From my experience the travel industry are the worst offenders of data security. I remember making booking on booking.com and not having to pay for my booking, and I wondered how hotels can confirm bookings, when I went to check in at the hotel I asked this question to the front desk staff, and they simply told me “oh we get a fax or email from the OTA of your credit card information”. You can imagine the look on my…
How Airlines don’t care about privacy: Case Study Emirates.com
141–150 of 177 posts
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#142Earlier quoted context omitted.
> malicious party Which one? Google, Twitter, Facebook, Microsoft, Yahoo, Crazy Egg, Criteo or NSA listening on the wire? My apologies if you disagree, but I feel that the article is borderline alarmist and I believe is written in the worst possible tone to communicate the problem. Yup, there is a shitton of analytics products. Yes, PII is leaked and this needs to be fixed. But, no, it's not like listed parties (BTW,…
You missed the part where it's unencrypted HTTP traffic. So, any 'malicious party' sitting at a café with free wifi.
And it's not just "any party sitting at a cafe". It specifically requires that this malicious party is sitting in the same cafe, present (physically or remotely) at the moment the site is accessed. So it's more likely to be an airport's WiFi network - which is much more probably place where an unsuspecting traveler may access such page. Hunting for a cafe with someone buying tickets from a specific airline is probably too complicated to pay off, unless the attack is personal.
Anyway, I don't argue this is all very bad. It is. What I want to say is that the problem was communicated in a very poor way. And even this follow-up blog article is so light on details, a person without some security knowledge would quite likely shrug it off with an impression it's some tinfoil-hatter screaming at analytics trackers.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#143Re: How Airlines don’t care about privacy: Case Study Emirates.com
#144it raises a larger question in the industry such as what kind of internal protection do companies such as "Amadeus IT Group" have in place to prevent employees from sifting through passengers etix[¹] booking data? I had the opportunity to witness a data-scientist being able to tap into life itinerary data-stream, set up listeners and filter out anything they liked. ¹ https://en.wikipedia.org/wiki/Etix
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#145Earlier quoted context omitted.
This is why we should stop quoting that all the time. Just because you are paying for a product does not prevent your data from being sold or used in unethical ways.
The quote is not wrong. If you aren't paying for something, then 100% of the time you are the product. If you are paying for something, then <100% of the time you are also the product.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#146Earlier quoted context omitted.
Sending credit cards via FAX to be printed out is not only OK with PCI DSS, it's recommended. The reason companies like Booking.com do this is because the credit card companies wanted it this way.
I remember having a chat with a small guesthouse owner a few years ago, he showed me what the OTA sent through to them which was clear copy text of the booking along with all the credit card details. The big online OTA would directly charge the customer 15% deposit if I remember correctly which they banked as their commission - kind of clever removing the big remittance headache. It was then down the hotel to directl…
Ultimately it's the credit card companies that regulate this playing field, and up to a certain point they're happy to make a large trade-off between security & convenience, because they can work the security issues into their processing fees.
Credit card companies aren't dumb, of course they know that small Mom & Pop hotels are going to have horrible security practices when it comes to credit cards. They also know that any security issues are going to be contained to the customers of that establishment.
This is why PCI puts a huge amount compliance burden on companies such as payment processors and travel agencies that process a lot of credit cards, but by-and-large ignore small players.
The hotelier you described and his method of ad-hoc charging credit cards with a 10% fee at some unrelated business is surely in violation of some PCI rule(s), but that's going to be a matter between his customers and his bank, not all customers of the travel agency and Visa/MasterCard.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#147Earlier quoted context omitted.
But Wikipedia is run by a non-profit organization...
I'd say the more direct response is that with Wikipedia there is no product, in that sense of the word.
Does Encyclopedia Britannica's website "britannica.com" have a product? Is Encarta a product? Of course they are, and so is Wikipedia, unless BY DEFINITION you exclude any "product" not exchanged for money from the definition of "product". And by that definition, the second can of beans I got at the grocery store on a buy-one-get-one-free sale wasn't a product -- which I feel demolishes the usefulness of the term.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#148Earlier quoted context omitted.
I tested going to a https link via gmail. On desktop chrome, it immediately opens the link (and hence passes the link parameters). On mobile it pops up a privacy error, "Attackers might be trying to steal your information" (NET::ERR_CERT_COMMON_NAME_INVALID), which is certainly the right thing to do. Still have to try it on Office365 and Outlook.
Strange, I always encounter `NET::ERR_CERT_COMMON_NAME_INVALID` even on Gmail with Chrome. What's your test setup?
I checked firefox and it works correctly too.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#149Earlier quoted context omitted.
As much as I agree with you that we seriously have got to stop trotting out that quote all the time, the quote doesn't necessarily preclude what you point out. According to the quote, if you don't pay for it, you're definitely the product, but clearly, as you mention, just because you pay for it doesn't mean you're still not the product. Unfortunately.
That quote is a lazy-soudbite-argument that "you shouldn't use free services" (because "you're the product" and that's "obviously" bad). However, if you stop to think about it for a second, you'll realize that it's dead wrong. It sounds nice & all, but it is in fact meaningless, and probably misguiding.
It is a cheap and easy way to explain to non-technical people that when something is "free" the provider is getting something back. Payment for advertising to you, collected data from you, and so on. If you(general) understand that, and are OK with that, then continue. But don't be naive.
Re: How Airlines don’t care about privacy: Case Study Emirates.com
#150I had a coworker who was flying to Morocco (I forget what airline). He called me over to his desk at some point to show me the screen as he was picking out his seat. By each occupied seat was a headshot of the passenger, pulled from what I assume was their Facebook profile. It was amazingly creepy.