Live data from Hacker News

How Airlines don’t care about privacy: Case Study Emirates.com

medium.com

101–110 of 177 posts

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#101
post #98
post #84

That's pretty bad, but frankly he could have communicated better to Emirates. If I was working as first line support and received that message with "omg do you know you are sharing fields a, b and c to partners. And maybe you are sharing with x, y and z also?" , without any technical details at all, I would also give a canned response, tag it as tinfoil hat and throw it into the junk.

Proper first-line support setup makes the staff send any queries they don't understand to higher levels, not throw away.

The new thing now even with big travel booking companies is to have one tier of phone support that can literally only provide canned answers, and a very difficult to get to escalation to an email team that will give you a canned answer.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#102
it raises a larger question in the industry such as what kind of internal protection do companies such as "Amadeus IT Group" have in place to prevent employees from sifting through passengers etix[¹] booking data?

I had the opportunity to witness a data-scientist being able to tap into life itinerary data-stream, set up listeners and filter out anything they liked.

¹ https://en.wikipedia.org/wiki/Etix

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#103
post #47

These magic URLs that can log you in automatically, generally ought to necessitate a very high degree of paranoia from whoever is implementing them. In this case the single point of failure seems like the leaky referrer, which ought to have been noticed as part of the aforementioned paranoia. I guess the problem here is that from an overall experience POV you want users to be able to get to their booking from their e…

ublock is fully functional in firefox mobile on android. I use it since v57, do not know how it was before that.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#105
post #13

I oftentimes reach for my 'call the regulator' button when I read these articles. Whats odd is how many people say "god no..." as if there was some consequential downside to using the very government entity we created (in law) to make corporate entities "do the right thing" when they don't appear to want to do it voluntarily. So.. here we go. Explain to me, why we don't want to enact law to require (through regulatio…

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

Even though they are not based out of EU and only operate in EU?

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#106
post #47

These magic URLs that can log you in automatically, generally ought to necessitate a very high degree of paranoia from whoever is implementing them. In this case the single point of failure seems like the leaky referrer, which ought to have been noticed as part of the aforementioned paranoia. I guess the problem here is that from an overall experience POV you want users to be able to get to their booking from their e…

Installing uBlock Origin on mobile Firefox is trivial.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#107

From my experience the travel industry are the worst offenders of data security. I remember making booking on booking.com and not having to pay for my booking, and I wondered how hotels can confirm bookings, when I went to check in at the hotel I asked this question to the front desk staff, and they simply told me “oh we get a fax or email from the OTA of your credit card information”. You can imagine the look on my…

Sending credit cards via FAX to be printed out is not only OK with PCI DSS, it's recommended. The reason companies like Booking.com do this is because the credit card companies wanted it this way.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#108
post #105

Earlier quoted context omitted.

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

Even though they are not based out of EU and only operate in EU?

Yes, the GDPR affects everyone who processes data of people in the EU, regardless of where they are based.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#109
post #105

Earlier quoted context omitted.

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

Even though they are not based out of EU and only operate in EU?

When you operate a business somewhere, you have to observe the laws of the place you do business in. It does not matter where you are based.

How someone gets a hold of you to enforce any action against you is a different matter. But Emirates kind of needs to come to the EU sometimes to do its business there.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#110
post #16
post #11

Has anyone heard of an exploit that sets people's flights to use the attackers frequent flyer number, thus collecting their miles?

No, because in most cases the program requires the passenger's name to match the FF account name.

a lot of FF programmes allow transferring of miles
Post reply on HN