Reading a lot of Bruce Schneier recently, and his excellent take on the security mindset, as well as working on a full security development lifecycle at work that is focused on getting security into each stage of the application, I have security mindset on the, er, mind. Bruce phrases it much better than me, but I think the security mindset is being able to see a scenario or situation and enumerate the potential mischief that could be enabled there.
So I see that Northwest is planning to try out paperless e-tickets using PDAs and similar smart devices. Essentially the screen displays a version of the ticket to the screen and that gets scanned. I already think that the current print your own ticket is ripe for abuse (for example, it wouldn’t be hard for me to make a fake ticket that got me through the ticket-required TSA checkpoint), but my mischievous little mind is already at work when going over scenarios that a dynamic screen that I control could present. As an exercise for the reader, to flex that security mindset, what can go wrong here?
~ Joshbw
Leave a reply