Want to Access a Fancy Airport Lounge? Just Fake a QR Code.

At least, that's what one computer security expert did in order to access classier airport lounges in Europe.

By David Murphy

Shutterstock

This story originally appeared on PCMag

Tired of watching others waltz into those fancy airport lounges, to pamper themselves in luxury and comfort (and yummy food and drinks) while they wait for their next flights? Wish you had access to these areas? If you get creative with your QR code creation, like computer security expert Przemek Jaroszewski, then you can easily spoof your way into wherever you want.

At least, that's what Jaroszewski did when his frequent flier status glitched and he wasn't allowed admittance into one of the fancy airline lounges he knew he could otherwise access. His solution? Build an Android app that generates made-up QR codes, which contains his name (a fake one), as well as all the key details he needs to get into the lounges: upcoming flight numbers, his destinations and a status for whichever carrier's lounge he's trying to get into.

"While traveling through airports, we usually don't give a second thought about why our boarding passes are scanned at various places. After all, it's all for the sake of passengers' security. Or is it? The fact that boarding pass security is broken has been proven many times by researchers who easily crafted their passes, effectively bypassing not just 'passenger only' screening, but also no-fly lists," reads a description of Jaroszewski's talk at this year's Defcon conference.

"Since then, not only security problems have not been solved, but boarding passes have become almost entirely bar-coded. And they are increasingly often checked by machines rather than humans. Effectively, we're dealing with simple unencrypted strings of characters containing all the information needed to decide on our eligibility for fast lane access, duty-free shopping, and more…"

As Wired reports, Jaroszewski has only tested his QR-based spoofing in European airports. And, of course, his trick would be easily defeated by any airport lounge that asks to see a passport or other form of identification to verify that he's actually who he is listing with the QR code. Though he could use his real name to thwart that, he would also have to make sure that the airline lounge doesn't cross-reference his details against a master list of eligibility.

In other words, there are plenty of things that can go wrong with his little trick. And, no, he's not using it to try and board flights under a different name; he surmises that the security checks are too strong to allow him to do that (nor would he want to).

He's also not releasing his little QR-creating code to the public. You'll just have to earn your elite status the hard way.

Related Topics

Editor's Pick

Everyone Wants to Get Close to Their Favorite Artist. Here's the Technology Making It a Reality — But Better.
The Highest-Paid, Highest-Profile People in Every Field Know This Communication Strategy
After Early Rejection From Publishers, This Author Self-Published Her Book and Sold More Than 500,000 Copies. Here's How She Did It.
Having Trouble Speaking Up in Meetings? Try This Strategy.
He Names Brands for Amazon, Meta and Forever 21, and Says This Is the Big Blank Space in the Naming Game
Business News

These Are the Most and Least Affordable Places to Retire in The U.S.

The Northeast and West Coast are the least affordable, while areas in the Mountain State region tend to be ideal for retirees on a budget.

Business News

I Live on a Cruise Ship for Half of the Year. Look Inside My 336-Square-Foot Cabin with Wraparound Balcony.

I live on a cruise ship with my husband, who works on it, for six months out of the year. Life at "home" can be tight. Here's what it's really like living on a cruise ship.

Business News

American Airlines Sued After Teen Dies of Heart Attack Onboard Flight to Miami

Kevin Greenridge was traveling from Honduras to Miami on June 4, 2022, on AA Flight 614 when he went into cardiac arrest and became unconscious mid-flight.

Thought Leaders

The Collapse of Credit Suisse: A Cautionary Tale of Resistance to Hybrid Work

This cautionary tale serves as a reminder for business leaders to adapt to the changing world of work and prioritize their workforce's needs and preferences.

Business Solutions

Learn to Build a ChatGPT Bot for Only $30

If you want to see what AI can do for your business, grab this course bundle today.