Charges Dropped In Fake Boarding Pass Case 135
An anonymous reader writes, "Investigators have dropped the criminal case against Christopher Soghoian after satisfying themselves that he acted without criminal intent. The grad student had created a web site capable of printing fake airline boarding passes. Soghoian is quoted: 'If they fix the airport security problems... then this entire process has been worth it. If they don't fix airport security, then... what was the purpose?'" Soghoian's blog has insightful comments about the divide between security researchers and government officials on subjects such as TOR.
More detail (Score:4, Funny)
Eh? (Score:4, Funny)
Yes, but was it "flipped" as well?
Perhaps, while we sit here, he would like to take a minute and tell us.
Re:Eh? (Score:5, Funny)
As I understand it, he used a fake boarding pass to fly to Bel Air [seeklyrics.com], where he whistled for a cab and when it came near, the license plate said "FRESH" and it had dice in the mirror.
Re: (Score:1)
Alternative boarding pass (Score:3, Funny)
Re: (Score:3, Interesting)
True. I took a flight recently (from the middle east to the UK), and they screwed up and put the wrong name on the ticket. The travel agent insisted everything would be fine at the airport, but I wasn't so sure. Upon reaching the airport, I checked with the help desk. You know what they did? They took my ticket, grabbed a pen, crossed out the wrong name and wrote in the right one. Nobody batted an eyelid when I checked in or boarded.
Re: (Score:2)
I'm laughing about this, but I'm crying inside! If enough "terrorists" just tried to scam their way onto flights _some_ of them would make it regardless of what Security Theatre measures were in place, which just makes the whole exercise a waste of time and money!
Golly. (Score:4, Funny)
Strange laws? (Score:4, Interesting)
I have a hard time to imagine what law could be violated by this unless somebody tried to actually use such a fake boarding pass to get on a plane or into a restricted area.
I could imagine that the mere act of printing a fake boarding pass *could* (depending on how it is done) violate the copyrights of the company. Anything else?
Re: (Score:3, Funny)
Hell, many of 'em freely admit to not reading the legislation they vote upon. Asking 'em to actually understand it is obviously going way too far.
Re: (Score:3, Informative)
There is currently now federal law
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Secondly, without some actual citation of law, I still believe this would fall under general fraud laws, not some spe
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Yeah but... (Score:1, Insightful)
I bet he doesn't have all his computer equipment back that was confiscated from him during the investigation. Who needs a guilty verdict to punish him? Due process is dead.
Re: (Score:3, Interesting)
Re:Yeah but... (Score:4, Informative)
But this is slashdot, where reading isn't a prerequisite to posting.
Re: (Score:2)
Is security worth the inconvenience? (Score:5, Insightful)
So what then? Change the Constitution so that we lose the right to security in our papers? I dunno.
But what I do know is that a not-really determined terrorist can plant a bomb anywhere outside the TSA security perimeter with impunity. In fact, a bomb can be placed anywhere in any city at any time and cause the type of destruction that generates terror.
Is the solution to negotiate with the terrorists? I dunno.
I don't like to give these crackpots any more legitimacy than they deserve, but if we are truly afraid of them wouldn't it help to find out what they want and then find a way to come to a mutual agreement?
If we're not afraid of them, then stop all this nonsense about making our country safer by strip searching grandma. The initial price of freedom is blood, but the recurring cost of freedom is risk. You can't have freedom without risk. You can reduce risk by reducing freedom and that's what the current tack is, but it's a mistake to assume that we have all agreed to this level of reduced freedom because a few fraidycats are unwilling to live in a risk-filled world.
Re: (Score:2, Insightful)
Re: (Score:2, Insightful)
That's classified of course! (mostly so they don't have to tell you that it's zero!)
Re: (Score:2)
None. In fact, I don't believe there has been a single instance of a terrorist or a hijacker caught by airport security worldwide. We've got nearly 40 years of airline security history too.
Since the experience is if a terrorist or hijacker get to the airport they will get on the plane, then the lesson should be more resources need to be spent preventing them from getting to the airport in the first place. Once they get to the airport,
Re: (Score:2)
Good luck with that one! Seriously, have you tried it?
Re:Is security worth the inconvenience? (Score:5, Informative)
The Slashdot discussion: http://politics.slashdot.org/article.pl?sid=06/06
-dave
Re: (Score:2, Interesting)
It's easy, and the US appeals court has recognized this right.
See: this story [washingtonpost.com]
Re: (Score:2)
"I don't like to give these crackpots any more legitimacy than they deserve, but if we are truly afraid of them wouldn't it help to find out what they want and then find a way to come to a mutual agreement?"
What if what they want is a Global Islamic State, ruled by the Koran and anyone resisting put to the sword?
I'm all for pragmatic compromise, but at a certain point it's time to simply kill the psychos.*
* yes, I'm FULLY awa
Re: (Score:2)
But it's stupid to allow risk where it's not necessary. I think a responsible government would sweep aside concerns about political correctness and simply deal with the problem, without the window dressing. Stringent screening of visitors? Unapologetic surveillance of middle-eastern men aged 14-50? Making everyone touch a piece of raw pork before boarding (sorry, no heavenly martyrdom for you if you die before you get cleansed!)?
I don't mind living with risks as a price
Re: (Score:1)
Organization's procedures are SOFTWARE (Score:5, Insightful)
The actions by any organization larger than, uhm, 200 people, are controlled by written procedures and norms, which are software. You'd, probably, learn this much in a management course (not that I tried).
The bigger the organization, the more likely you are to deal with someone who is merely executing the instructions — unable of, and unthinking about changing them. An organization like government, or a huge department like Homeland Security is all about it. A few "software engineers" and "analysts" high above devise the algorithms, some more "coding monkeys" codify it, and then it gets to run "in production".
We are the users. And we get worked-up about the bugs. In this case, the bug is a security one, where a presented certificate is accepted without checking with the issuer.
Somebody thought, that it would be good to limit the crowds next to the gates to people with boarding passes. Checking, that the pass is valid (as airlines do at the actual gates), either did not occur to the coder at all or was deemed too expensive...
The new release will, hopefully, have a fix. If not, than, certainly, the next one. Nothing, you've never heard before.
Re: (Score:2)
It has been my experience that bureaucracies don't generally want to believe that their policies and procedures are, indeed, essentially software and could therefore be considered as such, with provisions for analysis and with their design including provisions for exceptional cases. It is tough to debug such things once they get deployed - in part because there are usually few ways to report "bugs" and often nobody to read such bug reports if they were generated. In the ideal, the policies would specif
Re: (Score:2)
Bug-reporting is easy — you write to the bureaucracy's head (they'll never read it, but their staff might).
As for reacting to a bug-report, well, that sucks with most software... Something small with a single maintainer may get fixed quickly, but large projects (like KDE or Mozilla) have bug-reports lingering for years (I filed quite a few).
Re: (Score:2)
Police state (Score:1)
It was made perfectly clear during the meeting that parts of the US government, at least the two represented at the meeting, strongly disapprove of Tor - and in particular, thought that research universities such as IU, MIT, Georgia Tech, Harvard and others have no business supporting such projects.
Basically, what we are talking about here is the "parts of the U.S. government" working to turn the country into a police state.
Security, hah, I penetrated it by accident (Score:5, Interesting)
Got them for under $1 each.
To my dismay, they can't read standard bar codes.
To my amusement, and dismay, I figured out WHY they wouldnt read standard bar codes.
Some airline sold them to a liquidator. With their custom code in the flash memory to scan their baggage and boarding pass tags.
It wasnt too hard to learn all this. Every scanner had several stickers on it with diagonal red stripes and phrases like
"/// SECURITY DEVICE #xxxxxxxx/// "
"/// USER MUST HAVE SIGNED CONFIDENTIALITY AGREEMENT A8R55-2/// "
"/// FIRING OFFENSE TO REMOVE FROM RED ZONE (UNION HBK, PG 37)/// "
"/// DEADULUS & EARHART AIRLINE CUSTOM FIRMWARE VERSION 1.22"/// .
I wonder what their thought processes where?, something like:
those are antiques!!!! (Score:5, Funny)
Those are antiques! You might just try to re-sell them on eBay. Daedalus Airlines, in particular, had their assets sold of decades ago when the last wax-attached bird features fell off the last airliner. Both airlines declared bankruptcy, and eventually merged with the old Glenn Miller Airlines to form the Oceanic Air we know and love today. You know, the one with the slogan "Getting halfway there is all the fun". They're also the first airline to consider electrified wings in order to keep the gremlins off.
Re: (Score:2)
In the case of boarding passes it's simple - you check each one against the central database of valid passes for that flight. If you get two passes for the sa
your signature (Score:2)
There is nothing to fear. It is just a small fragment of MS-DOS assembly code. "B8 00 4C" is "mov ax, 4c00h", and "CD 21" is "int 21h". It is a MS-DOS system call that exits your program (system call number 4c) with a status 00 (the lower byte of ax). Now everyone knows...
I haven't used Windows for a long time, but I wonder if it still comes with an MS-DOS debugger?
CIA and TOR (Score:3, Informative)
Umm, not sure about this (Score:3, Informative)
I fly across country every other week and have well over 100,000 miles under my belt this year a lone and I have never once gotten through security without my ID. Wrong boarding pass, yes, but it still had my name and matched my ID. And since we have no National ID how does one make sure the the people paid $8 an hour know how to check every state and military ID and look for fakes?
Re: (Score:1)
It's really simple. When you checkin with the airlines, tell them you forgot your ID, and they'll print you up a special boarding pass that has the letters "SSSS" marked on it - which means that you'll get searched a bit more carefully (i.e. they'll swab stuff in your carry-on bag to check for bombs).
If your main goal is to bypass the no-fly list, and not to sneak something onto the plane, then this should be more than enough for you.
Plus, in some airports, they rush SSSS passengers to the
Re: (Score:1)
Re: (Score:2)
DHS Tax! (Score:2, Funny)
Terrorists work to destroy trust. (Score:3, Insightful)
Re: (Score:2)
Comment removed (Score:4, Informative)
Mind Reading (Score:2, Interesting)
Look, the charges against this guy are bogus. The criminals are the people in the TSA who treat us like dirt on a cop's beat, while leaving these gaping security holes for actual attackers to exploit. Who try to cover
Re: (Score:2)
50% Interesting
50% Troll
Sleazy trollMods never brush their teeth, anyway. Why should they even read the posts, let alone reply when they disagree?
Are expired fake boarding passes ok? (Score:2)
They mention fake airline itineraries, not boarding passes, but would a fake, used boarding stub also get you in trouble?
OT: having an affair is sleazy, but not illegal. If that alibi company is used to cover a crime, do they have any liability?
Yay! (Score:1)
TIME FOR GO TO BED! (Score:2)
There has long been a sharp division of opinion on the merits and failings of TOR [imdb.com]... So Soghoian's observations aren't anything new...
Not a security issue (Score:2)
Double Standard? (Score:2)
Probably get the usual terrorist plot stuff I suppose.
Just like that video where a white guy goes on a bridge by himself and starts snapping pictures. Nothing happens, so he leaves and comes back dressed as a sheik, complete with long white robe and head covering. He then proceeds to do the exact same things he did prior without the costume. Within 2 mins he is accosted by security
Re:Paranoia (Score:5, Insightful)
Don't you get it? Real crimes are copyright infringements. Spending money and resources protecting passengers on jet planes is a complete waste of time....
Real criminals are underprivileged 13 year old girls evilly downloading music they have not purchased. May they hang!
Re: (Score:2)
Those people using fake board pass generators are not paying anything for their privilege to visit the Cinnabon(TM) that is down by the gates. They must be stopped.
Re: (Score:1)
Re: (Score:2)
Part of your purchase of that 80% marked up cinnabon goes to pay for the airport which would otherwise be paid by the airlines and which would be part of your ticket.
Money is so fungible these days.
Pulling example numbers out of my nether regions:
Airline Ticket Sales: 60 million.
Total cost to run Airport a year 10 million.
Airline payments to airport: 6 million.
Very high rent to those restaurants: 4 million.
So tickets would have to cost 64 million a year without them.
So your $200 ti
Re: (Score:3, Interesting)
Came back from Europe recently. Picked up bag at destination. TSA lock had been ripped off the bag, taking two zipper pulls with it. (Bag is now unlockable.)
Looked inside. Contents rearranged, but on the top of the pile were ...
the two DVDs and a CD I bought in Amsterdam. No TSA notice that they'd
vandalized my bag. No apology. No lock. Nothing missing, so it wasn't a thief who did it.
From all appearances, they pried open my bag in a desperate
Re:Paranoia (Score:4, Insightful)
If you want to look for coordination, look towards the lobbyists. The RIAA and MPAA lobbyists who have helped pass the oppressive copyright protection laws don't have anything to do with the airline lobbyists or defense lobbyists who have helped write much of the War on Terror related laws.
Re: (Score:2)
Maybe they couldn't manage to convince an judges that there was actually a case to answer.
If I were Chris, I'd thoroughly check and wipe the disks of the computers that the FBI gave back to him.
Being sure to record (a
Re: (Score:1)
If creating boarding passes required circumventing a digital copyright control, then it would be illegal. It's not illegal to just print some shit out on your printer that happens to look like a boarding pass...
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
I would just sell them and buy new ones. Even if you carefully inspected all your hardware, would you really be able to tell if anything had been modified/removed/spliced in? It's probably safer to just assume that you won't find it if it's there and ditch everything.
easily faked boarding passes (Score:1)
Re: (Score:1)
Re:Paranoia (Score:4, Informative)
Bull.
Garland Grant (look it up).
[Only need one counter example to prove your 100% wrong]
Re: (Score:3, Informative)
Re: (Score:2)
What harm did he cause? (Score:2)
Re: (Score:2)
Re:Paranoia (Score:5, Insightful)
All these things can do is maybe get someone into the gate area. But seriously, if a terrorist wanted to blow up an airport, do you honestly think he would spend the hundreds of dollars building a bomb, and then balk at the $80 for a plane ticket? Hell, he could even steal a boarding pass from someone else. Seriously, requiring boarding passes to get into the gate area only serves to give people a false sense of security. It would not be an obstacle for anyone who wants to actually do harm.
I agree that posting the generator on the Internet was foolish, but only in the sense that posting anything that even appears to be able to help terrorists in today's climate is a stupid thing to do, not because it could actually endanger anyone's safety.
Re: (Score:2)
Don't forget the danger to everyone who ran the boarding pass generator... The Feds have the access logs and I know I'm in them. I didn't change the default name (Osama B.) or anything though. My God help you if you did and then generated a boarding pas
Re: (Score:1)
The trick is to bypass the no fly list without having to have fake ID, the loophole is that the name on your ID and boarding pass are not both checked at the same time and compared.
Re: (Score:2)
You must go to different airports then I do because all of the airports I go to require a boarding pass AND photo ID that matches the name and the photo looks like the bearer.
Re:Paranoia (Score:4, Insightful)
Right, but at that point, they don't actually check the name against any kind of list.
Just to make it clear:
There is no ??? and Profit.
What about baggage check, you ask? That is a tiny bit more complicated, but not really. You just get John Smith to come to the airport with you and he checks in and checks the bags. Then he goes home and Bob Terror takes it from there. It's even easier in some airports where they have skycaps who I don't think do any ID checking, or automated bag checking with the same problem.
As you can see, the no-fly list is useless because of this flaw. It's a waste of time, money and just hassles people who are NOT terrorists and who have somehow got on the no-fly list, via similar names or simple mistake.
They could make one simple change to make this system better - check ID at boarding. Yeah, it adds a little time and wouldn't stop terrorists with forging connections. I don't think it would actually do much to stop terrorists, either. Especially considering terrorists aren't likely to be on the no-fly list until you figure out they are terrorists and by then it's probably too late. But as it is now, what they are doing is 100% useless. At least that way it would be only 99% useless.
The other thing they could do is just stop the no-fly list and stop checking ID, as both are useless at this point and may never be effective at stopping terrorism. As long as ID is forgable and the method is to check ID, these systems are all just false hope. Unfortunately, it's false hope combined with hassling everyone else that flies.
Re: (Score:2)
Re:Paranoia (Score:5, Insightful)
As with most of the security changes imposed on air travel it is all mostly illusion, or as some other Slashdot poster called it "Security Theatre". If you make life difficult for the average travelor they will assume it makes life equally difficult for terrorists. Unfortunately, this just isn't true!
What I don't understand is if Osama and his cohorts are so dead set against us (ie The West) and he has armies of suicide jockeys all raring to go, then why aren't there 'planes falling out of the sky all around us. Why are shopping centres (malls) not blowing up? Trains, buses, garages, boats, ships. They could be instilling real terror on a daily basis but they're not! Hell, even failed attempts to blow up stuff would instil terror as it would confirm that they are still trying! It doesn't make any sense, unless they're simply not as powerful as we are being led to believe, in which case why are the politicians still trying to take away our freedoms?
Re:Paranoia (Score:5, Interesting)
BINGO.
Been saying this since ~6 months after 9/11.
Rummy also told us that A.Q. had several super-high-tech underground bases in Afghanistan, any one of which would have made Cobra Commander or Dr. Evil proud. Did you see the diagrams of them that the Whitehouse produced? It was some hilarious bullshit.
The lying didn't start with Iraq. A lot of people have forgotten, I think, the degree to which the Bush administration was spewing what should have been easily exposed as lies (I guess a lot of people fell for them; if Bush has achieved nothing else, he's convinced me that people are, on average, way, way dumber than I thought they were) since 9/12/01. They lied to hype up the war in Afghanistan, and they lied to exaggerate Al Qaeda's ability to project meaningful force into the U.S. Remember them saying how there were dozens or hundreds of "sleeper cells" here just waiting to be activated? What happened to that? They certainly haven't found any (thought they did a couple of times, turned out that they were just incompetent as usual) nor have we been attacked again, and they've stopped talking about it.
Remember the short-lived "Total Information Awareness" office whose first public message was to encourage U.S. citizens to spy on their neighbors? Ha!
This administration has been lying to us and manipulating us from the beginning. The willingness of most people here to accept it has convinced me that, excepting the unlikely chance that education will be overhauled, the dream of America is doomed. The country may survive, but our ideals, which began slowly dying as soon as the ink on the Constitution had dried, are dead, and cannot be saved in our lifetimes.
It turned out that We the People were just too dumb (or were made to be too dumb) to handle it. Let it be said that the final blow was struck by mass ignorance and apathy.
Re: (Score:3, Interesting)
Re: (Score:2)
Re:Paranoia (Score:4, Interesting)
You missed the point: it's not to save buying a ticket. (They scan the boarding pass at the gate and can detect a fake at that point, so you need to carry a real boarding pass anyway.) One of the goals of the system appears to be to exclude people from certain names from flying, at least without some additional checks. Since they don't scan the boarding pass at security, you can hand them a fake boarding pass (matching your real ID) at security. If that's the only time they check ID, then you can use a real boarding pass (bought under somebody else's name) at the other points. And if I understand right it's only at those other points that they actually check the name against no-fly lists. So the no-fly list doesn't work even given really good unforgeable ID's.
Seems like kind of a crazy system if that's correct--so it's fair game for being made fun of, which is all the fake boarding-pass generator does as far as I can tell.
Re: (Score:2)
Man, this gives me a great idea! I fly a pretty good amount, but my girlfriend does not. She always complains that I get to use the short line, get free upgrades, etc. I was blessed with a gender-neutral name, so when she's flying alone, I could print out a fake boarding pass with her name on it, and buy a ticket with my name on it. She gets the upgrades, and I get the miles.
Thanks, terrorists!
Re: (Score:2)
You do know that you can apply your miles to her ticket if you buy them together, don't you? I wound up paying for a co-worker's upgrade because I DIDN'T know that. I asked for an upgrade, and they upgraded her too, because our tickets were tied together in the system. I though they were being nice to her -- until I saw my milage statement a month later.
I think it's about efficiency, not security (Score:1)
Re: (Score:2)
Sure; it's not checking boarding passes that's being made fun of--it's the idea that the no-fly list can prevent people with certain names from flying.
The fake-boarding-pass generator points out that you don't even n
Re:Paranoia (Score:5, Insightful)
He isn't sacrificing the safety of others. This is the point of the exercise: our government is sacrificing the safety of us, and doing it while wasting (or stealing, depending on the individual politico) huge amounts of our tax money.
"Writing a research paper is one thing, but posting a boarding pass generator on the internet is pretty serious stuff."
Serious how, exactly? Serious in the sense that it actually demonstrates his claims, yes. Do you think anyone would pay attention or even hear if he just stated how poorly designed these procedures are? He would be dismissed as a political critic.
Saying that "posting a boarding pass generator on the internet is pretty serious stuff" borders on ludicrous. I can just picture the crowds running for cover, terrified, "Dear God! It's a boarding pass generator! On the INTERNET!"
"I find it very shocking that the FBI dropped the case. I think people have been sent to Guantanamo for much less."
Yes, people have been sent to Guantanamo for much less, but just because a few random peasants who happened to be in the wrong place at the wrong time got locked up for 5 years of their lives, torn from their wives and children, unable to speak even with a lawyer -- let alone protest their innocence -- does not make such pointless attacks on human liberty justifiable. Be surprised that the FBI dropped the case, but only be surprised because of the incongruity of this glimpse of sanity.
Re:Paranoia (Score:4, Interesting)
First and foremost, I've been a slashdot lurker, and finally registered for an account because I think I have something of value to say here.
So, I think you guys have totally overlooked the point of all this. The way he talks about fixing the airline boarding pass security issue highlights to me that he is a security minded individual and has taken this step because he's noticed a vulnerability and has generated a proof of concept to illustrate the need for reform. This is often the only way to spark change rapidly in a ginormous looming organization as many of these airlines are. In my opinion, this public disclosure of a vulnerability is no different than the daily postings on SecuriTeam or Remote-Exploit or similar sites.
I see the argument then being "well, he probably said that to get out of a lawsuit". While I'm in no position to agree or disagree, from a larger perspective, even if that was the case, this vulnerability has been address, the ball is in the airlines court to clean up their mess. He knew that was how it would go down, and that makes this guy a whitehat. He convinced the FBI of this, and thats why they dropped the charges. We may not have the most reliable and efficient government in the world, but hey at least they are trying to embrace technology. I'd like to think that our government recognizes the need for public disclosure of *SOME* vulnerabilities to enact change... but that may be too optimistic of me.
Security is never absolute, and I am a firm believer that we cannot enhance our own security without first understanding how to break it. This guy is the bug finder, who will fix the bug? Long story short --> chalk one up for the whitehats!
And if dude wasn't white? Well .. I'm not touching that with a ten foot pole-arm +1 even.
just my .02 ;P
-Marspeace'n'reallylouddrumandbass
Welcome to the collective (Score:2)
Welcome to the collective. Please turn in your life. You can pick up your hot grits in room 404.
Re: (Score:2, Informative)
Re: (Score:3, Informative)
Find a manual for one of them. The previous user most likely had them set to only respond to a very specific symbology, to avoid having the morons they hire accidentally confuse the system by trying to check-in things like Pepsi cans and bags of Cheetos.
You want to reset them to factory defaults, then enable all symbologies (or if you can't find an "enable all", just turn on the ones you need... Code128 works pretty well for general-purpose custom barco