Singapore KrisFlyer...
 

Singapore KrisFlyer Improves Account Security

14 Posts
4 Users
0 Reactions
312 Views
Posts: 40032
Admin
Topic starter
(@lucky)
Member
Joined: 13 years ago
[#9928]
wpf-cross-image

While I'm by no means a tech security expert, there are some travel companies that have mind-numbingly bad security practices. For example, IHG continues to use four digit PINs. IHG accounts get hacked all the time. Can anyone -- anyone -- help me understanding how in 2019 they still do this? Accounts get hacked all…

Continue reading: Singapore KrisFlyer Improves Account Security

Share your questions, experiences, and thoughts below.


13 Replies
13 Replies
 rich
(@rich)
Joined: 7 years ago

Posts: 1

it is really pathetic. 8 character passwords are pretty easy to crack. Personally they should require at least 12 but preferably 16 characters with numbers and special characters.

I once complained to a stock brokerage and their response was "some people don't want longer passwords". Of course in the states we can't get most people to use the chip in ccs and still swipe them in many/most locations. And most non-fast food restaurants can't handle Apple Pay (or other phone payment methods).

Wasn't BA and Hilton both bad for a while? (Regarding a short pin.)


Reply
(@Jackie)
Joined: 8 years ago

Posts: 76

what I don't understand is why they limit it to 16? Why not 50 or 100?


Reply
 Mike
(@Mike)
Joined: 9 years ago

Posts: 29

Ridiculous to have an upper limit... Sounds like they're possibly not even encrypting them


Reply
 Max
(@Max)
Joined: 9 years ago

Posts: 515

Wake me up when there is a loyalty program that offers 2-Factor-Authentication for login and transactions. Imho the security of these programs should be regulated the same way as for online banking accounts.


Reply
 Rain
(@Rain)
Joined: 9 years ago

Posts: 164

As said above this is still ridiculously lax.
Why limit the upper number of characters that you can use? It's not like the extra storage costs are noticeable.
Also, two factor authentication needs to be implemented.


Reply
 Sam
(@Sam)
Joined: 7 years ago

Posts: 1

@Max Qantas FF uses/forces 2FA. It’s actually a little annoying when you are traveling and they force SMS confirmation and are using a different SIM/number.

But I get the point - too many of these programs use 4-6 digit pins which are ludicrously easy to hack. This is a small step forward for Singapore Airlines and the rest still using PINs should hurry up and follow suit.


Reply
 dave
(@dave)
Joined: 8 years ago

Posts: 30

Re: Why limit the number of characters in a password? And similarly why limit the special characters you can use?

Because they've hired some cheap enterprise developers who can only build things with copy and paste code and their program managers don't know a anything about security.


Reply
(@jtmeded)
Joined: 5 years ago

Member
Posts: 0

@Lucky - LastPass lets you easily have multiple logins for each site, and then you just pick the one you want.


Reply
(@michaelr)
Joined: 11 years ago

Posts: 7

Why did Windows 10 re-introduce the 4 digit PIN?


Reply
(@jtmeded)
Joined: 5 years ago

Member
Posts: 0

@michaelr A pin on Windows is safer than a password, as it is tied to the specific device and not stored by Microsoft. Most issues come from remote attackers, which is not possible even with a simple pin.


Reply
(@fellowtraveller)
Joined: 5 years ago

Member
Posts: 0

IHG doesn't pay their hotels much for stays, so I guess it's cheaper to put points back into accounts than fix the software?


Reply
 Rob
(@Rob)
Joined: 7 years ago

Posts: 2

Not a cyber security expert, but I've heard 16 characters of mixed type would take several years to brute-force hack. Good enough for me.


Reply
 John
(@John)
Joined: 7 years ago

Posts: 45

I haven't used a password with Microsoft, Google or Yahoo in ages. All 2 factor auth. I don't understand why more organizations don't make the switch.


Reply