news.volyx.in

Bypassing airport security via SQL injection (ian.sh)

2004 points by iancarroll · 710 days ago · 440 comments on HN

Article summary

Researchers discovered a SQL injection vulnerability in the FlyCASS system, which is used by some airlines to manage access to the Known Crewmember (KCM) and Cockpit Access Security System (CASS) programs. This vulnerability allowed them to add unauthorized users to the system, potentially granting them access to airport security checkpoints and cockpit areas. The researchers reported the issue to the Department of Homeland Security, which initially responded promptly but later stopped communicating and issued incorrect statements about the vulnerability. The issue has since been remediated, but the incident raises concerns about the security of airport systems and the response of authorities to vulnerability reports.

Main themes

  • Airport security
  • SQL injection vulnerability
  • Vulnerability disclosure
  • Government response
  • Airline security protocols

What commenters say

  • The TSA's response to the vulnerability report was inadequate and misleading, downplaying the severity of the issue and failing to provide clear information about the remediation efforts.
  • The discovery of the SQL injection vulnerability highlights the ongoing problem of insecure systems and protocols in the aviation industry, which can have serious consequences for security and safety.
  • The incident demonstrates the importance of responsible vulnerability disclosure and the need for clear guidelines and protocols for reporting and addressing security issues in critical infrastructure.
  • Some commentators argue that the vulnerability was not as severe as claimed, and that the threat model is not as significant as suggested, while others disagree and point out the potential risks of such a vulnerability.
  • The use of exploits to test systems without permission is a risky and potentially illegal activity, and researchers should exercise caution and consider the potential consequences of their actions.
  • The lack of transparency and accountability in the government's response to the vulnerability report is a concern, and raises questions about the effectiveness of current protocols for addressing security issues in the aviation industry.
  • The incident highlights the need for better education and awareness among managers and decision-makers about the importance of security and the potential consequences of vulnerabilities, particularly in critical infrastructure.
  • Some commentators suggest that the vulnerability could have been used to carry out a serious attack, such as hijacking a plane, while others argue that the threat model is not as significant as suggested.