United Airlines’ so-called online security (2016)
techcrunch.com
United Airlines’ so-called online security (2016)
1–10 of 41 posts
Re: United Airlines’ so-called online security (2016)
#2United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers.
This has been in place for 3 years despite public shaming.
Re: United Airlines’ so-called online security (2016)
#3There needs to be real, material damages for companies who do not properly secure data following best-practice guidelines. Not just a 'oh sorry your account was compromised, please change your password!' circus - actual, concrete damages by way of fines or the like put on those who do not properly look after user data.
Re: United Airlines’ so-called online security (2016)
#4Re: United Airlines’ so-called online security (2016)
#5Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a
I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe software application.
Re: United Airlines’ so-called online security (2016)
#6https://krebsonsecurity.com/2016/08/united-airlines-sets-min... United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers. This has been in place for 3 years despite public shaming.
Re: United Airlines’ so-called online security (2016)
#7You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…
But hey they require security questions!
It’s 2019, how can this be...
Re: United Airlines’ so-called online security (2016)
#8But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to Outlawing a small set of easily identifiable and correctible attack vectors, would be enough to get companies thinking about security a bit more seriously. It doesn't have to be anything big, and I wager it'd have a serious impact.
Re: United Airlines’ so-called online security (2016)
#9You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…
I have problems taking any security advice seriously from such companies after that but since I fully expect them to use ut against me if I ever have to file a fraud complaint I guess I'll have to deal with it - and get another account with a company that isn't braindead when it comes to security.
Re: United Airlines’ so-called online security (2016)
#10You think that's bad, there's major Canadian banks where the password for your online banking account can't be longer than 8 characters or numbers, can't contain punctuation marks, and is stored in plaintext on their backend. Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe soft…
Not to excuse such password schemes - they're horrible, and banks need to get with the times - but if they were really so ineffective, their coffers would have been drained long ago.