Skip to main content

A flaw in e-ticket systems could mean a hacker can print your boarding pass

best flight tracking apps
Trevor Mogg

Security researchers at the firm Wandera have exposed a vulnerability in the e-ticking system used by several popular global airlines. The vulnerability was discovered in December and involves unsecured check-in emails that can put the personal information of passengers at risk or even allow a hacker to print boarding passes.

Though there is no evidence that currently supports a major data breach, eight airlines including Southwest, Air France, KLM, Vueling, Jetstar, Thomas Cook, Transavia, and Air Europa are impacted by this vulnerability. According to Wandera, these airliners are sending unencrypted check-in links, which otherwise automatically log passengers into a website to check flight status and print boarding passes. That can allow a hacker who is sharing the same Wi-Fi network as a passenger to intercept the link and gain access to the same information.

Several types of personally identifiable information can be accessed through this vulnerability, including passport information, seat assignments, first and last names and baggage selections. However, the type of information that can be stolen depends on each airline e-ticking system. In some cases, hackers can still leverage this information to their advantage to change an itinerary. That includes the ability to add or remove extra bags, change seating arrangements, or alter both the mobile phone number or email associated with a booking.

“Our threat research team observed that travel-related passenger details were being sent without encryption as one of our secured customers accessed the e-ticketing system of one of the airlines mentioned above. It was at that time that Wandera notified the airline and began further research,” Wandera said.

The vulnerability was shared the appropriate government agencies as well as with the airlines. A period of four weeks is given for the vulnerability to be fixed before it was made public. As a solution, Wandera recommends for airlines to adopt strong encryption methods, require user authentication, and use one-time tokens for links in emails.

This would not be the first time that airliners have faced scrutiny relating to its cybersecurity practices. Though more severe, a British Airways data hack in 2018 impacted more than 380,000 passengers after its computer systems were breached. A separate instance with Cathay Pacific also impacted up to 10 million of its customers in 2018.

Editors' Recommendations

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
How to download Vimeo videos on desktop and mobile
Vimeo app icon on Apple TV.

Downloading Vimeo videos lets you enjoy these high-quality, cinematic uploads without relying on an internet connection. These days, it’s easier than ever before to obtain these media files, too. Thanks to online video converters, you’ll be able to download and save videos straight to your smartphone, tablet, or laptop. There’s also the possibility you’ll just be able to download a video directly from Vimeo, without using extra software.

Read more
I finally found a gaming laptop utility that’s actually worth using
The Asus ROG Zephyrus G16 sitting on a coffee table.

Nearly all gaming laptops come with bundled first-party software, and most of it isn't all that good. They tend to be poorly designed and riddled with bloatware and features that you'll never need. Armoury Crate is Asus' version of that, and while it isn't terrible, it suffers from many of those same problems.

A large number of users on Reddit have voiced their criticism of Armoury Crate, accusing it of being buggy, broken, and overly complex. Some of the most common issues include the software's cluttered user interface, promotional pop-ups, unnecessary bloatware, and the high usage of system resources. In my experience, I do find Armoury Crate's UI to be confusing, and I've also noticed that the software runs way too many background processes and services, some of which seem unnecessary.

Read more
How to delete Slack messages on desktop and mobile
how to delete slack messages message confirm mac desktop

If your company uses Slack as its preferred communication tool, then you'll need to know the basics of navigating it. And one action you might want to know how to take in Slack is deleting a message. You can remove a direct message or one you post in a channel using any of the Slack desktop, web, and mobile applications.

For those times when you type a message in the wrong channel or conversation or simply say something you wish you hadn’t, here’s how to delete Slack messages.

Read more