Live data from Hacker News

Marriott says 5.2M guests exposed in new data breach

reuters.com

41–50 of 74 posts

Re: Marriott says 5.2M guests exposed in new data breach

#41

Earlier quoted context omitted.

I wonder if there will be a "data bubble" that will burst. I mean, I would imagine a TON of places have my birthday now. How valuable is that information really?

Whats to burst, storage is dirt cheap and they get their tiny data breach fines (if any) whether or not they store the color of your second dogs favorite chew toy with the rest of the info.

But that's exactly it - if it's so cheap, why is data so valuable?

Re: Marriott says 5.2M guests exposed in new data breach

#42
post #28

Earlier quoted context omitted.

In the US it is common now to swipe the driver’s license in order to verify age, at places as varied as bars and nightclubs, liquor stores, general shops that also sell liquor, and such. All you need to prove is your age, but the company that puts the scanner in place (in the case of bars and restaurants) collects all the info on the DL. Walgreens collects all the info and correlates it with your CC if you don’t pay…

I’m not aware of any major hotel brand that swipes driver’s licenses yet in the US.

Huh? I don't think I've ever checked into a hotel and not been asked to hand over my driver's license so the clerk can punch in a bunch of info from it onto their machine.

I assume it's to help them track you down if you cancel your credit card, trash the room, and flee.

Re: Marriott says 5.2M guests exposed in new data breach

#43

Earlier quoted context omitted.

Whats to burst, storage is dirt cheap and they get their tiny data breach fines (if any) whether or not they store the color of your second dogs favorite chew toy with the rest of the info.

But that's exactly it - if it's so cheap, why is data so valuable?

Storage is cheap, collecting the data is expensive. I mean this company had to run a national chain of hotels to collect this data. That's not easy.

Re: Marriott says 5.2M guests exposed in new data breach

#44
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

Name + DOB to disambiguate are the lookup keys they pass to data brokers to identify you, given a government ID (required to check in to a hotel). It gives them access to things like address history, email address history (for crosslinking of account records), credit rating, marketing channel tags, et c.

Same goes for the phone number that some website registrations demand. It's not to call you, it's to lookup your name and address and annual income.

Re: Marriott says 5.2M guests exposed in new data breach

#45
post #28

Earlier quoted context omitted.

In the US it is common now to swipe the driver’s license in order to verify age, at places as varied as bars and nightclubs, liquor stores, general shops that also sell liquor, and such. All you need to prove is your age, but the company that puts the scanner in place (in the case of bars and restaurants) collects all the info on the DL. Walgreens collects all the info and correlates it with your CC if you don’t pay…

I’m not aware of any major hotel brand that swipes driver’s licenses yet in the US.

The last hotel I stayed in, a W, did it as I checked in. And hmm, just realised they’re owned by Marriott.

Re: Marriott says 5.2M guests exposed in new data breach

#46
post #21
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

I often edit my birthday to coincide with my stays.

You could just travel on your bday :D

Re: Marriott says 5.2M guests exposed in new data breach

#47

Earlier quoted context omitted.

But that's exactly it - if it's so cheap, why is data so valuable?

Storage is cheap, collecting the data is expensive. I mean this company had to run a national chain of hotels to collect this data. That's not easy.

Okay, then collecting the data is expensive. Storage being cheap really doesn't matter. You can store tons of unstructured data but that data isn't valuable until it is structured which takes time and money.

Re: Marriott says 5.2M guests exposed in new data breach

#48

Earlier quoted context omitted.

Storage is cheap, collecting the data is expensive. I mean this company had to run a national chain of hotels to collect this data. That's not easy.

Okay, then collecting the data is expensive. Storage being cheap really doesn't matter. You can store tons of unstructured data but that data isn't valuable until it is structured which takes time and money.

Organizing the data is part of collecting it. For something like customer checkin data it would seem to be organized right at the point of collection. The clerk types your data into a database record and submits it to the store.

Re: Marriott says 5.2M guests exposed in new data breach

#49
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

It's mostly the YOB that's valuable; 'basic demographics' is a powerful tool.

Full DOB can probably isolate you from other people with same name for other marketing purposes.

They do have 'adult v child' stuff so they for sure have legit reasons for wanting to know in addition to sleazy reasons.

Post reply on HN