Live data from Hacker News

United Airlines’ so-called online security (2016)

techcrunch.com

1–10 of 41 posts

Re: United Airlines’ so-called online security (2016)

#2
https://krebsonsecurity.com/2016/08/united-airlines-sets-min...

United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers.

This has been in place for 3 years despite public shaming.

Re: United Airlines’ so-called online security (2016)

#3
United need to be heavily litigated when accounts eventually get compromised. This must be a wanton disregard for security, rather than simple naivety as many other sites exhibit.

There needs to be real, material damages for companies who do not properly secure data following best-practice guidelines. Not just a 'oh sorry your account was compromised, please change your password!' circus - actual, concrete damages by way of fines or the like put on those who do not properly look after user data.

Re: United Airlines’ so-called online security (2016)

#5
You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend.

Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a

I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe software application.

Re: United Airlines’ so-called online security (2016)

#6
post #2

https://krebsonsecurity.com/2016/08/united-airlines-sets-min... United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers. This has been in place for 3 years despite public shaming.

I'm stuck flying United most of the time and I get the sense their cybersecurity posture is consistent with their broader business posture: "If you do nothing, nothing will happen. If something external forces change, deny, deny, deny." Very old school. In all the worst ways.

Re: United Airlines’ so-called online security (2016)

#7
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

Yeah...I’m with one of those banks. It’s really bad.

But hey they require security questions!

It’s 2019, how can this be...

Re: United Airlines’ so-called online security (2016)

#8
I've often read discussion about how you can't regulate this sort of thing because the industry moves so fast that what's a best practice today can be tomorrow's horrible security (then enforced by law).

But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easily identifiable and correctible attack vectors, would be enough to get companies thinking about security a bit more seriously. It doesn't have to be anything big, and I wager it'd have a serious impact.

Re: United Airlines’ so-called online security (2016)

#9
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

Not quite as bad but I got a letter recently from something bank-ish (huge, international, traditional) that contained some serious admonitions including one about never using password managers or writing down the password in any way, concealed or not didn't matter.

I have problems taking any security advice seriously from such companies after that but since I fully expect them to use ut against me if I ever have to file a fraud complaint I guess I'll have to deal with it - and get another account with a company that isn't braindead when it comes to security.

Re: United Airlines’ so-called online security (2016)

#10
post #5

You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…

For what it's worth, such password schemes usually include lockouts after small-N tries to prevent the passwords from being brute-forced from the outside, and an attacker with database-level access is probably going to use it not to compromise passwords but to directly change balances.

Not to excuse such password schemes - they're horrible, and banks need to get with the times - but if they were really so ineffective, their coffers would have been drained long ago.

Post reply on HN