Live data from Hacker News

Marriott says 5.2M guests exposed in new data breach

reuters.com

51–60 of 74 posts

Re: Marriott says 5.2M guests exposed in new data breach

#51
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

My father and I both have the same first and last name, and same mailing address Our birthdays are two days apart. We use the same pharmacy. DOB (including year) is important!

Re: Marriott says 5.2M guests exposed in new data breach

#52
post #51
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

My father and I both have the same first and last name, and same mailing address Our birthdays are two days apart. We use the same pharmacy. DOB (including year) is important!

Don't they use personal ID number (e.g. SSN) to differentiate people? Or do you live in a place where you don't have those numbers?

Re: Marriott says 5.2M guests exposed in new data breach

#53
post #51
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

My father and I both have the same first and last name, and same mailing address Our birthdays are two days apart. We use the same pharmacy. DOB (including year) is important!

Same name? Is that common where you live? That would be .. unconventional around here, to put it mildly.

Re: Marriott says 5.2M guests exposed in new data breach

#54

Is it safe now to just assume that most everything about me has been exposed to someone? My only hope is that the number of places I've provided bogus information to creates enough noise that the truth is obscured some.

Probably (Mastercard provides free monitoring of leaked databases: https://mastercardus.idprotectiononline.com/enrollment/embed... ) however the service is kinda garbage because they censor it so much that I have no idea what of my data is actually leaked), but from a quick Google search it looks like you've voluntarily given out a lot about yourself anyways. I think most people have and are lulled into a sense of fa…

I often wonder how big my data footprint is. I don't have any social media, and I cycle between a few handles on any publicly facing site I keep an account with. I suppose Google must have all of my search history associated with my main email address, but I use several different emails and browsers in my day to day.

I guess I'm wondering how good all of these companies are at sharing data between themselves. What kind of data is exposed when I use my primary email to log into Zoom or Spotify on a work computer, or my phone, or one of my relative's computers? To what extent do these companies coordinate and share this data?

It all just seems like a really big unknown to me, and I'm relatively tech savvy.

Re: Marriott says 5.2M guests exposed in new data breach

#55
post #51

Earlier quoted context omitted.

My father and I both have the same first and last name, and same mailing address Our birthdays are two days apart. We use the same pharmacy. DOB (including year) is important!

Same name? Is that common where you live? That would be .. unconventional around here, to put it mildly.

Sure, very common.

John Smith, John Smith Jr...

Re: Marriott says 5.2M guests exposed in new data breach

#56

The last breach was November of of 2018 . They have had a year and a half to fix their abysmal security practices. Instead they choose to focus their efforts in that time on a ridiculous branding juggernaut("Bonvoy".) Seriously fuck this company. I hope people vote with their wallet.

Disclaimer: I did a lot of the work for marriott.com to run Microservices about 3+ years ago.

With that said, this is surprising to me: Information Protection at Marriott was one of the biggest hurdles to get the new version of their .com up and running, and the 2018 hack came from the Starwood Acquisition.

This one? There's really no good excuse for. Well, forcing employees to change their password every 30 days and keeping 12 months of password retention probably didn't help (super common to just suffix the month/year with your known password to get around that check). Either that, or it was a genuine bad actor/employee inside MI. Anything's possible, I guess.

Re: Marriott says 5.2M guests exposed in new data breach

#57
post #44
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

Name + DOB to disambiguate are the lookup keys they pass to data brokers to identify you, given a government ID (required to check in to a hotel). It gives them access to things like address history, email address history (for crosslinking of account records), credit rating, marketing channel tags, et c. Same goes for the phone number that some website registrations demand. It's not to call you, it's to lookup your n…

Huh, I chose a random date from the year before I was born and use it whenever sites ask for my birthday. I’ve never had one come back and say that isn’t really my birthday.

Re: Marriott says 5.2M guests exposed in new data breach

#59
post #55

Earlier quoted context omitted.

Same name? Is that common where you live? That would be .. unconventional around here, to put it mildly.

Sure, very common. John Smith, John Smith Jr...

Right, now that I think about it I'm familiar at least with the George Bush case of like father, like son.
Post reply on HN