Live data from Hacker News

Marriott says 5.2M guests exposed in new data breach

reuters.com

61–70 of 74 posts

Re: Marriott says 5.2M guests exposed in new data breach

#62

Marriot is an outsourced shop (TCS, Cognizant et. al). They are an empty shell run by “managers”.

Shocking that outsourced IT can't secure customer data. In my own experience with outsourced IT (specifically outsourced to India) it was extremely worrying that the people managing an IT infrastructure had no idea about very basic IT and had to ask the same questions over and over.

I do not trust Accenture. Fuck them.

Re: Marriott says 5.2M guests exposed in new data breach

#65
post #44
post #10

> contact details, loyalty account information and additional personal details such as gender and birthdays I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that. Except banking & government services, I typically provide a fake one if required, because, WTF?

Name + DOB to disambiguate are the lookup keys they pass to data brokers to identify you, given a government ID (required to check in to a hotel). It gives them access to things like address history, email address history (for crosslinking of account records), credit rating, marketing channel tags, et c. Same goes for the phone number that some website registrations demand. It's not to call you, it's to lookup your n…

It’s been a while since I checked in to a hotel but the only thing I remember giving them was my debit card.

Maybe I’m just so used to being asked for my ID I didn’t notice.

Re: Marriott says 5.2M guests exposed in new data breach

#66
post #52
post #51

Earlier quoted context omitted.

My father and I both have the same first and last name, and same mailing address Our birthdays are two days apart. We use the same pharmacy. DOB (including year) is important!

Don't they use personal ID number (e.g. SSN) to differentiate people? Or do you live in a place where you don't have those numbers?

Not everyone in the US has an SSN.

Re: Marriott says 5.2M guests exposed in new data breach

#67
post #44

Earlier quoted context omitted.

Name + DOB to disambiguate are the lookup keys they pass to data brokers to identify you, given a government ID (required to check in to a hotel). It gives them access to things like address history, email address history (for crosslinking of account records), credit rating, marketing channel tags, et c. Same goes for the phone number that some website registrations demand. It's not to call you, it's to lookup your n…

Huh, I chose a random date from the year before I was born and use it whenever sites ask for my birthday. I’ve never had one come back and say that isn’t really my birthday.

It's not like they're checking in real time. There is some error rate in matching people via data brokers, so this trick just manifests itself in a lower cardinality of "enriched" profiles in their database.

Re: Marriott says 5.2M guests exposed in new data breach

#68

Earlier quoted context omitted.

I’m not aware of any major hotel brand that swipes driver’s licenses yet in the US.

Huh? I don't think I've ever checked into a hotel and not been asked to hand over my driver's license so the clerk can punch in a bunch of info from it onto their machine. I assume it's to help them track you down if you cancel your credit card, trash the room, and flee.

But they don’t swipe it.

Re: Marriott says 5.2M guests exposed in new data breach

#70
post #64
post #38

Every time when I asked for my copied ID to be watermark when checking-in at hotels, they always gave me a strange look - as if I do not trust their information security.

Would you elaborate how to do this?

Yeah, I would like some more details. Not sure I understood what exactly it means to "watermark" the ID. Is the goal to change it subtly to find out if it was leaked? Or is the goal to redact parts of it?
Post reply on HN