• 3 Posts
  • 264 Comments
Joined 1 year ago
cake
Cake day: June 20th, 2023

help-circle






  • The TSA press office said in a statement that this vulnerability could not be used to access a KCM checkpoint because the TSA initiates a vetting process before issuing a KCM barcode to a new member. However, a KCM barcode is not required to use KCM checkpoints, as the TSO can enter an airline employee ID manually. After we informed the TSA of this, they deleted the section of their website that mentions manually entering an employee ID, and did not respond to our correction. We have confirmed that the interface used by TSOs still allows manual input of employee IDs.

    TSA: lalala i can’t hear you, everything is fine, no issue here









  • Digicert really is trying to explain this as nothing whereas they avoided a huge issue if someone realized you could get a wild card certificate for a domain you don’t own. The underscore in domain validation is needed so that subdomain DNS providers don’t issue a subdomain which can be used for domain validation. Without the underscore, someone could validate a domain and the register a username without the underscore at a provider which sets your subdomain as your username.

    Pretty bad situation but it could be worse if that happened and Digicert became untrusted completely.