"Look I am about to fly (come steal my identity)"

"Look I am about to fly (come steal my identity)"

Stop putting your boarding pass pictures up on Facebook, LinkedIn, Twitter, Instagram, etc. Stop it. If you really want to brag about sitting on an airplane - do it with words not with a picture of your boarding pass you idiot. Most of us have sat on a plane and we know what a boarding pass looks like. 

This is what you are saying to Identity Thieves - 

 Do you know how dumb computers are. They trust you. They will give you any information or private data you need provided you have some part of it which makes them think you are the rightful owner and you are permitted to view more private data. 

(Do NOT try this at home)

Someone I know decided he wanted to proclaim to the world that he was getting on a flight to LAX today. Good. Happy for you mate. He posts a picture on FB of his boarding pass with some stupid comment "Los Angeles baby"

Notice the ETKT (E-Ticket) number on the bottom right of the boarding pass. Notice his full name on the top. Ok. Lets try this. 

1. I know the Flight No - NH006. Quick search shows it to be an All Nippon Airline flight from Tokyo to LAX today. Interesting. 

2. Get on the All Nippon website and look for "Manage Booking". So far so good.

3. Enter Full Name / ETKT No. and what do we have here. 

  1. His full travel plan (could be used for Social Engineering)
  2. Passport No. and Expiry Date (I do not need to tell you what this could be used for - Credit Cards, Bank IDs, Passwords, etc.)

Basically - I can actually get so many details from his simple picture its not funny. I can literally cause havoc in his life if I wanted to. 

Heck, I could reprint the boarding pass and enter the airport (It would be difficult for me to actually fly without making a counterfeit passport but there are people who could do that easily) 

Its very simple for an airline to do the following - Every time I wish to manage my itinerary,I get an OTP sent to my registered cell-phone or email address. That's it. Its really simple but I guess they do not want to take the pains of modifying their website. 

We live in a dangerous world today. We are voluntarily putting up so much private data on clouds, servers, social media for anyone to capture and use it for their gain. We check into hotels and resorts not thinking if I need to break-into your house, you have just told me you and your family are in Hawaii for a week. 

I understand we get happy when some 'Likes' our posts, we do. Its natural. But before putting up something out there - think. Think if that piece of information can be used to steal some part of your identity. You never know.

Note 1: I was kind enough to let him know what his simple action could mean. I hope he takes off the post. 

Note 2: I was also kind enough to teach him a lesson by choosing a 'Child's Meal" for him. I hope he can learn form his mistake while eating Apple Sauce on the plane. 

Protect your data. Its YOUR DATA. 

Shiv Kumawat

Tech Entrepreneur & Visionary | CEO, Eoxys IT Solution | Co-Founder, OX hire -Hiring And Jobs

6 个月

Vishal, thanks for sharing!

回复

要查看或添加评论,请登录

Vishal Kapoor的更多文章