[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[DFRI-listan] Fwd: [hub@xxxxxxxx] PNR hacking demo today at CCC

-------- Forwarded Message --------
Subject: [hub@xxxxxxxx] PNR hacking demo today at CCC
Date: Tue, 27 Dec 2016 08:44:53 -0800
From: Edward Hasbrouck <edward@xxxxxxxxxxxxx>
Reply-To: PNR mailing list <hub@xxxxxxxx>
Organisation: The Practical Nomad
To: hub-at-mypnr.eu@xxxxxxxxxxxxxxx


Today at the 33rd Chaos Communication Congress (33C3) in Hamburg,
Germany, white-hat hackers from Security Research Labs will publicly
demonstrate their ability to access and alter other people's airline
reservations (PNRs).
They exploit vulnerabilities including ones that I wrote about and
called to the attention of all of the four major Computerized
Reservation Systems in 2002. But the CRSs have made a deliberate choice
not to close these because (a) government authorities have not enforced
existing data protection laws (in other countries than the USA, which
has no such laws) against CRSs, airlines, or travel agencies, and (b)
these travel companies put their profits ahead of passengers' privacy
and security.
There's been some advance coverage in German news media. But the CRS
exploits discussed in these news stories are not the most serious of
those that I expect the folks from SRLabs (perhaps best known for their
previous public demonstrations of "BadUSB" exploits) to demonstrate at
33C3. Watch the livestream here at 21:45 CET in Hamburg:

Recorded video will be posted later, but I don't know how soon. I'll add
a link once it is available.

In the meantime, here are links and answers to some of the most
frequently-asked  questions I've been getting in the last few days:


Best regards,

Edward Hasbrouck

Edward Hasbrouck

"The Practical Nomad: How to Travel Around the World" (5th ed., 2011)

Consultant to The Identity Project:

GnuPG/PGP public key:
0B0B 8F74 CEA3 83AB 97B3 F6AF BB7E F636 165C 22F5

hub-at-mypnr.eu mailing list

Attachment: signature.asc
Description: OpenPGP digital signature