US U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server - The list, which was discovered by a Swiss hacker, contains names and birth dates and over 1 million entries.

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

1674308368663.png


A copy of the U.S. No Fly List has leaked after being stored on an unsecure server connected to a commercial airline. The No Fly List is an official list maintained by the U.S. government of people it has banned from traveling in or out of the United States on commercial flights.

As first reported by The Daily Dot, a Swiss hacker known as maia arson crimew discovered the list on an unsecured Jenkins server one night while poking around on Shodan, a search engine that lets people look through servers connected to the internet.

“Like so many other of my hacks this story starts with me being bored and browsing shodan (or well, technically zoomeye, Chinese shodan), looking for exposed jenkins servers that may contain some interesting goods,” crimew said in a blog about the leak. “At this point I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words. ‘ACARS,’ lots of mentions of ‘crew’ and so on. Lots of words I've heard before, most likely while binge watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir.”

On the server was a large amount of company data about CommuteAir, including the private information about its employees. There was also a file containing a copy of a 2019 edition of the No Fly List. The list includes names and birth dates and more than 1.5 million entries, but many of those entries are aliases that all reference the same person.“It’s so much bigger than I thought it’d be,” crimew told Motherboard.

“TSA is aware of a potential cybersecurity incident, and we are investigating in coordination with our federal partners,” a spokesperson for the TSA told Motherboard.

The United States has maintained a No Fly List for decades, but its number was much smaller in the days before 9/11 and only contained 16 people. After the attacks and the creation of the Department of Homeland Security, the list rapidly expanded. The exact number of people on the list is unknown, and the leaked data is a few years old and contains multiple entries for a single individual, but recent estimates put the total number at somewhere between 47,000 and 81,000 people.

“It’s a perverse outgrowth of the U.S. police and surveillance state,” crimew said. “Just a list with no due process…mostly just based on them being related to someone or being from the same village as someone. It’s so massive. I feel like this has no place anywhere. I feel like this doesn’t solve the problem.”

crimew told Motherboard they weren’t shocked to stumble on an unsecured copy of the No Fly List. “I’ve been digging into various jenkins [servers] for a while and there’s just so much to find,” they said. “It was just a matter of time until I found something like this.”

CommuteAir said the leak happened because of a misconfigured development server. “The researcher accessed files including an outdated 2019 version of the federal no-fly list that included first and last name and date of birth,” it said. “Additionally, through information found on the server the researcher discovered access to a database containing personal identifiable information of CommuteAir employees. Based on our initial investigation, no customer data was exposed. CommuteAir immediately took the affected server offline and started an investigation to determine the extent of data access. CommuteAir has reported the data exposure to the Cybersecurity and Infrastructure Security Agency, and also notified its employees.”



Check the blogpost, it's actually quite amusing.

 
Shoutout to @chiobu 's home turf for linking the list. Worry not, you don't need to go to a website like https://sizeof.cat/post/tsa-nofly-list-download to get a couple dodgy ZIP files to get the actual CSVs. I've attached them here. SELECTEE=increased scrutiny NOFLY=no fly list. Not archiving URLs since it's commentary and whatever the fuck sizeof.cat is. Edit: too beeg for excel to open... I have Access for my own use but that's unhelpful for sharing, someone who actually knows DBs could probably sort something out.
 

Attachments

Shoutout to @chiobu 's home turf for linking the list. Worry not, you don't need to go to a website like https://sizeof.cat/post/tsa-nofly-list-download to get a couple dodgy ZIP files to get the actual CSVs. I've attached them here. SELECTEE=increased scrutiny NOFLY=no fly list. Not archiving URLs since it's commentary and whatever the fuck sizeof.cat is. Edit: too beeg for excel to open... I have Access for my own use but that's unhelpful for sharing, someone who actually knows DBs could probably sort something out.

I used the CSV Viewer Online to open the 70+ mb file and it loads pretty fast and fine: https://csv-viewer-online.github.io/

I also tried one of those fancy spreadsheet web applications but I had to split the file into 3 and the application is still trying to import the first file 🤣
 
Very cool, thank you @BelUwUga
To help people search these, you can use grep or ripgrep to "ctrl+f" them very quickly. Grep is on Mac already, Windows users can set up WSL or use a Linux virtual machine.
Windows also has findstr which is probably fine but I can't attest to its performance which is probably negligible.

How many "Mohammad"'s in each file?
SELECTEE.csv:8,884
NOFLY.csv:35,478

The youngest people have dates of birth in 2015. The absolute youngest listed as being born Jan 1, 2015. Mohamed, Mohamed, and Muhammed.
The oldest has/have dates of birth in 1921. There are 10 January 1st, 1921 birthdays, though they appear to all be variations of the same person. A Mohammed.
 
The troon that posted this also has posted this now
this file ("Deutsch emails") contains the complete source of email threads for the 2023-03-08 Mother Jones story “Inside the Secret Working Group That Helped Push Anti-Trans Laws Across the Country”. the emails are comprised of communications spanning 2019-2021 principally regarding an attempt to pass a trans youth transition treatment ban in south dakota in 2019, spearheaded by republican rep. fred deutsch and sen. lee schoenbeck.

there are extensive discussions between deutsch and notorious anti-gay and anti-trans “experts” associated with known hate groups targeting transgender healthcare in the united states, including dr. quentin l. van meter and dr. michelle cretella of the catholic medical association, dr. andre van mol of the christian medical & dental associations and american college of pediatricians, dr. michael k. laidlaw of the kelsey coalition, dr. william j. malone of the society for evidence-based gender medicine, dr. paul w. hruz of the national catholic bioethics center, laura haynes of narth, and deacon dr. patrick w. lappert of catholic reparative therapy group courage international. participants discuss crafting their language to avoid acknowledging that transgender people exist, constructing new ways to define doctors as criminals for providing gender-affirming care, and targeting a federal agency publication that correctly points out the dangers of anti-gay conversion therapy. their emails frequently digress into personal vendettas and ambitions of destroying established professional groups such as the endocrine society, and they typically celebrate their anti-trans legal and political achievements as a victory of the christian god.

the emails describe a wider national effort against transition treatment for minors, which included discussions with idaho rep. julianne young and sen. steve vick, georgia rep. ginny earhart, and florida rep. anthony sabatini. several anti-lgbt conservative legal groups are intimately involved in the discussion, including alliance defending freedom, adf-affiliated detransitioners hacsi horvath and walt heyer, eunie smith of eagle forum, adf-linked attorney vernadette r. broyles of the child & parental rights campaign, jane robbins of the american principles project, kara dansky and natasha chart of women’s liberation front, richard mast of liberty counsel, and emily zinos of minnesota family council and hands across the aisle. more recently, the transphobia-captured state of alabama harassed the endocrine society and wpath with subpoenas for their internal communications regarding hate groups and individuals participating in the deutsch emails, including segm, the american college of pediatricians, michael laidlaw, william malone, andre van mol, michelle cretella, and quentin van meter. the release of the deutsch emails is in the public interest and brings an equivalent level of transparency to the internal work of these major anti-trans advocacy and lobbying groups.

CLARIFICATION: i, maia, am not the source of this email leak, merely a publisher, since i feel that this should be more widely available than just to selected journalists

if you liked this or any of my other work feel free to support me on my ko-fi. i am unemployed and poor and do this work for free because i enjoy it, so anything goes a long way.
 
And of course its not him who stole the actual emails, but he merely publishes them for clout and then adds in a disclaimer "teehee, no it wasn't me who did the hard work I'm just the publisher guys uwu". :story:
 
  • Like
Reactions: Wright
Back