Skip to content

Comment on How the British Airways' breach kickstarted today's web security challenge

Comments

The bit about the ground-handler agent not having 2FA is a bit of a red herring, getting access to a session is trivial - just find an empty common-use terminal in the airport. Or just bribe one of the thousands of underpaid and overworked agents working at any moment in any airport.

2FA would be tricky since these accounts can't be nominative anyway (at least not with the current economic model): there is so much turnover and subcontracting that it would be a nightmare to manage

The real question is how they broke out of the Common-Use Citrix session to get access to a non-airport environment, and that unfortunately isn't explained - there shouldn't be any relation whatsoever between the BA website and BA's Airport CUPPS network

2FA would be tricky since these accounts can't be nominative anyway (at least not with the current economic model): there is so much turnover and subcontracting that it would be a nightmare to manage

I disagree. Due to all the security theatre involved with post-9/11 air travel, every air-side employee is already subject to relatively strict regulations. Employees are already given personalized RFID access cards, making those same cards 2FA-capable would be a relatively small change.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.