Archive for October 9, 2022

Lufthansa Has Banned AirTags In Luggage

Posted in Commentary with tags on October 9, 2022 by itnerd

According to Boing Boing, the German airline Lufthansa has banned AirTags in luggage:

Lufthansa argues that baggage trackers fall in the category of portable electronic devices, and are therefore subject to dangerous goods regulations issued by the International Civil Aviation Organization (ICAO). This is specifically because of the transmission function. Lufthansa claims that the transmission function needs to be turned off during flight when in checked luggage, just as is required for cell phones, laptops, etc.

And the airline’s twitter feed has seemingly confirmed this:

The Boing Boing article has an alternate view:

My first thought is that I’m not surprised to see Lufthansa be the first airline to add a ban like this. Lufthansa isn’t exactly a customer-friendly airline, and the airline has had an awful summer when it comes to lost bags (I even had a delayed Lufthansa bag experience). AirTags empower travelers in terms of knowing exactly where their bags are, and I imagine that’s something some airlines don’t actually like. If you look at Twitter, you’ll see a ton of people expressing frustration with Lufthansa because they know exactly where their checked bag is, while the airline refuses to help.

I’ve wondered why it took this long for an airline to do this. After all they don’t want to be called out on losing luggage seeing as lost luggage has become insanely common these days. So if they can find any excuse to ban AirTags, they will.

Here’s the other part of this, how will they enforce this? Are they going to come up with some sort of scanner to find them? And if they do find them, will they remove them or remove the passenger? Also does this also apply to Tile or Chipolo products? They do the same thing as AirTags, but don’t have the network that AirTags have. I guess that they’re not afraid of those products catching them out when it comes to losing passenger’s bags.

I’m pretty sure that AirTags will continue to be used by passengers, which will lead to more stories of passengers tracking their lost luggage and calling out airlines due to that. I’m also pretty sure that as this story gets out, Lufthansa will get a whole lot of bad press which may make them rethink this ban. And that will make other airlines think against doing something similar.

Meta Sues Chinese Developers Over Stealing Facebook Login Info

Posted in Commentary with tags on October 9, 2022 by itnerd

Earlier this week, I told you about Meta sending notifications to roughly a million people that they Facebook accounts were compromised by account login stealing malware that are in the Google Play Store and Apple App Store. Well, Meta has filed a lawsuit against several Chinese developers doing business as HeyMods, Highlight Mobi, and HeyWhatsApp for developing and deploying this malware starting May 2022. You can read the full details of the lawsuit here. But here are the highlights. According to Meta:

  • The threat actors created this malware and posted them on their own website, as well as the Google Play Store and other Android app download sites.
  • Once the apps were downloaded and installed, the users were prompted to enter their WhatsApp user credentials and authenticate their WhatsApp access on these applications.
  • The credentials were then sent to the threat actors.
  • Meta worked with Google to take out these apps.
  • Meta is suing the developers for breaching WhatsApp’s terms of use and Meta’s developer agreement.

Now I seriously doubt that Meta will get a cent from these developers as it is highly unlikely the Chinese government will assist a US court in holding its citizens responsible for something like this. But that’s not the point of this lawsuit. It’s meant to send a message that Meta will come after anyone who does anything to harm the company or its users. And I for one hope that this is the first of many lawsuits filed to go after threat actors like these as it will place pressure on the Chinese government to deal with these threat actors or risk losing respect in the international community.

UPS Is Being Used In An Email #Scam

Posted in Commentary with tags on October 9, 2022 by itnerd

UPS appears to the latest company that I’ve found that a threat actor has decided to use as part of an email scam. The email in question looks like this:

It appears to be from UPS, but the UPS logo is wrong. The quality of the English is also a #Fail as well as evidenced by phrases like “Your package was stopped at the distribution hub due to incomplete delivery informations.” The tracking number is also not consistent with the format that UPS uses. And finally, there’s the email address.

Clearly this isn’t a UPS email address.

Other than that, the colours that are used are pretty much on point. It won’t fool most people. But I can imagine that a few might fall of it.

So, what’s the endgame here for the threat actors? I can’t say as when I tried to access the site that was linked in the email, it didn’t appear. Perhaps someone already took it out or the threat actors have moved on? It’s hard to say. But I can safely say that if this email hits your inbox, delete it.