The bit about the ground-handler agent not having 2FA is a bit of a red herring, getting access to a session is trivial - just find an empty common-use terminal in the airport. Or just bribe one of the thousands of underpaid and overworked agents working at any moment in any airport.
2FA would be tricky since these accounts can't be nominative anyway (at least not with the current economic model): there is so much turnover and subcontracting that it would be a nightmare to manage
The real question is how they broke out of the Common-Use Citrix session to get access to a non-airport environment, and that unfortunately isn't explained - there shouldn't be any relation whatsoever between the BA website and BA's Airport CUPPS network
2FA would be tricky since these accounts can't be nominative anyway (at least not with the current economic model): there is so much turnover and subcontracting that it would be a nightmare to manage
I disagree. Due to all the security theatre involved with post-9/11 air travel, every air-side employee is already subject to relatively strict regulations. Employees are already given personalized RFID access cards, making those same cards 2FA-capable would be a relatively small change.
Comments
The bit about the ground-handler agent not having 2FA is a bit of a red herring, getting access to a session is trivial - just find an empty common-use terminal in the airport. Or just bribe one of the thousands of underpaid and overworked agents working at any moment in any airport.
2FA would be tricky since these accounts can't be nominative anyway (at least not with the current economic model): there is so much turnover and subcontracting that it would be a nightmare to manage
The real question is how they broke out of the Common-Use Citrix session to get access to a non-airport environment, and that unfortunately isn't explained - there shouldn't be any relation whatsoever between the BA website and BA's Airport CUPPS network
I disagree. Due to all the security theatre involved with post-9/11 air travel, every air-side employee is already subject to relatively strict regulations. Employees are already given personalized RFID access cards, making those same cards 2FA-capable would be a relatively small change.