Equipment

Anarchist hacker exposes the TSA’s 1.5 million-name no-fly list-

First reported by the Daily Dot, an activist and hacker who goes by the name maia arson crimew uncovered a version of the United States government’s No-Fly List dated to 2019 on an unsecured server owned by regional US airline, CommuteAir (formerly CommutAir). The glimpse at this well-known, but not publicly available, US government registry is the latest in a cavalcade of major corporate security breaches in recent months.

Crimew, an independent hacker and researcher, discovered the list via a variant of Shodan, a cybersecurity-focused search engine that allows users to find unsecured servers on the net. Crimew found one such server owned by CommuteAir, a partner of United Airlines specializing in short-range flights. In addition to the list itself, preposterously named NoFly.csv, crimew uncovered detailed employee records for CommuteAir, as well as credentials to allow her access to “navlblue APIs for refuelling, cancelling, and updating flights, swapping out crew members, and so on.”

Crimew has not published the No-Fly List in full, but has made it available by request for journalists. Crimew described it to Kotaku as being over 1.56 million entries long, containing names, birthdates, and aliases for targeted individuals. Crimew told the Daily Dot that “it’s just crazy to me how big that Terrorism Screening Database is and yet there is still very clear trends towards almost exclusively Arabic and Russian sounding names throughout the million entries.”

CommuteAir confirmed that the database was genuine and dated to 2019, while the TSA told the Daily Dot that it was “aware of a potential cybersecurity incident with CommuteAir,” and that it was “investigating in coordination with [its] federal partners.”

Although the US government maintained a small list of individuals with a “no transport” flag prior to 2001, the No-Fly list exploded in size and scope following the September 11 attacks. Critics argue the list is an opaque overreach of the security state that has disproportionately affected Muslims. The list includes some American citizens.

In 2016, Senator Diane Feinstein disclosed that the list covered 81,000 people, while in 2005, the TSA admitted that it had received 30,000 complaints from people who had been added to the list by mistake. It is unclear how many of the 1.5 million entries on NoFly.csv are aliases, accounting for common misspellings, or other forms of repeat entry for the same individual, while the Daily Dot mentions the possibility that this leak could reflect the wider and less restrictive Terrorism Screening Database as opposed to the narrower and harsher No-Fly List.

This is not crimew’s first act of hacktivism. She has previously leaked data from Intel, Nissan, and cloud-based security firm Verkada. Crimew had her home raided by Swiss police in relation to charges from the US government over these breaches, but she is protected from extradition to the United States by the Swiss constitution. Crimew maintains a personal website and active Twitter account.

Related Posts

The Story Behind ‘Cassandro’

Halfway through Cassandro, the biographical drama about the wrestler Saúl Armendáriz out now on Prime Video, the soaring ballad “Hasta Que Te Conocí” plays over a poignant scene.

Saúl (Gael García Bernal) and his mother Yocasta (Perla de la Rosa) have snuck into the backyard pool of an empty house for sale in their city, El Paso. It’s a pretty thing that they can’t afford with a yellow kitchen, and Saúl wants to buy it for them with money from his fights as soon as possible. They float in the abandoned pool and chat, somewhere between serene and melancholy, as the Mexican singer Juan Gabriel croons, “Yo sabía de cariño, de ternura. Porque a mí desde pequeño, eso me enseñó mamá.” (“I knew of affection, of tenderness because since I was little, my…

Best Buy and Target’s Prime Day equivalent sales are on now-

Amazon decided to stick a sale event in the summer with its Prime Day deals, which start this week on Tuesday, so naturally its competitors have followed suit. They can’t call their competing events “Prime Day,” of course, which is how we now have Target Circle Week and Best Buy Black Friday in July. Look what you’ve started, Bezos!

I’m just going to call all these sales “Prime Day,” even though that’s Amazon’s thing. It’s easier that way. So, as I was saying, Target Prime Day and Best Buy Prime Day have started, and already have some PC gaming deals to offer before Amazon’s official Prime Day kickoff.

That includes some gaming laptops, a few of which we’ve already noted in our hub of the best Amazon Prime Day PC gaming deals. 

Best Buy also has deals on PC gaming…

Former dev from sunken Sims competitor Life by You alleges the team had ‘the rug pulled’ from under them—despite outperforming the company’s internal metrics-

Life by You seemed poised to corner an untapped market—that corner being a version of the Sims not bogged down by over $1,200’s worth of DLC. As PCG’s Joshua Wolens noted during a preview, it was angled to be “Sims with the brakes cut”.

Unfortunately, that didn’t materialise. A mere month after delaying its early access without a new date, Paradox released a statement that the game would go unreleased forevermore. In the announcement, the company argued that “the road leading to a release that we felt confident about was far too long and uncertain.” Within a day, Paradox Tectonic—the division of Paradox making the thing—was shut down.

However, a former developer from Paradox Tectonic alleges a very different story. In a lengthy LinkedIn post, Willem Delvent…

GTA Online’s Halloween event makes a fan rumour real and gives one of its protagonists a last goodbye-

I’ll make no bones about it: I preferred Grand Theft Auto 4 to GTA 5. The latter is great and all but I never got over the more grounded and gritty take of GTA 4 and in particular its tragic central cast, defined and trapped by their lives in the criminal underworld. GTA 4 had two great expansions, The Ballad of Gay Tony and The Lost and the Damned, both introducing their own protagonists and side stories. One of them was the biker Johnny Klebitz, who, unlike many of Rockstar’s leads, ends his GTA 4 arc in a better place.

An early twist in GTA 5 upset the apple cart: One of that game’s three protagonists, the psychopathic Trevor, finds a drug-addled Johnny and beats him to death. This has always been an unpopular twist, which perhaps indicates narratively it was a good one (boo!),…

All Genshin Impact codes from the 4.7 livestream-

The Genshin Impact 4.7 livestream codes for this version have arrived. For those that aren’t aware, or maybe just started playing Genshin for the first time recently, miHoYo presents a livestream in advance of each new update. This shows off the new characters, quests, and events that are happening, and as a little bonus incentive to watch, there are three livestream codes that get you some Primogems.

For this version, it looks like the new characters are Hydro five-star, Sigewinne and Electro five-star Clorinde, plus potential reruns for Furina and Alhaitham. As usual, I’ll add each livestream code as it drops during the special program—these codes generally expire within a day, so you should redeem them as soon as you can. There’s also inf…

Roblox wants you to interview inside Roblox to work at Roblox-

I suppose there was a time when the thought of conducting interviews over Zoom or Skype was unheard of, so perhaps the idea of interviewing candidates inside virtual worlds isn’t such a wild concept. Especially when, in Roblox’s case, the virtual world you’re interviewing inside is for the very platform you’re trying to work for.

The Roblox Career Center is touted as an “immersive experience” where would-be candidates can drop in for information all about working for the company. A blog post from VP of talent acquisition Jason Buss promises it to be a place where “candidates can learn more about the complex technical challenges we are tackling and the innovation we are driving through immersive events, podcasts and conversations with Roblox employees.”

There are places to go…