TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

It's time to publicly shame United Airlines' so-called online security

50 pointsby galazzahalmost 9 years ago

10 comments

madaxe_againalmost 9 years ago
It&#x27;s entirely their prerogative as to whether or not they provide a decent level of security, and it&#x27;s entirely up to consumers to choose whether or not to work with them.<p>The vast majority of people do not know what 2fa is, and sure as hell don&#x27;t care to know, so the only people irked by their misleading messaging are IT professionals, who, again, can fly with someone else.<p>Essentially, there is clearly no incentive for them to improve their security unless it hurts their bottom line - and there&#x27;s no point from their perspective in investing in something which makes no money.<p>Of course, if they have a major hack there will be some brief PR damage (none of the high profile hacks of major companies seem to have inflicted <i>any</i> reputational damage - instead the public blame the &quot;terrorist hackers&quot; the media parade), and their insurers will cover any direct losses, including those as a result of a class action, which they&#x27;re probably indemnified against anyway.<p>In short, they have no reason to change, so probably won&#x27;t. If anything, they&#x27;ll be upheld as the golden standard, because legislators will buy into their PR, not being in any way technical themselves. Perception is reality.
评论 #12284722 未加载
kogepathicalmost 9 years ago
In all fairness to United, it&#x27;s probably pretty difficult to implement real 2FA in COBOL.<p>(In passing jest to: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12246490" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12246490</a> )
评论 #12287822 未加载
oneeyedpigeonalmost 9 years ago
To be fair, all UA say is:<p>&gt; Your security questions will also be used as part of upcoming two-factor authentication to further protect your account<p>The stupid nature of the &#x27;enum answers&#x27; aside, this doesn&#x27;t necessarily mean they&#x27;re not implementing 2FA properly. They <i>might</i> have 2F set up as securely as the very best practitioners, then have this security question crap layered on top. We need to know for sure that they think the security question is one of the two factors before tearing them a new one.
评论 #12284837 未加载
chris_7almost 9 years ago
The dropdowns are hilarious for non-security reasons, you have to choose your favorite artist... from a list of about 12 artists. I suppose it could be an improvement on the misogynist, homophobic, and Facebook-able &quot;mother&#x27;s maiden name&quot;.<p>I&#x27;m almost disappointed that they&#x27;re not having their phone staff ask for your actual password - I&#x27;d love to have the experience of reading my 1Password-generated password to them.
stwealmost 9 years ago
The author seems to use authorization and authentication interchangeably multiple times in the text. They may be right about the point they are making, but it leaves a bad taste.
swangalmost 9 years ago
security questions as a recovery mechanism are fucking terrible.<p>most people are going to fill in the same response for their security q&#x2F;a over multiple sites so pretty much any bad actor in any organization could possibly look at the security q&#x2F;a, guess that their question&#x2F;answers are the same on other sites and exploit that avenue.<p>also fuck remembering all of that.<p>but i think hsbc was even worse than what united is asking for. for their online banking you had to enter in your password then enter in another password using a browser based keyboard (AVOIDS KEYLOGGING!) and then answer a security question or something like that. i must have asked for a new passcode to reset everything every couple of months (they mail these to you via snail-mail).<p>of course the problem with the system was (and i forgot exactly how) there was a way sometimes to reset all these systems so you didn&#x27;t have to remember your answer for each security measure. i was pretty sure it was a bug with the system but fuck if i want to endure the hell in trying to explain to a website with terrible security that you&#x27;ve found a bug in their terrible system and please don&#x27;t put me in jail and what do you mean, &#x27;what is a hash function?&#x27;
calanyaalmost 9 years ago
Providing account authentication as a service seems like a no-brainer.<p>Does no company in this space know how to sell to conservative IT organizations like air lines?
评论 #12284659 未加载
评论 #12284677 未加载
cmurfalmost 9 years ago
Apple also uses security questions like this for Apple ID accounts. I don&#x27;t like it, but where&#x27;s the outrage? Is there is a way to do this correctly, other than the user asking their own question?
desdivalmost 9 years ago
I wonder at what point will companies finally realize that it would be cheaper and easier to just give each customer a security token.
评论 #12284664 未加载
评论 #12287861 未加载
duncan_baynealmost 9 years ago
Can we start by shaming Techcrunch.com&#x27;s mobile layout?<p><a href="https:&#x2F;&#x2F;s4.postimg.org&#x2F;5er0ol93h&#x2F;Screenshot_2016_08_14_17_59_56.png" rel="nofollow">https:&#x2F;&#x2F;s4.postimg.org&#x2F;5er0ol93h&#x2F;Screenshot_2016_08_14_17_59...</a>