That's pretty bad, but frankly he could have communicated better to Emirates. If I was working as first line support and received that message with "omg do you know you are sharing fields a, b and c to partners. And maybe you are sharing with x, y and z also?" , without any technical details at all, I would also give a canned response, tag it as tinfoil hat and throw it into the junk.
Proper first-line support setup makes the staff send any queries they don't understand to higher levels, not throw away.
How Airlines don’t care about privacy: Case Study Emirates.com
101–110 of 177 posts
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#102I had the opportunity to witness a data-scientist being able to tap into life itinerary data-stream, set up listeners and filter out anything they liked.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#103These magic URLs that can log you in automatically, generally ought to necessitate a very high degree of paranoia from whoever is implementing them. In this case the single point of failure seems like the leaky referrer, which ought to have been noticed as part of the aforementioned paranoia. I guess the problem here is that from an overall experience POV you want users to be able to get to their booking from their e…
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#104Re: How Airlines don’t care about privacy: Case Study Emirates.com
#105I oftentimes reach for my 'call the regulator' button when I read these articles. Whats odd is how many people say "god no..." as if there was some consequential downside to using the very government entity we created (in law) to make corporate entities "do the right thing" when they don't appear to want to do it voluntarily. So.. here we go. Explain to me, why we don't want to enact law to require (through regulatio…
Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#106These magic URLs that can log you in automatically, generally ought to necessitate a very high degree of paranoia from whoever is implementing them. In this case the single point of failure seems like the leaky referrer, which ought to have been noticed as part of the aforementioned paranoia. I guess the problem here is that from an overall experience POV you want users to be able to get to their booking from their e…
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#107From my experience the travel industry are the worst offenders of data security. I remember making booking on booking.com and not having to pay for my booking, and I wondered how hotels can confirm bookings, when I went to check in at the hotel I asked this question to the front desk staff, and they simply told me “oh we get a fax or email from the OTA of your credit card information”. You can imagine the look on my…
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#108Earlier quoted context omitted.
Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.
Even though they are not based out of EU and only operate in EU?
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#109Earlier quoted context omitted.
Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.
Even though they are not based out of EU and only operate in EU?
How someone gets a hold of you to enforce any action against you is a different matter. But Emirates kind of needs to come to the EU sometimes to do its business there.