Live data from Hacker News

How Airlines don’t care about privacy: Case Study Emirates.com

medium.com

141–150 of 177 posts

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#141

From my experience the travel industry are the worst offenders of data security. I remember making booking on booking.com and not having to pay for my booking, and I wondered how hotels can confirm bookings, when I went to check in at the hotel I asked this question to the front desk staff, and they simply told me “oh we get a fax or email from the OTA of your credit card information”. You can imagine the look on my…

Booking.com literally became successful because they build this massive infrastructure around European hotels that refused to update their booking systems past fax and phone calls

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#142

Earlier quoted context omitted.

> malicious party Which one? Google, Twitter, Facebook, Microsoft, Yahoo, Crazy Egg, Criteo or NSA listening on the wire? My apologies if you disagree, but I feel that the article is borderline alarmist and I believe is written in the worst possible tone to communicate the problem. Yup, there is a shitton of analytics products. Yes, PII is leaked and this needs to be fixed. But, no, it's not like listed parties (BTW,…

You missed the part where it's unencrypted HTTP traffic. So, any 'malicious party' sitting at a café with free wifi.

So did the message to the support, screenshotted in the article.

And it's not just "any party sitting at a cafe". It specifically requires that this malicious party is sitting in the same cafe, present (physically or remotely) at the moment the site is accessed. So it's more likely to be an airport's WiFi network - which is much more probably place where an unsuspecting traveler may access such page. Hunting for a cafe with someone buying tickets from a specific airline is probably too complicated to pay off, unless the attack is personal.

Anyway, I don't argue this is all very bad. It is. What I want to say is that the problem was communicated in a very poor way. And even this follow-up blog article is so light on details, a person without some security knowledge would quite likely shrug it off with an impression it's some tinfoil-hatter screaming at analytics trackers.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#144

it raises a larger question in the industry such as what kind of internal protection do companies such as "Amadeus IT Group" have in place to prevent employees from sifting through passengers etix[¹] booking data? I had the opportunity to witness a data-scientist being able to tap into life itinerary data-stream, set up listeners and filter out anything they liked. ¹ https://en.wikipedia.org/wiki/Etix

Having worked with Amadeus IT products for airlines, I can tell you this - they are the most regressive "IT" products available in the world.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#145

Earlier quoted context omitted.

This is why we should stop quoting that all the time. Just because you are paying for a product does not prevent your data from being sold or used in unethical ways.

The quote is not wrong. If you aren't paying for something, then 100% of the time you are the product. If you are paying for something, then <100% of the time you are also the product.

What of Linux?

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#146
post #107

Earlier quoted context omitted.

Sending credit cards via FAX to be printed out is not only OK with PCI DSS, it's recommended. The reason companies like Booking.com do this is because the credit card companies wanted it this way.

I remember having a chat with a small guesthouse owner a few years ago, he showed me what the OTA sent through to them which was clear copy text of the booking along with all the credit card details. The big online OTA would directly charge the customer 15% deposit if I remember correctly which they banked as their commission - kind of clever removing the big remittance headache. It was then down the hotel to directl…

This definitely still happens, but I think implicit in your post and this thread in general is the unstated statement "...and this is a horrible state of affairs that shouldn't persist for even one more day!".

Ultimately it's the credit card companies that regulate this playing field, and up to a certain point they're happy to make a large trade-off between security & convenience, because they can work the security issues into their processing fees.

Credit card companies aren't dumb, of course they know that small Mom & Pop hotels are going to have horrible security practices when it comes to credit cards. They also know that any security issues are going to be contained to the customers of that establishment.

This is why PCI puts a huge amount compliance burden on companies such as payment processors and travel agencies that process a lot of credit cards, but by-and-large ignore small players.

The hotelier you described and his method of ad-hoc charging credit cards with a 10% fee at some unrelated business is surely in violation of some PCI rule(s), but that's going to be a matter between his customers and his bank, not all customers of the travel agency and Visa/MasterCard.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#147
post #118

Earlier quoted context omitted.

But Wikipedia is run by a non-profit organization...

I'd say the more direct response is that with Wikipedia there is no product, in that sense of the word.

There most certainly IS a product! The only way I can imagine that you came to believe there wasn't is that you were confused by the fact that they give their product away.

Does Encyclopedia Britannica's website "britannica.com" have a product? Is Encarta a product? Of course they are, and so is Wikipedia, unless BY DEFINITION you exclude any "product" not exchanged for money from the definition of "product". And by that definition, the second can of beans I got at the grocery store on a buy-one-get-one-free sale wasn't a product -- which I feel demolishes the usefulness of the term.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#148
post #56

Earlier quoted context omitted.

I tested going to a https link via gmail. On desktop chrome, it immediately opens the link (and hence passes the link parameters). On mobile it pops up a privacy error, "Attackers might be trying to steal your information" (NET::ERR_CERT_COMMON_NAME_INVALID), which is certainly the right thing to do. Still have to try it on Office365 and Outlook.

Strange, I always encounter `NET::ERR_CERT_COMMON_NAME_INVALID` even on Gmail with Chrome. What's your test setup?

Doh, you're right. I looked at the site earlier and forgot to click on the red triangle and click "re-enable warnings". Mea culpa.

I checked firefox and it works correctly too.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#149
post #99

Earlier quoted context omitted.

As much as I agree with you that we seriously have got to stop trotting out that quote all the time, the quote doesn't necessarily preclude what you point out. According to the quote, if you don't pay for it, you're definitely the product, but clearly, as you mention, just because you pay for it doesn't mean you're still not the product. Unfortunately.

That quote is a lazy-soudbite-argument that "you shouldn't use free services" (because "you're the product" and that's "obviously" bad). However, if you stop to think about it for a second, you'll realize that it's dead wrong. It sounds nice & all, but it is in fact meaningless, and probably misguiding.

I've thought about it for several seconds and don't see what is wrong with the quote.

It is a cheap and easy way to explain to non-technical people that when something is "free" the provider is getting something back. Payment for advertising to you, collected data from you, and so on. If you(general) understand that, and are OK with that, then continue. But don't be naive.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#150

I had a coworker who was flying to Morocco (I forget what airline). He called me over to his desk at some point to show me the screen as he was picking out his seat. By each occupied seat was a headshot of the passenger, pulled from what I assume was their Facebook profile. It was amazingly creepy.

isn't this mostly so you don't accidentally end up sitting next to a woman who isn't your wife?
Post reply on HN