Experts Warn About Security Flaws In Airline Boarding Passes
concealment writes in with a story about a newly found security issue with the bar codes on boarding passes. "Flight enthusiasts, however, recently discovered that the bar codes printed on all boarding passes — which travelers can obtain up to 24 hours before arriving at the airport — contain information on which security screening a passenger is set to receive.
Details about the vulnerability spread after John Butler, an aviation blogger, drew attention to it in a post late last week. Butler said he had discovered that information stored within the bar codes of boarding passes is unencrypted, and so can be read in advance by technically minded travelers.
Simply by using a smartphone or similar device to check the bar code, travelers could determine whether they would pass through full security screening, or the expedited process."
Has anyone seen a case where a passenger is waved through security? Each time I go through, everyone in line for screening goes through the same process (then again, I am completely average and might not have seen advanced/reduced security for anyone except pilots).
How possible would it be to do very subtle Photoshop (or the GIMP) changes to ensure someone goes through the expedited process? Heck, terrorism aside, I'D do it just to avoid the cancer machines.
http://puckinflight.wordpress.com/2012/10/19/security-flaws-in-the-tsa-pre-check-system-and-the-boarding-pass-check-system/
This will be buried.... people will forget... and the TSA security theater will continue or even get stepped up to counter this little mishap.
What flaw are we talking about?
Obviously it is a feature for "technically minded travelers". Ist'n it?
--whacky
Indeed. It's pretty hard to say "random search" if the guy's badge code has a special section selecting him for "extra screening"
This sounds more like a special code that exempts people from a full search, but I wonder what other codes there might be.
Wonder how long till John Butler gets arrested for sharing this info. National security and all that.
Be seeing you...
I was randomly selected for the SSS tag on my boarding pass. It was great. We were in Phoenix and the regular screening line was massive, at least an hour long. The "special" line had about 10 people in it. We zipped right through. Would have needed to skip lunch if we were in the regular line.
We noticed the letters on the pass too before entering the lines so I guess they have not really cared about this "issue" in the past.
I think the special screening is more of a quality control measure on the regular screening guys than it's a real boost to security.
this only applies to the TSA who actually scan and pass people around the security scanning solution based on the results of what is in the barcode. in europe, you always have to go through scanning process, regardless of what your 2D barcode has encoded within in. all the TSA is doing here, is opening up a chance for terrorists based on local soil to get through the security scanning process simpler. the challenge is that the USA has the most number of travelers through the airline system than anywhere else in the world; doing extensive security checks does choke the system - so, they need to try and filter out the more frequent/trusted flyers, the net result is they are wasting time screening some since they done screen everyone.
Not only could you photoshop the barcode, but hell, you could photoshop the name, the destination, the flight number, pretty much anything you wanted... The brainless goons at the security checkpoint wouldn't know the difference. (They don't scan tickets or anything).
In my experience (working for a contractor for a major US airline), you could even use a photoshopped (printed at home) boarding pass to get on the plane. When they scan it at the gate and the computer beeps saying "no such thing", generally the non-english-speaking gate agent will just scan it a few more times, give up, and let the person on the plane. When the passenger count from the computer later doesn't match up to the number of people on the plane, they'll just "go with what's on the plane" in the interest of getting the plane out on time. This happens on a DAILY BASIS. "Security" is a joke.
BP data is not meant to be a security things. If they saved CAPS 2 data on it, well *shrug*. Anyway the rule at check in on how to set whether there will be a screening are known. If I recall correctely the code, if you paid with CC, are business traveler or better, have a return ticket, and a miles and more or similar card, given baggage, you have next to no chance beyond random chance, whether if you paid cash, one way, with carry on, belong to the monkey class (M - Eco) , no FT cards, you are bound to be checked 100% of the time. At least it used to be that way, now the rule might be a bit more elaborate but I doubt it changed. Also it used to be you had anyway a 10-20% chance of being selected anyway at the security point, independentely of what the BP said. IMHO it is a non story.
C. Sagan : A demon haunted world:
http://www.amazon.com/gp/product/0345409469/
visit randi.org
including the inability to get non-stop flights for most routes, having to pay to park in a lot that is still a 10 minute ride to the terminal, having to arrive 2 hours early to ensure getting thru security on time to board, having small innocuous items in my pockets stolen by TSA, risking having large innocuous items in my bags stolen by TSA, getting severely overcharged for food at airport terminals, getting X-rayed by someone who is not my doctor or dentist, having to do mini-marathons thru airports to make connecting flights, getting my bags lost, etc. etc. have all combined to cause me to decide to drive everywhere I go. Eventually, the Alcan Highway is going to get photographed up the wazoo, by me, 'cuz I'll drive up and ferry back. But the X-rays were the last straw, that shall not stand. I quit. You can find me on I-10 to Tucson next year, I-74 from Indy to La Crosse, I-64 to St. Louis, etc. etc. Until the unconstitutional TSA activity is removed, I will not choose to fly anywhere I can drive, or boat, or travel by train.
It means "even the Nazis were only half as thorough as us"....
Got them moderator blues I blieve I walk out the do', With these mod-points I been gettin', I 'most never post no mo'
All you have to do is have proper locks and PROPERLY CHECK A FIREARM.
as of that moment your luggage is considered a sealed container and can not be legally opened without you being present. ...)
(please note this does not have to be a working firearm and details may vary with each airline but
Any person using FTFY or editing my postings agrees to a US$50.00 charge