Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from vnunet.com



Other blogs
PCW Inter@ctive
Your views, your comments, your say

Security Watchdog
Sniffing out IT security
issues

The test bed
The hottest products, news and gossip from PCW's
Labs.

IT Sneak
IT Sneak Blog rummages in the dustbin of IT events.

Backbytes
An irreverent and offbeat look at the lighter side of technology

InterActive Home
Your complete guide to home entertainment technology

Taking Stock
Gags and Gossip from Accountancy Age.

Gizmodo
The gadgets weblog.



« Acer grumbles at closed Windows pricing loophole | Main | Broadband sharing project reaches first milestone »

Information security student flunks proper disclose class the hard way

Computer security student Christopher Soghoian failed his first class in proper disclosure of security vulnerabilities. But instead of an "F", he found his front door window smashed in and all computers missing from his apartment.

Airportsecuritychkpt The FBI decided to raid his apartment after the student put up an online service that allowed visitors to create fake boarding passes for Northwest Airlines.

The site has since been taken offline, but the bare page can still be accessed through Google's cache.

Printing your boarding pass at home is one of the conveniences air travel in the internet age. These printouts will get you past the first security check that allows passengers into the gate area. This security check is the only time when a passenger's identification is checked.

Soghoian wasn't the first to warn about the weakness in the online check-in system. But he is the first one to create a publicly available service that allows people to create new passes with just a few clicks.

As any seasoned security researcher knows, you don't warn the world against the dangers of nuclear weapons by setting one off. We've got governments to do that.

Boardingpass_1

Soghoian's boardpass forging service

Christopher Soghoian

Technorati technorati tags: , ,

October 30, 2006 at 10:09 PM | Permalink

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451b07469e200d8356c707f69e2

Listed below are links to weblogs that reference Information security student flunks proper disclose class the hard way:

Comments

they are very good and useful!!!

http://www.uggsoutletstores.org
http://www.blackuggonsale.com
http://www.buy-uggs-online.com
http://www.uggbootsforsale.net

Posted-by: ugg boots | 31 Dec 2009 08:05:33

Post a comment






 

Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Ltd. 2008
Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503