Live data from Hacker News

I was a senior VP of tech at Starwood: here’s my take on the guest data breach

phocuswire.com

21–30 of 61 posts

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#21
This is an exceptionally self-serving take on the matter at hand. So much so that it’s frankly breathtaking that it’s been upvoted to #1.

Dear Israel del Rio,

As a Mariott and SPG member since history, kindly focus on not disclaiming responsibility in a public forum, since you almost assuredly aren’t as innocent as you claim.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#22

This article seems full of points that a lay person might nod along with, yet don't hold up to scrutiny. > The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It does not mean that. It means that we don't know of any exploited vulnerabilities before that point. > If the detection tool was used prior to this September, why…

Your first point lacks context of the next paragraph. Here’s the two paragraphs combined which changes the meaning.

>The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years.

>It is difficult to imagine how an architectural or platform vulnerability would not have been discovered or exploited sooner.

He’s saying it’s most likely this exploit has been discovered earlier than 2014. This is even more aggressive than your point which was

>>It does not mean that. It means that we don't know of any exploited vulnerabilities before that point.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#23

This is an exceptionally self-serving take on the matter at hand. So much so that it’s frankly breathtaking that it’s been upvoted to #1. Dear Israel del Rio, As a Mariott and SPG member since history, kindly focus on not disclaiming responsibility in a public forum, since you almost assuredly aren’t as innocent as you claim.

Additionally, quit using this as a platform to promote your startup, you phony.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#24

"The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It is difficult to imagine how an architectural or platform vulnerability would not have been discovered or exploited sooner." Not really. There's been vulnerabilities that have been out in the wild for quite some time and took years to be found. Sometimes it just comes…

Don't disagree, but how much more insecure is Marriott to say, Motel 8?

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#25

This article seems full of points that a lay person might nod along with, yet don't hold up to scrutiny. > The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It does not mean that. It means that we don't know of any exploited vulnerabilities before that point. > If the detection tool was used prior to this September, why…

> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys. I worked some place where lots data was encrypted with a key. The key hadn't changed in months - at least 6 months by the time I found it. I was told this same key would be used to encrypt web session data in a cookie. There were more than a dozen people who I knew had access to the key,…

> The key hadn't changed in months - at least 6 months by the time I found it. I was told this same key would be used to encrypt web session data in a cookie. There were more than a dozen people who I knew had access to the key, and another 5 had come and gone (and had had access to the same key) in the previous 6 months.

What's so wrong with any of this?

Software requires operators and developers. If you can't trust them, you can't trust your service, period. It's normal for operators and developers to occasionally have access to sensitive data (e.g. when your service crashes, somebody has to look at the crash dump). Such access should be restricted (requiring approval) and logged, of course, but it's difficult to eliminate entirely at scale.

It's good to rotate keys on a regular basis - but an annual key rotation doesn't seem negligent to me for a key used to encrypt session data, which is necessarily long-lived.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#26
I'm amongst the most frequent guests at Starwood, spending >100 nights a year in their hotels. I wasn't thrilled when it was announced they'd be acquired by Marriott. This year, they began the switchover process to migrating to Marriott's technology, and the full switch officially happened in mid-August.

It was a complete and utter disaster.

Everything was buggy, points mysteriously disappeared, reservations disappeared. Inconsistent UI, a mix of old and new systems. A truly awful experience dealing with support agents who were incapable of comprehending what was happening. I'm still waiting for a handful of stays to be credited to my account months later and nobody can help me because the systems are broken.

I found myself staying mostly at Hyatt hotels while the dust settled. I'll end the year with another 100 nights with Starwood/Marriott, and 80 with Hyatt. But, given the direction the company has taken since the merger, that number will likely be going down on the Marriott side.

After hearing that Marriott laid off the majority of Starwood's technical staff before attempting this migration, I'm not surprised it went this way. I'm also very much inclined to believe that the data breach happened during this migration.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#27
post #17

Worth pointing out that at the time of this guy's tenure, and for many years afterwards, the way you authenticated yourself while booking a rewards reservation with SPG via the phone was to verbally tell the agent your online password. Like, WTF.

The SPG password for phone has been a different password from the web login password for as long as I can remember (2014?)

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#28

Earlier quoted context omitted.

> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys. I worked some place where lots data was encrypted with a key. The key hadn't changed in months - at least 6 months by the time I found it. I was told this same key would be used to encrypt web session data in a cookie. There were more than a dozen people who I knew had access to the key,…

> The key hadn't changed in months - at least 6 months by the time I found it. I was told this same key would be used to encrypt web session data in a cookie. There were more than a dozen people who I knew had access to the key, and another 5 had come and gone (and had had access to the same key) in the previous 6 months. What's so wrong with any of this? Software requires operators and developers. If you can't trust…

> Such access should be restricted (requiring approval) and logged, of course, but it's difficult to eliminate entirely at scale.

It’s not clear how you could practically enforce this requirement if devs just have the raw key on their workstations.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#29
post #5

There’s no meaningful security in travel companies. They share with everyone and controls are a joke. Hell, Hilton allowed for 4-digit numeric passwords until a few years ago.

IHG (Holiday Inn, InterContinental) is still a 4 digit PIN and a numeric (or email) userid.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#30
This guy appears to have no clue what he is talking about, and is painfully ignorant of both security and technology.

I realize that’s not a very substantive comment, but wow.

”The Valhalla system was fully activated in 2009, and my understanding is that all best practices were followed in its design (firewalls, DMZs, encryption, etc.).”

”It is difficult to imagine how an architectural or platform vulnerability would not have been discovered or exploited sooner.”

”It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys.”

This is just painful to read from someone so senior on their soapbox. It’s probably exactly why they got hacked. Also note that this isn’t the first major starwood breach: https://www.starwoodhotels.com/html/HTML_Blocks/Corporate/Co...

Post reply on HN