TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

U.S. No Fly list publicly shared on a hacking forum, government investigating

208 点作者 dotty-超过 2 年前

27 条评论

yawboakye超过 2 年前
i was contacted on twitter by the journalist at dailydot who broke the news (<a href="https:&#x2F;&#x2F;twitter.com&#x2F;davidcovucci" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;davidcovucci</a>) because i have java code on github from ~10 years ago that reads a certain ‘nofly.csv’ file (<a href="https:&#x2F;&#x2F;gist.github.com&#x2F;yawboakye&#x2F;3888617" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;yawboakye&#x2F;3888617</a>). the interaction was short and i wondered what he was looking for exactly. well, it was joke code, written as part of introduction to java. all this makes me wonder where ‘super-secret-nuclear-codes.csv’ could get me
评论 #34582500 未加载
hn_throwaway_99超过 2 年前
The way the no fly list was shared, it was absolutely inevitable that this would happen. A much more secure way to handle this:<p>1. Airlines are each given a no fly list that only includes tokens, e.g. each person&#x27;s name hashed with a secret key that is specific to the airline, on a periodic basis.<p>2. When the airline wants to check if a user is on the list, they hit a government-owned service that returns the user&#x27;s token (again, the token will be unique for each airline because each airline gets their own secret key).<p>3. The airline would then check the token against their revoked token list.<p>The benefit of this is:<p>1. The full token list by itself is useless<p>2. Even if the airlines API credentials are stolen, the response from the government-owned service is useless on its own.<p>3. So a bad guy would need to steal the token list AND the API creds to get any value, and even then it would be easy for the government to detect unusual access patterns to their service.<p>Remember back in the late 90s when we all used to store passwords in plain text? Yeah, we know how that turned out, and in this case, storing the list not only in plain text but sharing it to tons of different companies willy nilly is a million times worse if you expect it to stay secret.
评论 #34585040 未加载
评论 #34586232 未加载
评论 #34591183 未加载
评论 #34585848 未加载
metalcrow超过 2 年前
Link to the actual forum, since it&#x27;s not provided for some reason: <a href="https:&#x2F;&#x2F;breached.vc&#x2F;Thread-TSA-NoFly-List-Database-Leaked-Download" rel="nofollow">https:&#x2F;&#x2F;breached.vc&#x2F;Thread-TSA-NoFly-List-Database-Leaked-Do...</a>
评论 #34584236 未加载
评论 #34582573 未加载
评论 #34586340 未加载
评论 #34584784 未加载
评论 #34584357 未加载
评论 #34584022 未加载
评论 #34584336 未加载
评论 #34586214 未加载
capableweb超过 2 年前
Seems there is a blog post authored by the same person credited in the dump (&quot;maia arson crimew&quot;) describing how the data was acquired here: <a href="https:&#x2F;&#x2F;maia.crimew.gay&#x2F;posts&#x2F;how-to-hack-an-airline&#x2F;" rel="nofollow">https:&#x2F;&#x2F;maia.crimew.gay&#x2F;posts&#x2F;how-to-hack-an-airline&#x2F;</a> (&quot;how to completely own an airline in 3 easy steps and grab the TSA nofly list along the way&quot;)<p>Discussed 10 days ago on HN (1024 points | 642 comments): <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34446673" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34446673</a>
jeffwask超过 2 年前
This is one of those terrifying security and operational scenarios. Sure the TSA can say nothing on our end was compromised but if the data is readily accessible to download and accessed by every mom and pop carrier with a 3 person IT staff that can barely keep the lights on is anything actually secure?
评论 #34584123 未加载
BXLE_1-1-BitIs1超过 2 年前
Including the birthdate would be an improvement. Here in Canada, there&#x27;s babies that get put through enhanced screening for having a flagged name, but there&#x27;s an IT contract out there for many millions to provide something like redress numbers.<p>ChatGpt could likely generate the SQL for well under a million.
评论 #34584766 未加载
aestetix超过 2 年前
I hope the list is made public soon. The TSA needs to be abolished.
评论 #34582417 未加载
评论 #34585047 未加载
评论 #34584977 未加载
评论 #34584078 未加载
sschueller超过 2 年前
What security benefit is there for this list being secret? Sure privacy may be an issue but I should have the right to know if I am on it as I see absolutely not benefit if this list being secret other than the government having another reason to put people in jail.<p>Also if you know you are on it you can save the airlines and everyone else a lot of trouble by not trying to fly in the first place.<p>Does the list even state why you are on it?
评论 #34584857 未加载
评论 #34584618 未加载
gggggg5超过 2 年前
My comment linking to the file seems to have been quietly censored by dang or some other moderator. Not [flagged], just [dead].<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34583299" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34583299</a><p>Linking to this file does not seem to violate any documented HN rules, and download links charging money for the file were allowed to stay up.
评论 #34604257 未加载
xwdv超过 2 年前
Let me tell you about the No-Rent list. Oh yes, if you fuck up a rental car or boat or do any kind of chargebacks for the rental, you will be immediately and automatically added to the No-Rent list for that company. Sometimes these lists can be distributed to central repositories where other rental companies can choose to follow the suggestions and not rent a car to you due to your status as high risk. One of my earliest jobs involved working on a system with such a list. I’ve had quite a bit of experience in engineering solutions to keep people in check.<p>I suspect there might be something for real estate, but more fragmented. You could end up on a no-rental list and be banned from renting property. I am certain Airbnb has such a list as well.
评论 #34583302 未加载
photonbucket超过 2 年前
How does the no-fly list work in practice? Are they just told &#x27;no, go away&#x27; when they try to board a plane, or are they arrested?
评论 #34582229 未加载
评论 #34582158 未加载
评论 #34582029 未加载
评论 #34582098 未加载
评论 #34584076 未加载
评论 #34581954 未加载
评论 #34581950 未加载
dotty-超过 2 年前
Discussion for original blog post detailing how the leak occurred: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34446673" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34446673</a>
scohesc超过 2 年前
Too bad there isn&#x27;t a &quot;reason&quot; column showing even a summary of why they ended up on the no-fly list - probably because the reason is too sensitive for the people who regularly access the list to see.<p>&quot;Matters of National Security&quot; and all that jazz.
评论 #34582540 未加载
评论 #34582761 未加载
评论 #34584168 未加载
skywhopper超过 2 年前
I&#x27;m very curious about this list and whether I&#x27;m on it. I have an extremely common Anglo-American first+last name and there was a period of years when I would regularly get my boarding pass stamped &quot;SSSS&quot; and pulled aside for the secondary screening almost every time I flew, which at the time was 5-6 times a year or more.<p>Now, my name is truly so common that I have convinced myself there was something more than just that name triggering the SSSS designation. Otherwise, most major airports would have been patting down someone with my name multiple times a day. I suppose that&#x27;s possible, but if so it would really damn the value of this sort of list. The extra screening did seem to depend on which airline and which airports I was using, so maybe there was something else going on. Or maybe some dude with my name just crossed some line he shouldn&#x27;t have and me and everyone else with that name paid the price for a few years.
评论 #34584924 未加载
stackedinserter超过 2 年前
List like these must be publicly available to anyone, like credit history&#x2F;score. Also, there must some justice process for getting in and out of this list.<p>I still don&#x27;t understand how societies accepted no-fly list, civil forfeiture, de-banking, de-platforming people and other clearly totalitarian practices in or &quot;democratic&quot; and &quot;free&quot; countries.
评论 #34583193 未加载
评论 #34581767 未加载
评论 #34582507 未加载
评论 #34581938 未加载
评论 #34583506 未加载
评论 #34583677 未加载
评论 #34583548 未加载
评论 #34583660 未加载
评论 #34582301 未加载
评论 #34583739 未加载
评论 #34583884 未加载
评论 #34583431 未加载
评论 #34581805 未加载
评论 #34583127 未加载
评论 #34583477 未加载
评论 #34583833 未加载
评论 #34585218 未加载
freitzkriesler超过 2 年前
If a politician ran on eliminating the nudie TSA scanners and this silly list, I&#x27;d vote for him in a heart beat
kristofferR超过 2 年前
Interestringly the spreadsheet includes the columns SID,CLEARED,LASTNAME FIRSTNAME,MIDDLENAME,TYPE,DOB,POB,CITIZENSHIP,PASSPORT&#x2F;IDNUMBER,MISC, but only LASTNAME, FIRSTNAME, DOB is populated.<p>And there are some guys from 1911 and 1912 there.
shadowgovt超过 2 年前
Our industry is still not, in general, an industry that employs licensed professionals. Subsets of it, to be sure, but there is no such thing as a &quot;computer engineering license&quot; in the same sense as a &quot;civil engineering license,&quot; for example.<p>If there were, using production PII in the test infrastructure would be grounds for license revocation.
quazar超过 2 年前
<a href="https:&#x2F;&#x2F;breached.vc&#x2F;Thread-TSA-NoFly-List-Database-Leaked-Download" rel="nofollow">https:&#x2F;&#x2F;breached.vc&#x2F;Thread-TSA-NoFly-List-Database-Leaked-Do...</a>
boomboomsubban超过 2 年前
I wonder if they got the list from crimew or if they followed the directions on her blog. You&#x27;d hope the offending airline would have fixed the issue over the past few weeks but who knows.
评论 #34583636 未加载
omgomgomgomg超过 2 年前
Oh dear, yes we understand this is the world post 911, but many, many criminals will simply use entirelly fake identities.<p>And the data hygiene and itegrity are horrible,there are dead people on it.
openasocket超过 2 年前
What are the ethics of publishing such a list? The act of doing so exposes people and damages their reputations, and because there isn&#x27;t a just procedure for adding people to that list that damage is likely unfair. It&#x27;s not like this is the registry of sex offenders, where at least there was an actual court case to determine their registry and there are well-defined procedures for removal in case of mistakes or issues. Shouldn&#x27;t we advocate for there to be a fair, just procedure for adding and removing people from the no-fly list before making it public?
评论 #34583941 未加载
评论 #34582629 未加载
评论 #34583936 未加载
评论 #34584067 未加载
LinuxBender超过 2 年前
I&#x27;m honestly surprised it&#x27;s taken this long for one of these lists to be <i>leaked</i>. Many businesses are required to pull this and many other lists into their applications to approve&#x2F;deny people and this is not just airlines. For the longest time these lists were on an unencrypted FTP server with a simple username&#x2F;pw. I only had to deal with this because one of our firewalls did not play well with FTP. I tried to convince them to use HTTPS or SFTP. Hopefully they have at least done that by now.
O__________O超过 2 年前
Assuming this list doesn’t include anyone who’s on the Secondary Security Screening Selection (SSSS) list by default:<p>- <a href="https:&#x2F;&#x2F;wikipedia.org&#x2F;wiki&#x2F;Secondary_Security_Screening_Selection" rel="nofollow">https:&#x2F;&#x2F;wikipedia.org&#x2F;wiki&#x2F;Secondary_Security_Screening_Sele...</a>
评论 #34584291 未加载
bastardoperator超过 2 年前
The names are almost exclusively middle eastern.
评论 #34584639 未加载
ding_dang超过 2 年前
Breached is the new site of the RAID Forum that was taken down a few months ago.
gala8y超过 2 年前
OT: You could write a PhD not leaving their (bleepingcomputer) cookie consent pop-up.