TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

United declares 4-digit pin login and lack of SSL “functioning as designed”

33 pointsby sethvargoalmost 10 years ago

5 comments

curryhowardalmost 10 years ago
&gt; That means the attack surface for accessing someone&#x27;s account is NP hard, but N is always equal to 4.<p>FYI, the &quot;N&quot; in &quot;NP hard&quot; is not a number. It stands for nondeterministic. The mention of &quot;NP hard&quot; in the first place just seems...unnecessary.
评论 #9836382 未加载
评论 #9836405 未加载
评论 #9836714 未加载
评论 #9836669 未加载
eastbayjakealmost 10 years ago
It&#x27;s not a bug <i>for the purposes of a bug bounty program</i> because logging in with a 4-digit pin is the actual design, not an unintended flaw in implementation
akerl_almost 10 years ago
Title seems quite linkbaity. In a 4digit PIN-based system, being able to log in with a 4 digit PIN isn&#x27;t a vuln, it&#x27;s how the system works.<p>They even state up-front that improvements to the system are in the works.
评论 #9836772 未加载
deftnerdalmost 10 years ago
Also, when you factor in the human tendency to pick very easily guessed PIN codes, it&#x27;s laughably easy. [1] 11% are &quot;1234&quot;<p>Also, when you log into the United website, you can transfer airline miles. True, once someone complains about their miles disappearing, United might pull them back and ban the receiving account, but it might take a while.<p>It would be trivially easy to steal lots of airline miles into one hacked account and then sell them onto other people on the open market. When United takes them back, the buyers will be without recourse.<p>[1] <a href="http:&#x2F;&#x2F;www.datagenetics.com&#x2F;blog&#x2F;september32012&#x2F;index.html" rel="nofollow">http:&#x2F;&#x2F;www.datagenetics.com&#x2F;blog&#x2F;september32012&#x2F;index.html</a>
评论 #9836416 未加载
NeutronBoyalmost 10 years ago
Well, is that how it&#x27;s supposed to be functioning?<p>The tweet says it&#x27;s a security vulnerability, their response says it&#x27;s functioning as designed. Not mutually exclusive.