Skip to main content

Why posting photos of your boarding pass is a terrible idea

Ah, travel. Remember travel?

Travel was when we used to go “other places,” in a time when the U.S. wasn’t literally banned from the rest of the world. And often, when preparing to travel, we used to post pictures to social media of our boarding pass to show off to our friends and — more importantly — anonymous internet strangers.

Recommended Videos

Turns out this is and has always been a terrible idea because the internet is dark and full of hackers. Or in this case, a person in Australia who knows how to access the “inspect element” option on a website’s drop-down menu and used it to hack personal details from the country’s former Prime Minister.

"So you know when you’re flopping about at home, minding your own business, drinking from your water bottle in a way that does not possess any intent to subvert the Commonwealth of Australia?"https://t.co/OCvJKODTTZ

— “Alex” (@mangopdf) September 16, 2020

As chronicled in an extremely hilarious blog post, complete with YMCA background music, Alex Hope, a hacker and blogger based in Australia, detailed his odyssey of kind-of-accidentally-on-purpose discovering the passport and phone numbers of former Australian Prime Minister Tony Abbott.

It all started when Abbott posted a picture on Instagram of his boarding pass in March, in which the booking reference number is clearly visible (the photo has since been removed, because duh).

Turns out, as Hope discovered, you can easily log in to certain airline websites using just this information: A last name and a booking reference. And voilà, Hope got his hands on the rather sensitive information of the major Australian diplomat, including what the airline was saying about Abbott, his phone number, and his diplomatic passport number.

This sent Hope down a wormhole of government email addresses and telephone numbers, trying to inform the powers-that-be that he had rather easily snagged this information and that it was a problem. In the end, Hope said officials corrected the issue.

When reached for comment, Hope confirmed to Digital Trends that he wasn’t a professional white-hat hacker, and the blog was basically just a fun side project, but that he does work in computer security professionally.

“I didn’t have to use any like, actual computer knowledge for this,” he told Digital Trends over Twitter. “But doing this kind of thing for work did get me in the useful habit of recording my screen whenever I’m about to do a crime.”

Making yourself an easy target

While Hope’s story is the latest (and currently, funniest) documentation of how this kind of identity theft works, it’s been a known problem for a while.

Hope’s hack was fairly low-tech (a simple right-click will do it), but there are websites out that that can also fully scan a boarding pass bar code simply through the picture, according to Reader’s Digest.

In 2017 and 2018, both Forbes and the tech blog Null-Byte pointed out that while some bad actors will go so far as to “socially engineer” (aka phish) information out of people, a simple search of #boardingpass on Instagram will yield thousands of potential targets. Even if a bar code or a booking reference aren’t forthcoming, just a frequent flyer number will work. Even Google Images indexes boarding pass pictures.

It doesn’t take much to get people’s personal information and screw up their lives via identity theft. So don’t let vanity — or a compulsive desire for social media validation — will be your downfall. Stop posting pictures of your boarding passes. Or at least obscure the important information if you must show off to your pals.

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
Google just gave vision to AI, but it’s still not available for everyone
Gemini Live App on the Galaxy S25 Ultra broadcast to a TV showing the Gemini app with the camera feature open

Google has just officially announced the roll out of a powerful Gemini AI feature that means the intelligence can now see.

This started in March as Google began to show off Gemini Live, but it's now become more widely available.

Read more
This modular Pebble and Apple Watch underdog just smashed funding goals
UNA Watch

Both the Pebble Watch and Apple Watch are due some fierce competition as a new modular brand, UNA, is gaining some serous backing and excitement.

The UNA Watch is the creation of a Scottish company that wants to give everyone modular control of smartwatch upgrades and repairs.

Read more
Tesla, Warner Bros. dodge some claims in ‘Blade Runner 2049’ lawsuit, copyright battle continues
Tesla Cybercab at night

Tesla and Warner Bros. scored a partial legal victory as a federal judge dismissed several claims in a lawsuit filed by Alcon Entertainment, a production company behind the 2017 sci-fi movie Blade Runner 2049, Reuters reports.
The lawsuit accused the two companies of using imagery from the film to promote Tesla’s autonomous Cybercab vehicle at an event hosted by Tesla CEO Elon Musk at Warner Bros. Discovery (WBD) Studios in Hollywood in October of last year.
U.S. District Judge George Wu indicated he was inclined to dismiss Alcon’s allegations that Tesla and Warner Bros. violated trademark law, according to Reuters. Specifically, the judge said Musk only referenced the original Blade Runner movie at the event, and noted that Tesla and Alcon are not competitors.
"Tesla and Musk are looking to sell cars," Reuters quoted Wu as saying. "Plaintiff is plainly not in that line of business."
Wu also dismissed most of Alcon's claims against Warner Bros., the distributor of the Blade Runner franchise.
However, the judge allowed Alcon to continue its copyright infringement claims against Tesla for its alleged use of AI-generated images mimicking scenes from Blade Runner 2049 without permission.
Alcan says that just hours before the Cybercab event, it had turned down a request from Tesla and WBD to use “an icononic still image” from the movie.
In the lawsuit, Alcon explained its decision by saying that “any prudent brand considering any Tesla partnership has to take Musk’s massively amplified, highly politicized, capricious and arbitrary behavior, which sometimes veers into hate speech, into account.”
Alcon further said it did not want Blade Runner 2049 “to be affiliated with Musk, Tesla, or any Musk company, for all of these reasons.”
But according to Alcon, Tesla went ahead with feeding images from Blade Runner 2049 into an AI image generator to yield a still image that appeared on screen for 10 seconds during the Cybercab event. With the image featured in the background, Musk directly referenced Blade Runner.
Alcon also said that Musk’s reference to Blade Runner 2049 was not a coincidence as the movie features a “strikingly designed, artificially intelligent, fully autonomous car.”

Read more