But... but do I really need all this security with an airline website? What's the worst thing someone can do with my account? Buy me a ticket? See my address? Or I am just extremely naive?
United Airlines’ so-called online security (2016)
31–40 of 41 posts
Re: United Airlines’ so-called online security (2016)
#32I've often read discussion about how you can't regulate this sort of thing because the industry moves so fast that what's a best practice today can be tomorrow's horrible security (then enforced by law). But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easil…
Insurance premiums of all types are based on risk factors, so the policy would be written against a checklist of best practices.
Similar to how having a fire extinguisher in your kitchen reduces your home insurance premiums by small percentage, the same could be said for each security practice. Encrypted passwords: -2%. Mandatory 2FA in place: -3%. Etc.
Re: United Airlines’ so-called online security (2016)
#33You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…
Re: United Airlines’ so-called online security (2016)
#34But... but do I really need all this security with an airline website? What's the worst thing someone can do with my account? Buy me a ticket? See my address? Or I am just extremely naive?
If you have stored credit cards, they can buy tickets for anyone. They can change existing reservations. They can steal your passport number. All sorts of things.
Re: United Airlines’ so-called online security (2016)
#35Earlier quoted context omitted.
If you have stored credit cards, they can buy tickets for anyone. They can change existing reservations. They can steal your passport number. All sorts of things.
But whoever buys a ticket will have to provide his passport information, surely not something a hacker wants to do?
Re: United Airlines’ so-called online security (2016)
#36I know they have fought quite a bit of mileage theft out of a number of countries and they thought this was a good idea of doing that but it's awful.
Re: United Airlines’ so-called online security (2016)
#37Earlier quoted context omitted.
Thanks for sharing your experience. No one wants innocent peoples' data to be compromised, but maybe your story will do something to discourage others from participating, and United will feel the consequences as a result. Having a bug bounty program is one thing; standing behind it is another. Is there a ranking of bug bounty programs in terms of ease of use, good faith, etc?
It's never good to have bugs in the wild that could risk customer information. I want to see United shape up, but I don't want regular guys to suffer for it.
Re: United Airlines’ so-called online security (2016)
#38Earlier quoted context omitted.
But whoever buys a ticket will have to provide his passport information, surely not something a hacker wants to do?
You would be surprised. I work at an airline fraud prevention platform, and the legal hassle with credit card/loyalty fraud (which is what this would be) is so complex that fraudsters are often not charged with fraud. They just go ahead and provide their real information. Or change it right before takeoff at the airport, leaving the fraud analysts with no time.
Re: United Airlines’ so-called online security (2016)
#39Earlier quoted context omitted.
It's never good to have bugs in the wild that could risk customer information. I want to see United shape up, but I don't want regular guys to suffer for it.
If people aren't going to be given the reward they deserve for all the work they put in, why should any of them help United? It isn't a free service.
Re: United Airlines’ so-called online security (2016)
#40Earlier quoted context omitted.
If people aren't going to be given the reward they deserve for all the work they put in, why should any of them help United? It isn't a free service.
Am I forcing them to by not wanting there to be a United data leak? What kind of reasoning is that?