Live data from Hacker News

How Airlines don’t care about privacy: Case Study Emirates.com

medium.com

131–140 of 177 posts

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#131
Emirates.com has changed a lot in the 18 years since I last worked on it. But I can see how this might have come about.

Each 3rd party add-on is probably required by marketing in one form or another (analytics, social sharing, partner data, advertising, ). And possibly development has been done just thinking about how to do something, rather than if they should be doing something. We don't know what the gatekeepers have managed to prevent getting deployed...

Part of how I see my role is to always to have a product-owner sanity-check hat on. But at the end of the day, it's the people with the wallets who decide what gets included in their outcome, even if it's against the recommendations of experts.

Commercial reality sometimes trumps common sense.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#132
post #118

Earlier quoted context omitted.

I don't pay for wikipedia (actually I do via donations and edits but that's not the point) but I don't see anything bad about their BM.

But Wikipedia is run by a non-profit organization...

I'd say the more direct response is that with Wikipedia there is no product, in that sense of the word.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#133
post #125

Earlier quoted context omitted.

It's not just that. It's the airlines' means for complying with a specific federal law as well. https://www.law.cornell.edu/cfr/text/14/91.21 The reason that different airlines have different rules, is that their OpSpecs have different (and sometimes evolving) treatment on portable electronic devices, which is their way, as operators, of complying with § 91.21 (shared because I suspect some will find it interesting i…

Yes, and I would add some (hopefully) "common sense" consideration. IF you were a captain, responsible for a several millions dollar aircraft and for hundreds of lives, AND IF there was a teeny-tiny, extremely low probability that using a phone (or computer or other electronic device) could cause a disaster, including the possibility of a suicide act of sabotage, how would you implement in practice the Federal Rule y…

#1 clearly, or perhaps switched off below 10K feet MSL.

Try #2 and you find yourself unemployed as a captain. Try it as an airline and you find yourself without passengers and shortly, without an airline.

Airlines and aviation authorities balance safety, cost, and convenience all the time. ETOPS is a good example of that balance evolving. ETOPS-240 would have been unthinkable at the start of the jet age.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#134
post #13

I oftentimes reach for my 'call the regulator' button when I read these articles. Whats odd is how many people say "god no..." as if there was some consequential downside to using the very government entity we created (in law) to make corporate entities "do the right thing" when they don't appear to want to do it voluntarily. So.. here we go. Explain to me, why we don't want to enact law to require (through regulatio…

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

I can only hope for the EU that their economic incentive remains strong enough to prevent foreign companies from totally pulling out, resulting in the EU market becoming bleaker and bleaker. And it's not even the current companies that I worry most about - they often have already invested too much to withdraw because of this - it's the new companies that may flat out refuse to enter the EU market.

The GDPR is yet another regulation that adds a lot of liability with the risk of huge fines for a foreign company. And while no regulation in itself is ever going to be enough of reason, it's the plethora of regulations that is, and the more it grows, the more companies will feel it reached the tipping point for them, which may result in either withdrawal or refusal to serve the EU market. If this proves true, EU citizens should expect to see a lot more of "We're sorry, this service is not available in your country" messages. And it's already pretty bad from what I've heard.

Note: I'm not saying Emirates will pull out because of this, they won't. I'm also NOT against the GDPR and I totally understand the need, I just wish it would be regulated on a more universal level. Same with copyright regulations.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#135

Nothing will happen until a malicious party ends up cancelling an entire flight’s worth of passengers and it starts costing them serious money and reputation. It’s a sad state of affairs when there is no ethical way to correct certain grossly unethical business practices.

> malicious party Which one? Google, Twitter, Facebook, Microsoft, Yahoo, Crazy Egg, Criteo or NSA listening on the wire? My apologies if you disagree, but I feel that the article is borderline alarmist and I believe is written in the worst possible tone to communicate the problem. Yup, there is a shitton of analytics products. Yes, PII is leaked and this needs to be fixed. But, no, it's not like listed parties (BTW,…

You missed the part where it's unencrypted HTTP traffic. So, any 'malicious party' sitting at a café with free wifi.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#136
post #107

From my experience the travel industry are the worst offenders of data security. I remember making booking on booking.com and not having to pay for my booking, and I wondered how hotels can confirm bookings, when I went to check in at the hotel I asked this question to the front desk staff, and they simply told me “oh we get a fax or email from the OTA of your credit card information”. You can imagine the look on my…

Sending credit cards via FAX to be printed out is not only OK with PCI DSS, it's recommended. The reason companies like Booking.com do this is because the credit card companies wanted it this way.

I remember having a chat with a small guesthouse owner a few years ago, he showed me what the OTA sent through to them which was clear copy text of the booking along with all the credit card details. The big online OTA would directly charge the customer 15% deposit if I remember correctly which they banked as their commission - kind of clever removing the big remittance headache. It was then down the hotel to directly capture the remaining balance and enforce the cancellation rules. He explained that if customers don't turn up he takes the credit card details down to the road to a small independent unrelated travel agency which attempts to hit the card and charges him 10% for privilege, he says it's about 50/50 weather the card authorizes. I think this still happens.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#137
One funny thing is that Emirates makes it look like they do care about security by implementing a surprisingly onerous Captcha requirement before Skywards login. I usually get it wrong a couple of times before I can get to my account -- lots of 6s that might be Gs, partially obfuscated 8s that might be 3s, etc.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#138

Emirates.com has changed a lot in the 18 years since I last worked on it. But I can see how this might have come about. Each 3rd party add-on is probably required by marketing in one form or another (analytics, social sharing, partner data, advertising, ). And possibly development has been done just thinking about how to do something, rather than if they should be doing something. We don't know what the gatekeepers h…

Absolutely agree with you, having been a digital marketer and later Product Manager for an Airline, I realized the ill-effects of mindlessly using tools to "crack" the secret sauce of heightened UX and hence increased revenue stream. Would I do it today? No. Would a CMO push for third party trackers? Hell, Yes. The onus lies on CTO to evaluate products, third party tools against a checklist that also covers User-Data protection as one of the bullet points.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#139
post #105

Earlier quoted context omitted.

Even though they are not based out of EU and only operate in EU?

Where they are based doesn't matter. If they are collecting revenues (taking payments) from EU clients, it applies. That includes generating ad revenues from EU based eyeballs. When it comes to on-ad-generating, free websites, it remains to be seen how bold EU regulators get. It'll be hard to penalize or prosecute such websites, and there are enough violations in the fat cats anyway, so I'm guessing those free websit…

> That includes generating ad revenues from EU based eyeballs.

That would be fairly hard to enforce against a company that doesn't have a physical or legal presence in the EU.

In general, I'm disturbed by governments trying to enforce laws beyond their border just because their citizens are somehow involved by sending information over the internet. In some fields, it's a legal minefield just to comply with the rules of one country, much less several. This won't be a major difficulty for big players with high-paid lawyers and compliance departments, but it could easily kill startups, some before they're even launched.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#140
post #13

I oftentimes reach for my 'call the regulator' button when I read these articles. Whats odd is how many people say "god no..." as if there was some consequential downside to using the very government entity we created (in law) to make corporate entities "do the right thing" when they don't appear to want to do it voluntarily. So.. here we go. Explain to me, why we don't want to enact law to require (through regulatio…

I oftentimes reach for my 'call the regulator' button when I read these articles. And what regulator is that? Does Dubai even have a "regulator" overseeing stuff like this? Emirates is wholly owned by the government of Dubai. So basically you would be complaining about one Dubai government agency to another Dubai government agency. Perhaps you could complain about this to some US or EU regulator? Would they care enou…

Emirates has a physical presence in the EU and would definitely be subject to EU regulations when a flight to, from or purchased in the EU is involved.
Post reply on HN