FlyerTalk Forums - View Single Post - TSA to Test Encrypted Flight Boarding Passes
Old Feb 12, 2009 | 7:54 am
  #5  
JaggedMind
 
Join Date: Mar 2007
Location: DEN
Programs: Frontier Summit, Marriott Gold, Hertz 5*
Posts: 171
The problem I see is that this is going to be seen as such a fun challenge to hackers and crackers that an actual boarding pass generator program will be created and passed around in no time. A small amount of known data being encrypted with constant keys with loads of samples available is a small task to crack in today's world.

To make this pretty much secure you need:
- Passes checked against airlines' systems in real-time.
- Encryption keys updated often (weekly or sooner).
- Use stronger encryption or encrypt lots of extra "junk" data. This is probably not possible while keeping the decryption time low and the barcode within the size requirements.

And there is always the possibility of something like the TSA's copy of all the airline keys getting loose some day.
JaggedMind is offline