✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
@bobdahacker Whoa. I sorta thought most airlines would have addressed the massive info leaks in their boarding passes, but I guess not. Looks like my advice from years past -- shred your boarding pass and don't post them on social media -- is still sound.
@briankrebs Means a lot coming from you! 105 days and counting. Hopefully this will get Frontier to fix their shit.
@bobdahacker I consider myself lucky to live in Finland, where weak customer data security has been a crime for more than a decade already! 🇫🇮🥰