DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech exam­ines the inter­sec­tion of tech­nol­ogy and defense from every angle and pro­vides analy­sis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • 'Canes
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the "Buzz"
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT's Dust
  • Extra! Extra!
  • Eye on China
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar's Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples' Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward'z Wonderz
  • You can run…

Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Homeland Security » The Fake Boarding Pass Saga

The Fake Boarding Pass Saga

boardingpass_veganstraight.jpgLast week Christopher Soghoian, a 24 year-​​old Ph.D. stu­dent in infor­ma­tion secu­rity at Indiana University, whipped together a web­site that allowed any­one to cre­ate a fake Northwest Airlines board­ing pass. He hoped to bring atten­tion to a secu­rity hole that allows any­one, includ­ing some­one on the No-​​Fly list, to enter the secu­rity line with a fake doc­u­ment. Instead he got another kind of atten­tion.
For those unfa­mil­iar with the story, it’s one I’ve been fol­low­ing in my blog and in a proper news story for Wired News since Soghoian told me about his site Wednesday night.
Soghoian, a secu­rity researcher who has done work at Google, Apple and IBM, told me the site’s pur­pose was to demon­strate the futil­ity of the No-​​Fly list:

I want Congress to see how stu­pid the TSA’s watch lists are. Now even the most tech­ni­cally incom­pe­tent user can click and gen­er­ate a board­ing pass. By doing this, I’m hop­ing [Congress] will see how silly the secu­rity rules are. I don’t want bad guys to board air­planes but I don’t think the sys­tem we have right now works and I think it is giv­ing us a false sense of security.

Even with­out his gen­er­a­tor, the No-​​Fly list can be avoided:

If you can pur­chase a ticket over the inter­net with a pre-​​paid debit card and can fly with­out I.D., then for domes­tic flights the No-​​Fly list doesn’t work.

On Friday, Congressman Ed Markey (D-​​Mass) called for the site to be shut down and arrested, and later that day, the FBI shut­tered the site and met with Soghoian. Whatever he said must not have been con­vinc­ing, since the FBI raided his house with a search war­rant signed by a judge at 2 a.m. Saturday morn­ing and seized his com­put­ers, though they didn’t arrest him. Markey then retracted his call for Soghoian’s arrest on Sunday and in fact, sug­gested the gov­ern­ment hire him instead (though Markey called the site a ‘lousy way’ of pub­li­ciz­ing the prob­lem).
Since Sunday, the story has slowed con­sid­er­ably. Soghoian has lawyers now and isn’t talk­ing to reporters, though is occa­sion­ally updat­ing his blog.
Soghoian’s site exploited a well-​​known secu­rity hole, one first pub­li­cized by secu­rity expert Bruce Schneier in 2003, given the full-​​on Slate treat­ment in 2005, and, accord­ing to secu­rity blog­ger Adam Shostack, was explained to high-​​level Homeland Security offi­cials in 2004.
That doesn’t mean all secu­rity researchers applaud Soghoian’s method. Indeed, Avi Rubin, who’s best known for his vot­ing secu­rity work, told Xeni Jardin that his for­mer teach­ing assis­tant should have shown this to the gov­ern­ment pri­vately.
So what’s the upshot? Will the gov­ern­ment ban board­ing passes tick­eted at home? Will they pros­e­cute Soghoian for build­ing this site? Won’t other hack­ers put their own ver­sion online? Will this prompt recon­sid­er­a­tion of the use of noto­ri­ously inef­fec­tive watch lists for domes­tic travel?
The short anwsers, in my opin­ion, are No, No, Maybe but not as many as you’d expect, Definitely Not.
The long answers are here at 27BStroke6, which despite Noah’s dig, is a great name for a blog. (Think Brazil).
– Ryan Singel
Photo: VeganStraightEdge

Share |

October 31st, 2006 | Homeland Security | 220610 Comments »http://defensetech.org/2006/10/31/the-fake-boarding-pass-saga/The+Fake+Boarding+Pass+Saga2006-10-31+23%3A40%3A28christian You can skip to the end and leave a response. Pinging is currently not allowed.

« « WaPo Digs for Bombs | Military Ballots’ Privacy Risks » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Allen Thomson says:
    October 31, 2006 at 10:35 pm

    Extensive evi­dence shows that there is no way to effec­tively point out vul­ner­a­bil­i­ties to cor­po­rate enti­ties. If you try the inter­nal route, it will fail and you’ll get branded a loose can­non. If you try the exter­nal route, it will fail and you’ll be put on the ene­mies list. So do it for what­ever rea­sons you want to, but don’t expect to change the objec­tive sit­u­a­tion, ever.

    Reply
  2. ted says:
    October 31, 2006 at 11:50 pm

    Will they also go after Senator Schumer for somthing sim­i­lar?
    http://www.senate.gov/~schumer/SchumerWebsite/pressroom/press_releases/2005/PR4123.aviationsecurity021305.html

    Reply
  3. john s says:
    November 1, 2006 at 10:37 am

    he should have added void across the board­ing pass

    Reply
  4. Joel Mackey says:
    November 1, 2006 at 8:17 pm

    Lets see, a Democrat has gov­ern­ment agents harass a pri­vate cit­i­zen because he is exer­cis­ing his 1st Amendment rights…and the Republicans are a threat to civil liberties?

    Reply
  5. reefdiver says:
    November 2, 2006 at 10:47 am

    The TSA still screens the indi­vid­u­als and their bags, and the air-​​line checks the ticket on entrance to the plane. The air­line assures all pas­sen­gers who checked bags also board the air­craft. Why worry?
    Right now this fake ticket would be a great way to be to get into to the ter­mi­nal to be with your depart­ing fam­ily or friends while they’re wait­ing to depart. Or you could use this to once again meet them at the gate on arrival. Great idea.

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

    Most Popular Posts
    • What Does this Handle Do?
    • Marines Quiet About Brutal New Weapon
    • Starship Troopers Meets G.I. Joe
    • Dowd's Bogus Grief Deficit
    • Semi-auto Grenade Thrower
    • Adapting Women to Subs
    • Fort Hood Rampage
    • Keep it Simple
    • Mystery Drone Revealed
    • REPLACEMENT ARM, GOOD AS NEW
    Recent Comments
    • Market for Acoustic Defense Systems Heats Up
      These devices vibrate tissue and bone not just...
      WJS
    • Semi-auto Grenade Thrower
      So are you saying the grenade launcher is a hoax or the M-16?...
      WJS
    • Fort Hood Rampage
      Dear Cannon Fodder; Only politically correct patriots should be accepted...
      Zandor
    • Dowd’s Bogus Grief Deficit
      LOL Still all this pissing an moaning about the editorial...
      Philo
    • Fort Hood Rampage
      I'd say go read some history on fascist ideology and then compare that...
      Philo
    • Fort Hood Rampage
      Islame isn't a race, genius……
      Philo
    • Semi-auto Grenade Thrower
      I sure as hell don't need to have someone take pictures of me...
      Zandor
    • Fort Hood Rampage
      "Now please tell me where in the Bible Jesus or his disciples...
      DualityOfMan
    • Fort Hood Rampage
      No, I am not a muslim. And no, the Koran does not say anything about...
      DualityOfMan
    • Fort Hood Rampage
      You aren't. You're just annoying. Like a paper cut between...
      bdwilcox
    Recent Articles
    • Semi-​​auto Grenade Thrower
    • Market for Acoustic Defense Systems Heats Up
    • Fort Hood Rampage
    • Keep it Simple
    • Airbag Defense
    • Dowd’s Bogus Grief Deficit
    • Did Someone Move the Furniture Around?
    • Lockheed Says Sbirs Still on Track For 2010
    • What Does this Handle Do?
    • Adapting Women to Subs
  • Channels: Military.com | Military Benefits | Military News | Off Duty | Join the Military | Military Education | Veteran Jobs | Military Money | Military Deals | Military Family | Military Community
  • Military.com Network: Military.com | MilBlogging | Defense Tech | DoD Buzz | SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps | Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program | Monster Network | Help | Feedback | Privacy Policy | User Agreement | © 2009 Military Advantage