• @[email protected]
    link
    fedilink
    English
    9619 days ago

    The TSA press office said in a statement that this vulnerability could not be used to access a KCM checkpoint because the TSA initiates a vetting process before issuing a KCM barcode to a new member. However, a KCM barcode is not required to use KCM checkpoints, as the TSO can enter an airline employee ID manually. After we informed the TSA of this, they deleted the section of their website that mentions manually entering an employee ID, and did not respond to our correction. We have confirmed that the interface used by TSOs still allows manual input of employee IDs.

    TSA: lalala i can’t hear you, everything is fine, no issue here

    • @[email protected]
      link
      fedilink
      32
      edit-2
      19 days ago

      If Security through Obscurity isn’t working, consider Security through Stupidity, I guess.

      I worked with some oilfield SCADS folks in the early 2000’s who used open IP for their valves, who were very convinced no one would use their equipment because “no one knew they were there.” At some point, it’s no longer trust in good actors.

      Compliments to the authors, someone owes these guys challenge coins.

    • @jaybone
      link
      20
      edit-2
      19 days ago

      TSA is such a joke. And now we’ll never be rid of them. Thanks Al Quaida, you have successfully achieved your goal of inconveniencing the infidel travelers for decades now. I hope you are happy with yourselves.

        • @TechnologyChef
          link
          218 days ago

          It seems also harmful to our humanity of Amendments treating disabled, brown, and black people without suspicion and abuse.

    • @[email protected]
      link
      fedilink
      118 days ago

      100% not true.

      A bar code is required for KCM. Has been for a while now. Manual entries have not been allowed for quite some time.