Live data from Hacker News

How Airlines don’t care about privacy: Case Study Emirates.com

medium.com

51–60 of 177 posts

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#51
post #41

If you look at https://track.emirates.email you will see that it isn't emirates either, but a service provided by Mandrill, an add-on for MailChimp, and the cert is valid for https://mandrillapp.com . Surely they could have figured out how to use SNI. The fact that your mail client / embedded browser takes you happily to sites with broken certs, giving them a tracking token (and in this case, total access to your boo…

Exactly, the fact that the url does not have any expiry (apart from the end of booking), the email providers in this case Mailchimp would also have access to the same. For the case why browser did not redirect the broken cert, that is because the link sent in the email was over http.

I tested going to a https link via gmail. On desktop chrome, it immediately opens the link (and hence passes the link parameters). On mobile it pops up a privacy error, "Attackers might be trying to steal your information" (NET::ERR_CERT_COMMON_NAME_INVALID), which is certainly the right thing to do. Still have to try it on Office365 and Outlook.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#52
post #6

Airlines don't care about privacy, security, user experience, prices... There are many things you don't have to care about when competition is low and barriers to entry are incredibly high. As an aside, turns out 9/10 decoy bombs and bladed weapons are smuggled onboard with no problems in tests. All the security theatre and voodoo rituals requiring passengers to switch off all electronic devices for no actual reasons…

Airlines aren't responsible for security. The rules are specified by the IATA and national agencies and security is either handled by a government department (e.g. TSA) or by the airport itself.

Also, switching off electronic devices has nothing to do with security. The apparent reason is that it can cause issues with navigation, as was theorised after a plane crash in the 90's. Most flights these days don't even require you to turn your electronics off, or even put it in airplane mode.

I'm fairly sure the reason that they made you turn your electronics off wasn't even for the plane, but rather to ensure that you pay attention to the safety briefing.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#53
Hmm, no mention of luggage tags or boarding passes? Your luggage tag usually has your last name and your booking code. Those 2 bits of information are enough to login to your flight details, including your passport information. They are also on your boarding pass, also coded on the barcode, which people sometimes post online, it can also be photographed from a distance with a good enough camera.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#54

Hmm, no mention of luggage tags or boarding passes? Your luggage tag usually has your last name and your booking code. Those 2 bits of information are enough to login to your flight details, including your passport information. They are also on your boarding pass, also coded on the barcode, which people sometimes post online, it can also be photographed from a distance with a good enough camera.

FTA: Every single passenger's info is readable by a list of 20+ domains that are not Emirates.

That's quite different from having to put physical eyeballs on a luggage tag.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#55

Hmm, no mention of luggage tags or boarding passes? Your luggage tag usually has your last name and your booking code. Those 2 bits of information are enough to login to your flight details, including your passport information. They are also on your boarding pass, also coded on the barcode, which people sometimes post online, it can also be photographed from a distance with a good enough camera.

I think you are referring to an attack similar to this: https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme..., I just linked this video in the article and not the complete attack vector.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#56
post #41

Earlier quoted context omitted.

Exactly, the fact that the url does not have any expiry (apart from the end of booking), the email providers in this case Mailchimp would also have access to the same. For the case why browser did not redirect the broken cert, that is because the link sent in the email was over http.

I tested going to a https link via gmail. On desktop chrome, it immediately opens the link (and hence passes the link parameters). On mobile it pops up a privacy error, "Attackers might be trying to steal your information" (NET::ERR_CERT_COMMON_NAME_INVALID), which is certainly the right thing to do. Still have to try it on Office365 and Outlook.

Strange, I always encounter `NET::ERR_CERT_COMMON_NAME_INVALID` even on Gmail with Chrome. What's your test setup?

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#57
post #20

Earlier quoted context omitted.

I'm waiting for someone to state "when you're not paying for something, you are the product", except in this case, you are paying for something, yet you're still the product. This is just...disgusting.

This comment is spot on. Do you mind if I use it as a caption on the artice aswell(with due credits)

not at all; I don't mind

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#58
post #27
post #10

Earlier quoted context omitted.

Absolutely agree, data security is a not a priority for almost all organizations in Service Industry. Hopefully GDPR and E-Privacy will be the beginning of an era when organizations are forced to think about protecting user information.

The website sounds like a blatant GDPR violation, and GDPR has teeth.

I'm wondering how sharp those teeth are. What are they going to do, revoke Emirates operational licenses throughout Europe? That would not go over well with flyers...

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#59
post #13

I oftentimes reach for my 'call the regulator' button when I read these articles. Whats odd is how many people say "god no..." as if there was some consequential downside to using the very government entity we created (in law) to make corporate entities "do the right thing" when they don't appear to want to do it voluntarily. So.. here we go. Explain to me, why we don't want to enact law to require (through regulatio…

I'm waiting for someone to state "when you're not paying for something, you are the product", except in this case, you are paying for something, yet you're still the product. This is just...disgusting.

This is why we should stop quoting that all the time.

Just because you are paying for a product does not prevent your data from being sold or used in unethical ways.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#60
post #27

Earlier quoted context omitted.

The website sounds like a blatant GDPR violation, and GDPR has teeth.

I'm wondering how sharp those teeth are. What are they going to do, revoke Emirates operational licenses throughout Europe? That would not go over well with flyers...

A fine of up to €20 million or up to 4% of the annual worldwide turnover, whichever is greater. Yeah there's a reason everyone's panicking about GDPR, it can seriously wreck your business.
Post reply on HN