Live data from Hacker News

United Airlines’ so-called online security (2016)

techcrunch.com

11–20 of 41 posts

Re: United Airlines’ so-called online security (2016)

#11
post #8

I've often read discussion about how you can't regulate this sort of thing because the industry moves so fast that what's a best practice today can be tomorrow's horrible security (then enforced by law). But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easil…

This kind of law would be very ineffective as they need to grand-father previously built applications and so enforcement becomes very complicated and only practical in data-breach scenarios, so might as well make laws that fines for data breach in relations to non-zero day and neglect of security by industry standards (I know it when I see it, expert opinion, et al).

That is, don't legislate implementation but consequences.

Re: United Airlines’ so-called online security (2016)

#12
post #10
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

For what it's worth, such password schemes usually include lockouts after small-N tries to prevent the passwords from being brute-forced from the outside, and an attacker with database-level access is probably going to use it not to compromise passwords but to directly change balances. Not to excuse such password schemes - they're horrible, and banks need to get with the times - but if they were really so ineffective…

Full write access to a database is a totally different thing than reading out the plaintext passwords or getting a leaked dump of the data. Perhaps a mishandled backup.

Re: United Airlines’ so-called online security (2016)

#13
> Two-factor authorization has a specific meaning: ...

Well that was the worst place the author could have mixed up authorization and authentication...

In fact, he seems to use authorization and authentication pretty much interchangeably, which kind of undermines his rant a bit...

Re: United Airlines’ so-called online security (2016)

#14
post #11
post #8

I've often read discussion about how you can't regulate this sort of thing because the industry moves so fast that what's a best practice today can be tomorrow's horrible security (then enforced by law). But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easil…

This kind of law would be very ineffective as they need to grand-father previously built applications and so enforcement becomes very complicated and only practical in data-breach scenarios, so might as well make laws that fines for data breach in relations to non-zero day and neglect of security by industry standards (I know it when I see it, expert opinion, et al). That is, don't legislate implementation but conseq…

They don't need to grandfather anything - it's similar to the GDPR in the sense that you can give companies time to prepare, and then it comes into force.

Prepare the law, give companies 3-5 years to prepare, and after that, anything is fair game. If your company is accepting plaintext passwords there should be something that makes you say "oh we have 3 years to change this, let's hire someone to fix this". If a system is live and in use, it -should- follow some -minimal- standards for security.

That doesn't preclude your data breach fine idea - that'd be useful for more advanced security situations that can't be predicted (as you said, based on expert opinions).

But something as basic as "you're not allowed to pretend it's 2FA if it's just password + questions" or "you're not allowed to store passwords in plaintext", that sort of thing should be the minimal baseline that companies should have to adhere to, surely.

Re: United Airlines’ so-called online security (2016)

#15
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

I never realized that my bank (Desjardins) was not recognizing the case sensibility.

Do you have a source about the plain text passwords claim? I won't even be surprised if that's true.

Re: United Airlines’ so-called online security (2016)

#16
post #2

https://krebsonsecurity.com/2016/08/united-airlines-sets-min... United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers. This has been in place for 3 years despite public shaming.

I'm stuck flying United most of the time and I get the sense their cybersecurity posture is consistent with their broader business posture: "If you do nothing, nothing will happen. If something external forces change, deny, deny, deny." Very old school. In all the worst ways.

Does this mean that United Airlines is still using the inadequate system described in the article? In my opinion, public shaming is the last resort: when you tried everything and failed to make your legitimate concerns about cyber-security heard by the company, you go public and hope that the bad press creates some kind of PR issue... But what if it doesn't? What if the public shaming proves useless? What can be done then?

Re: United Airlines’ so-called online security (2016)

#17
post #15
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

I never realized that my bank (Desjardins) was not recognizing the case sensibility. Do you have a source about the plain text passwords claim? I won't even be surprised if that's true.

From people I know who've interacted with the customer service representatives, in particularly weird/complicated situations once you've reached the second or third tier of people who resolve unusual problems, and authenticated yourself, it's possible to get them to read back your own password to you.

Re: United Airlines’ so-called online security (2016)

#18
post #8

I've often read discussion about how you can't regulate this sort of thing because the industry moves so fast that what's a best practice today can be tomorrow's horrible security (then enforced by law). But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easil…

You can regulate by having legislation that has 2 components. One is the law that such companies have to follow best practices. Second, best practices are created and published by a set of companies who have the best record of implementing security correctly, or even having security professionals (and there are many well respected security experts who can do this since they talk about it on their blogs all the time).

Re: United Airlines’ so-called online security (2016)

#20
post #16

Earlier quoted context omitted.

I'm stuck flying United most of the time and I get the sense their cybersecurity posture is consistent with their broader business posture: "If you do nothing, nothing will happen. If something external forces change, deny, deny, deny." Very old school. In all the worst ways.

Does this mean that United Airlines is still using the inadequate system described in the article? In my opinion, public shaming is the last resort: when you tried everything and failed to make your legitimate concerns about cyber-security heard by the company, you go public and hope that the bad press creates some kind of PR issue... But what if it doesn't? What if the public shaming proves useless? What can be done…

"boycott"? you can quit flying with them, but individuals doing this will have pretty much 0 effect. in many cases, a specific airline may be the only practical way to get from A to B, so you're generally stuck. This is even more grating on me when I fly and hear "we know you have a choice, thank you for flying with _____ today!". No, really, most of the time, I don't have much of a choice. Drive 7 hours or spend 4 hours in airport. Fly ABC direct or DEF via 2 layovers. Neither are great choices (if they exist at all).
Post reply on HN