cutting off of hands and feet from opposite sides or exile from the land.
Okay, so maybe you aren't a muslim. Do you even know what Muslims teach from the Koran (see above quote). This is but ONE of many such verses, which require DEATH or dismemberment for Apostates and Infidels.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
I've never heard anyone suggest 6-12mo mandatory military training, with only volunteer military enlistment. Like mandatory ROTC. It's a very interesting idea.
There's about 1.2M highschool graduates this year, and supposedly 7.5M US citizens enrolled in the ROTC (though that seems high, and is uncited). It seems that the ROTC is already serving the right scale of enrollees. I'd favor replacing mandatory HS gym classes with ROTC for at least a year or two, required for HS graduation. Perhaps even mandatory service - but what do you do with AWOL HS dropouts, jail them? Force them into the program? In separate units?
The problem I have is that militarizing the youth rebalances America's existing warmonger culture more towards the military mindset. Actual military experience can go a long way to disabusing the notion of blind authority obedience, but does a year of ROTC? Or does it just present the best face of the military: integration, opportunity, discipline, expensive toys, mayhem, fraternity (& sorority), a bad influence on American voters?
I probably totally disagree with you about the necessity of obstacles to citizens getting guns, regardless of their "good character". But we'd probably agree that teaching everyone how to handle a gun would make those who get one for private use a lot more safe. And possibly make criminals expect more of their targets to not only have one, but to be able to use one, and to actually use it in an emergency.
This is a compelling idea. Did you think of it, or did you hear it somewhere? Is anyone else talking about it?
--
make install -not war
was never convicted in criminal court. The IRS got him in tax court for not paying taxes.
So justice had there try. Now its TSA's turn. Next the IRS will look over his finances looking for undeclared paypal donations for his defence, student loan fraud, etc. Next the army will conscript him under some secret law, and send him to Iraq. If they still can't get him there is always the RIAA & MPAA.
If that printout of that email message contains a security code, what is the problem?
I suffer from attention surplus disorder.
Yep. Gave me the willies, too. But that was nothing compared to my shock that the whole country didn't rise up and shout their own horror.
We're surrounded by people who don't learn from history, or from reading at all. Presumably because their lips get too tired.
I'm not a Muslim. I'm not a Catholic. I'm not a Christian. But I'm also not blind. The problem is not with radical MUSLIMS, but radical PEOPLE. And just to add clarity; Exodus 22:20 "He that sacrificeth unto any god, save unto the LORD only, he shall be utterly destroyed." Leviticus 24:16 "And he that blasphemeth the name of the LORD, he shall surely be put to death, and all the congregation shall certainly stone him: as well the stranger, as he that is born in the land, when he blasphemeth the name of the Lord, shall be put to death." Acts 3:23 "And it shall come to pass, that every soul, which will not hear that prophet, shall be destroyed from among the people." Islam isn't the only religion to preach intolerance. Most followers of the Bible would likely argue that only a small radical slice of zealots would actually follow through with these things. I can imagine that the same might be said of followers of Islam and the quote you pulled...
I'd rather be an ignorant moron than an anonymous coward.
All you need is a couple of Christmas presents.
...Rob
The American Dream isn't an SUV and a house in the suburbs; it's Don't Tread On Me.
That's the United States today, unfortunately. If I had the financial resources I'd move to Europe, Russia, Asia, Australia, anywhere other than here. Anything is better than the $@&^ed-up crap our government is getting away with now. They are a bunch of psychopaths that can't stand to have anyone smarter than they are (which is any non-government employee) point out their flaws. I'll be glad when the common people of this once great nation are fed up and take it back. Terrorist attacks on the United States and abroad have brought out the worst in our government . . . so much so that we're hated around the world by everyone not a government scumbag. Losers!
At least with Continental's E-ticket, there's a bar code on the printout. They scan that and check it against your passport before allowing you on the plane. So not only do you need to have the printout, which could be easily faked, you have to have a barcode number that associates with a record in their database which matches your passport, which is a hell of a lot harder. You'd have to have a fake passport as well. Not impossible, but certainly less trivial.
They put the guy who can forge boarding passes on the no-fly list? does anybody else find that kinda... i don't know... retarded?
How about giving him a call and talking to him about this situation...
James A. Roberts
(317) 390-6916
1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcf
True, but a suicide bomber could have exploited the security hole and software that the guy made public. That is where I see his actions as being a problem.
I was reading Feyman's memoirs just before I read this, so please excuse it did affected me a little. What may be perfectly easy to understand to a game theorist and can be summed up in one dilemma can easily take a few dozen pages to describe to the uninitiated. Similarly there are years of courses to understand the basic foundation upon which theoretical mathematicians don't even have to think of consciously. And finally what to a hacker may be plain as day may be completely counterintuitive to the way the rest of the world thinks. (In this case, any output can be converted to input, and fed back out again.)
Further, because the concept is known by a vendor as a "possible" problem, doesn't mean they will address it. By creating an interface for even those unfamiliar with the theory, the concept became a reality. On top of which, there is innate skepticism from the part of the vendor (for the most part) that their product could be broken in such a "trivial" manner; or put another way big head smackers sometimes take simple examples.
While I know it is a neologism, that word is possibly one of the more annoying words I know. It's up there with 'guesstimate' and 'edutainment/infotainment'. We already have perfectly good expressions that aren't inane.
Sorry, just felt the need to say that, no offence to the good Doc.
Are you a grammar Nazi? I'm trying to improve my English; please correct my errors!
This is a compelling idea. Did you think of it, or did you hear it somewhere? Is anyone else talking about it?
Yeah, Switzerland has a policy like this in place already.
I guess my question is how the "differently-abled" would serve out their requirement. And how low would that threshold for "differently-abled" be?
For example, one of my friends in high school was legally blind. He could march in marching band, and could drive a car (passably), but I would never want to have him behind the trigger on a gun. Or, let's say a teenager who is obese, and unable to meet a fitness requirement, how do they serve? Or what about the "If I had a gun, I'd get all Columbine up in this place," kinds of kids? Or the opposite-side pacifist kids? (The link from Wikipedia to the Swiss Armed Forces answers a few of those questions, but would they be applicable to the US?)
"What do you think?" "I think 'What, do you think?!'"
Avoid Missing Ball for High Score
Not if there was good physical security, which is the only kind that matters. Remember that most suicide bombers only commit one crime during their lives, so there isn't any history of suspicious behavior.
-b.
I think it's more then permission, the difference in a black hat and a white hat comes down to real intentions. Saying you're trying to inform people means bullshit because it's just that. If you want to inform people, inform people of the problem as well as the airline, meantion you have a working prototype but that's it. Don't start handing it out blindly to random people.
Just because you have a new technology doesn't mean make it available to everyone with out at least trying to inform those who should be informed. that means TSA, DHS or what ever group. If you did this for better security work WITH them. Acting like they should automatically know what you've done is just stupid, what ever his purpose it wasn't done the correct way, which means in the end it wasn't done for the right reason. If you honestly think it's something to expose, start by telling the company and if they insist it's unimportant that's when you announce it to the world. If it is still ignored then you should consider sharing instructions/devices/ or what ever with the world.
"Most followers of the Bible would likely argue that only a small radical slice of zealots would actually follow through with these things."
Uh huh. Not blind? But unable to see the riots over a FREAKING CARTOON! When was the last time you saw a Riot in Texas because someone "insulted" Jesus? When was the last time you saw a riot in Israel when someone insulted the Jewish G-D?
Uh huh. That's what I thought. Are you willing to die for your beliefs? You willing to kill to defend them? The war isn't over Terrorism, it is over Radical Islam*. They have proven their willingness to die and kill for it, they teach it, the live it. You willing to do the same to prevent it? Now, isn't that radical thought?
*Possible Redundancy Error, please verify. Y / N ?
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
Does NOBODY see the irony here?
The government is putting him on the No-Fly list, BECAUSE HE RELEASED A PROGRAM THAT ALLOWS PEOPLE TO CIRCUMVENT THE NO-FLY LIST.
So this helps, how?
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
It's etymologically correct (sim + cure + ity), sounds like it means, is easy to spell, and has few syllables/letters.
Which word do you prefer to "simcurity"?
FWIW, I like guesstimate and edutainment/infotainment. I also like "infotainvert". Which perfectly good expressions that aren't inane mean exactly what those words say?
--
make install -not war
> *Possible Redundancy Error, please verify. Y / N ?
* Possible it wasn't funny the first time, mod down again? Y / N ?
My other car is first.
What he did was illegal but it was not wrong. While this is a point of semantics, it is a very important one.
This sig intentionally left blank.
The military already has ways to use disabled people. Because they are "differently abled", though not necessarily able in a way that is more able than those without any specific disability.
The US deploys troops abroad in a 6:1 ratio of "support" (everyone else) to "warfighter", at best. At worst, it's probably 10-20:1, like in Germany or Japan (or Canada, where it might be 50:1 or worse). Domestic deployment is much more "topheavy". Consider that 140K Iraq troops are probably 6-10:1, including National Guard (which has a much stronger warfighter ratio). That 100K troops, of whom maybe 20K are non-Guard warfighters, is draining the US warfighter pool to the breaking point (requiring all those Guard, and near-draft retention rules). Even though the total US military personnel is about 1 million people. That means that 2% of the military is Iraq warfighters, maybe 4-8% is global warfighters. Totally imprecise numbers, but those are the relative scales.
That leaves at least 900K people who talk on the phone, use the Internet, drive around in shipping, cook food, repair machines. But mostly bureaucrats who go to meetings. That is apparently necessary to the way our military works (though a separate policy I favor would reduce all of that, especially abroad). I'm sure that the disabled would be productively used in that huge bureaucracy and operations dump. There's probably even a case to make that people paid disability welfare could contribute some of their abilities to the military, saving money. In the "mandatory ROTC", the disabled would just get trained for those extra jobs that do not demand strong health/fitness. While socializing them, training (even forcing) them to work, and probably making them a lot more fit than those sadistic yet pointless gym classes.
"Misfits" like homicidal maniacs and pacifists (and just nonconformists all between) are a different story. There are lots of jobs as I just described that they could do without being near anything (or anyone) that goes "BANG". Many of those people, especially the homicidal maniacs, probably should go through some socializing program that helps them get over that just by seeing what it's really like to kill and die, watching those suited to do so. The military has a long history of figuring out which people are too dangerous to assign as killers, though it also gives us someplace "useful" to put those violent people.
Pacifists are another story. Pacifism is too easy a copout - and I'm a pacifist. "Conscientious objectors" are relatively easy: put them in jail, minimum security, with alternate training available, for the duration of their service. With only other COs, most likely, if just for their own protection. No punishment, just call them on their conscientious committment not to kill. To distinguish them from the rest of us less "moral" people who are committed mainly to "not dying", with "not killing" in second place. Real pacifists can't handle being part of a war machine any more than your blind friend can drive a car, so we have to put them somewhere that makes the same time and freedom sacrifices as the rest of us.
But there's a lot more national service than just the military. The National Guard is primarily for nonmilitary disasters. With Climate Change, we have a lot more work coming down the pipes. There's border control, which can be treated more as legitimate domestic labor protection than as racism, and is popular in pockets across the political spectrum. A national "tutor corps" would really improve education, the best national security. And would probably be popular with a disproportionate amount of people too smart to be willing to kill or die for our country, and are looking at careers that allow them to avoid living for our country, too. There's all kinds of community service that's too good for petty criminals to work. And of course the military itself has plenty of work demand indistinguishable from civilian work/study programs.
Maybe we just make the nonmilitary service last longer, like 1
--
make install -not war
Shame on us! Shame!!
I'm ashamed to live in a country where so many idiots are in positions of authority.
(que up the "then leave" remarks in 3... 2... 1...)
--Phillip
Can you say BIRTH TAX
That would be an electronic boarding pass if it ha a bar code.... Maybe they've changed this since I last flew an airline that did this. Not sure. I just remember being able to get a boarding pass at the gate if you had no luggage. I'm pretty sure that was after 9/11/01, but I may be wrong.
Again, none of the things being discussed would get you on a plane, just into the terminal itself. The point is that requiring a boarding pass to access the terminal is basically a no-op security-wise. It neither adds to nor detracts from security. Similarly, requiring a photo ID effectively becomes a no-op as a result of checking it against a printed customer name rather than the ID on a computer screen after scanning the barcode on the boarding pass.
Check out my sci-fi/humor trilogy at PatriotsBooks.
That the security code is just a string of six letters and numbers, and that I've never seen the people at the checkpoint check that code against anything.
Check out my sci-fi/humor trilogy at PatriotsBooks.
Moderation -1
70% Overrated
30% Insightful
TrollMods can't stand hearing that Bush is a terrorist incompetent. So they will anonymously suppress any mention, rather than openly disagree.
Is it any wonder that the president they worship created the TSA that is suppressing Soghoian? Why do they hate America?
--
make install -not war
I might have come across a little harsh, sorry for that :)
Anyway, I think it's more of a personal aversion. To me those terms seem constructed (well, duh) and unnatural, and I find them unaesthetic and inelegant. For instance, I prefer 'simulated security', which consists of well-established words with clearly defined meanings, one of more qualities of which 'simcurity' apparently lacks since you felt the need to explain the term in your post.
If you use the term 'guesstimate' you're very imprecise. I have no idea how much confidence I should put in your answer. How did you arrive at your conclusion? Either you're guessing, or you're making an estimate based on interpretation of data in some manner, which one is it? In my opinion there is no 'in between' for which 'guesstimate' is an adequate term. It might be an estimate with incomplete data, but still an estimate. Or a guess. Whichever.
Hmmmm, 'infotainvert'? I believe you're pulling my leg, sir. A Google search yields three hits, two of which points to the same Slashdot article where it was used by you, the third to a literally contentless site at www.infotainvert.com. My first impression is that it is constructed to ridicule exactly the contrived terms of which we are speaking.
Besides, you will note that English is not my first language. In Norwegian, which IS my first language, people will sometimes try to bring similar terms into everyday use. They mostly have little luck for the same reasons I stated above. Maybe we just look at languages in a different manner?
Let's just agree to disagree, shall we?
BTW, otherwise your post was an interesting one. Going to bed now...
Are you a grammar Nazi? I'm trying to improve my English; please correct my errors!
Ah, you're Norwegian. I couldn't tell at first, because your English is so impeccable. Though your extreme politeness in legitimately complaining seemed a little weird - though we do have plenty of Scandinavians in the Upper Midwest :).
;). Americans, especially here in NYC, prefer the fastest combination of words to express an idea. That's why we call it "NYC", instead of "New York City", because it saves a syllable, and a lot of typing (and modulating the shift key).
But I can understand your aversion to American neologisms, at least more than we Americans aver (pun to test your bilinguality
Personally, I think that value on abbreviation comes from our German immigrants towards the middle of the end of the 1800s. Many of whom became publishers, some of whom still dominate publishing, like at the NYT (NY Times) and other major periodicals. German efficiency, along with "neologisms" like the common German technique of combining words into very long ones, seems consistent with the abbreviations favored by New Yorkers, and the country we intellectually colonized here. Maybe Germans don't neologize in Europe (or verb nouns, as I just did). I don't really know where those long combinations of German words come from, or how they're "authorized", if at all. But in America, especially perhaps in old cities once English colonies, we like to have our own way with the Queen's English.
I explained my "simcurity" neologism precisely because it is so new. English etymology is mostly "simple when you know how", more a mnemonic technique than an actual generative system, except in science. So I explain it for a while, until it's conventional. Like the process by which hyphenation disappears as the neologism gains currency.
It does seem that we look at languages differently. I don't think our disagreement is due to your use of English as your second language. Because my second language is Spanish, in which I neologize and speak circuitously with my rusty facility and limited vocabulary. Maybe you're just a more precise speaker than am I, because you learned English from rigorous academics, while I learned to speak Spanish on the streets (after lots of ineffective academic training). I certainly love to neologize, and practice the art whenever I can get away with it.
In any event, this has been a most agreeable disagreement. TTYL.
--
make install -not war
Victimless crime
Victimless crime
Victimless crime
How do you avoid corruption in a democratic state, if the people themselves aren't able to audit the actions of the state? By asking permission from the corrupt?
That's what this is. A bunch of people taking paychecks from the people, while not actually doing their jobs, and then when someone blows the whistle, it is the whistleblower who gets punished. That sounds exactly like the situation in China, where---*surprise*---corruption is rampant.
http://outcampaign.org/
We now have a better understanding of the risks of airline travel; We have less of a false sense of security.
http://outcampaign.org/
Oh, and what idiot moderators moderated my original post as flamebait? I hope you get meta-moderated.
First of all, I think the rule of law is extremely important. The laws (at least in theory) represent the rules agreed to by the people and until the people choose to rewrite them, everyone should abide by them. This allows citizens and foreigners stability (as opposed to anarchy) while giving them control at the same time (as opposed to a dictatorship).
If the laws offend some citizens, they must pursue the legal process for changing them, but not violate them. I think most of the posts today complain that the laws aren't fair, etc. There are ways of having them rewritten. I'd like to see them rewritten. This farce where a well-meaning individual must risk their career to make a difference in the security practices of the TSA could result in a new bill that more clearly defines such things (cited in the TSA letter) as:
To see changes though, this would have to motivate the people. So far, the voters of the USA have chosen to leave things alone. Apparently, the TSA is doing just fine according to most Americans.
Further, I think the case can be made that Chris is innocent of the charges.
If a system fails to control access when its encryption becomes public knowledge, it is not a secure system, in the same way that DRM can never stop piracy. This is immaterial to the case, however, since Chris only provided a web page to generate encrypted data, and did not reveal the key.
I can see your point. However, what Chris has done is akin to publishing a Star Trek replicator's database entry for borg implants. He knows they are dangerous. He also knows that others (like Senator Schumer) have previously published the same information. If someone chooses to load the database entry into their replicator (they would have to intenti
Was it illegal? Obviously.
Was it wrong? Elsewhere in this thread I've already said why it was, but basically: 1) He risked causing an inconvenience to travelers if the governmental response was to reject home-printed boarding passes. 2) He risked increasing security checkpoint delay times because the security people would have to scan the boarding passes to make sure they were real. 3) He didn't publicize anything that anyone with an ounce of computer skills didn't already know.
So, basically, his exercise was pointless, accomplished nothing, and had the possibility of inconveniencing a lot of people. That's "wrong" as far as I'm concerned. If you're going to inconvenience people, there damn well be a better reason than making some headlines for your 15 minutes. And if you're going to make a public website that allows people to print bogus boarding passes in this political/security environment, forgive me if I don't really care if you later complain that you've been added to the no-fly list.
http://en.wikipedia.org/wiki/Christian_Identity As I stated, there are religious zealots in every religion. Thanks for proving my point.
I'd rather be an ignorant moron than an anonymous coward.
You're wrong :) I've tried this a few times since 9/11 at various airports since I usually just have a carry-on.
I did find it interesting that Alaska Airlines still has self-service kiosks at some airports (San Diego, for instance) in the gate area. When asked about that, they told me it would be too expensive to remove them in hopes they can use them again sometime, as well as the occasional traveler connecting through a non-partner airline could use it without going through security.
This comment does not necessarily represent the views and opinions of the author.
Or maybe he can dig a tunnel to Mexico. He can't use an existing Mexican tunnel, due to all the oncoming traffic...
Excuse me, but please get off my Pennisetum Clandestinum, eh!
One of my favorite Archie-isms.
My mom says I'm cool.
Seems to me this is all not about security. If it were, they would welcome the guy. This is really about dominating the population. ''You have an inconvenient opinion? Sorry, our software says you are a potential security risk. No airtravel for you....''
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Don't fuck with us, because we'll fuck with you.
It's disappointing how far things have gone off-track.
--
Don't like it? Respond with words, not karma.
The TSA guy aren't idiot. They do not want to investigate the kid to make the problem go away, they want to send a STRONG message to other kid , or heck, security researcher : "do the same stunt and we will make sure you will sooooo buried in shit that you can say goodbye to your carrier, flying/travel freedom, and peace of mind". In other word they are trying to implement self-censorship through fear.
C. Sagan : A demon haunted world:
http://www.amazon.com/gp/product/0345409469/
visit randi.org
It goes without saying that for anyone gullible enough to think that they can get away with doing something like this under their real identity... (fill in the blanks)
This is the one time where I would categorically have advised to consult with an attorney beforehand, so that he could have understood the type of trouble he might be in for pointing this out the way he did, and releasing the software in the wild.
It really doesn't seem very smart to go about it headfirst like this, and he is paying for it now.
Maybe we need 'whistle-blower lawyers', or at least courses in responsible and perfectly safe whistle-blowing?
There has to be a better way to force the TSA to fix their flaws.
Z.
<conspearacy theory>
I know this is an extreme comparison, but how'd that sort of thing work out for Karen Silkwood? She went old-school public and got killed! Perhaps the immediate notoriety offered by the web is "safer".
</conspearacy theory>
It must have been something you assimilated. . . .
Well at least they are doing something proactive to catch kids wanting to see mom/dad at the gate.
I always thought they were strictly reactionary and look for things that have already happened?
When the only tool you have is a hammer, every problem looks like a nail
Certanly the act of embarassing the emperor has to be punished..
FRA: STFU GTFO
Noo. Were he a criminal, he might have sold the technology to Hizbollah or somesuch without alerting anyone.
CI is a FRINGE group, and not taught in "churches", at least as a matter of course.
However, Radical Islam, is standard fair, and taught all over the place. I can name several prominent Muslim Clerics just off the top of my head. I cannot do the same for CI. Besides, when was the last time a CIer hijacked a plane, blew up a building, set an IED, destroyed a Mosque, Church or Synagogue?
The problem here, is that you want to marginalize Radical Islam and make it seem like it is just a few wackos, when the reality is, radical = mainstream.
Further, most "christians" are willing and do denounce violence from such groups as CIers. I have yet to see such boldness from the Muslim communities, except in VERY RARE CASES, and then, those people usually end up hiding for the rest of their lives. Do you remember Salman Rushdie? All he did was write a FICTIONAL NOVEL.
Now compare to the violence associated with "The Last Temptation of Christ". Right, what violence. There wasn't any.
While you may like to try to compare the extremes, but there is no comparison, because nominal christianity and judiasm is not "extreme", whereas nominal Islam in its current state IS.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
Ireland was less about religion than it was about identity and nationalism. Zealots didn't kill greeks, they killed "apostate" Jews (Messianics). It was later turned around into state sponsored terrorism when Rome became "christianized" in around AD 324. After the conversion of the pagans into the Roman Sun God turned Christianity, the Jews were highly persecuted by the state.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
As someone living in the Southern United States, the so-called 'Bible Belt', I beg to differ. Good old Southern racism is, sadly, very much alive down here. It's passed down from generation to generation like a mutant gene, and it gets its roots from the 'fringe' religious ramblings of Christian Identity.
However, Radical Islam, is standard fair, and taught all over the place. I can name several prominent Muslim Clerics just off the top of my head. I cannot do the same for CI. Besides, when was the last time a CIer hijacked a plane, blew up a building, set an IED, destroyed a Mosque, Church or Synagogue?
Why did Buford O. Furrow, Jr. attack a Jewish Community center in 1999? Christian Identity.
Why did Benjamin Smith go on a minority-targetted sooting spree in 1999? Christian Identity.
Why did two members of the Creativity Movement attempt to blow up Black and Jewish landmarks in 2002? Perhaps you're starting to get the picture.
It's a very parallel ideology. In fact, the head of the Ku Klux Clan, Posse Comitatus, and the Aryan Nation/Aryan Brotherhood, August Kreis, has recently reached out to al Qaeda in an attempt to form an alliance.
The problem here, is that you want to marginalize Radical Islam and make it seem like it is just a few wackos, when the reality is, radical = mainstream.
Please don't assume to know what I want, because I realize Radical Islam is more than a 'few wackos', just like EVERY religion has more than its share of 'wackos'. I'm just not getting my world-view spoon fed to me by my own religious leaders, and can see that the problem is not with any one religion in particular, but with any movement, religious or otherwise, that sponsors hate.
Further, most "christians" are willing and do denounce violence from such groups as CIers. I have yet to see such boldness from the Muslim communities, except in VERY RARE CASES, and then, those people usually end up hiding for the rest of their lives. Do you remember Salman Rushdie? All he did was write a FICTIONAL NOVEL.
Yes, most Christians do denounce the violence. Out of one side of their mouth, that is. The other is normally too busy spouting out propaganda against any religion, lifestyle, or medical procedure that they disagree with.
Plus, it's a lot easier to play the 'concerned citizen' and decry the violence while sitting in a comfortable position within the highest populated religion in the U.S. Try to advance non-Christian views in a predominantly Christian culture and see how far that gets you. Probably about as far as advancing non-Islamic views in a predominantly Muslim culture.
Now compare to the violence associated with "The Last Temptation of Christ". Right, what violence. There wasn't any.
Oh? Tell that to the people injured by the molotov cocktails tossed into the movie theater by Catholic fundementalists. Scorsese himself stated that for over a year, death threats had him so scared he couldn't open his own mail.
While you may like to try to compare the extremes, but there is no comparison, because nominal christianity and judiasm is not "extreme", whereas nominal Islam in its current state IS.
Nominal Christianity, Judaism, or Islam are not what I was referring to. I was just making a point that, like you said, there are 'wackos' in each and every one of them. And right now, with all the focus on the scary Muslim wackos, it's the rest that'll sneak up on you if you don't pay attention. While everyone keeps on worrying about all those terrorist attacks, civil liberties are being taken, scientific advancement is being squelched, and the gap between Church and State is shrinking at an alarming pace.
As I stated, extremists are the issue. On that I think you agree. You state that the Islamic extremists are the norm, and according to population census when it comes to religious preference, that's utterly false. The radicals are driven by politics, using their religion as a means to an end, as a way to incite the sheeple, as a flag around which their flock can gather.
Just like Christianity...
I'd rather be an ignorant moron than an anonymous coward.
I didn't say they fixed it, I said he did it in a way that will force them to fix it.
When the media coverage of TSA goofs occur, they have to respond with a fix. Granted it's another media patch, and yes, you are quite right that SOMEONE doesn't want real security, but that's the Airlines that don't want to do the things like foot a security officer on each flight, add the bulletproof doors, and so forth.
Where "WE" don't want real security, is that "WE" don't want to pay for the upgrades needed. It's money, it's allways about the money here in the US.
A positive attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.