TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Alaska Airlines website exposes passenger data

65 pointsby JaakkoP5 months ago
TL;DR: Alaska exposes other customers names, record locators, flight information, phone numbers emails, and probably more. I could have canceled or changed these people&#x27;s flights.<p>The first time it happened it appeared by seeing &quot;Treat yourself, Samantha&quot; in the website ad for upgrading yourself to Premium class. My name is not Samantha.<p>I clicked, and saw Samantha Lastname was traveling from Miami to Seattle. There was her phone number, record locator, ticket and mileage numbers, emails and other info. It also would have let me change or cancel her flights.<p>When I refreshed I got a new person. Trevor. He&#x27;s going from JFK to SEA, and back to EWR.<p>I figured this wasn&#x27;t one-off (yet still serious) bug, and called Alaska Support. They didn&#x27;t believe me, but once I had rattled off the customer information I had in front of me and told them I&#x27;m none of these people, they transferred me to somewhere I thought was a higher up.<p>The higher-up person verified some information, asked no questions on how to replicate the bug, and asked me to log out and log back in. Once I did, the issue did not show up again. They said they&#x27;ll send me 3,000 points for reporting. That sounded pretty low to me as it seemed like a serious data leak, but whatever.<p>I contemplated whether to post about this as I thought it would be interesting for the HN audience to see, but decided against it thinking I&#x27;ll give Alaska time to fix it.<p>It&#x27;s been 4 months now, and today this happened again. I saw an upgrade ad for Sally. Sally and Chris are traveling in the same reservation from Redmond, OR to Seattle in Main Preferred class. Knowing what I was looking at, I figured Alaska had done absolutely nothing to fix the issue.<p>I have a theory what&#x27;s causing it as there&#x27;s something specific that happened before both of these issues, but I&#x27;ll refrain from posting it here so it&#x27;s not as easy to exploit. Who knows what else the payload might include.<p>I took screenshots throughout the process, including some console logs, to document what I saw. I am sharing this here in the hope that the added visibility will finally push Alaska Airlines to address the issue.

10 comments

rootsudo5 months ago
They have an ecomm team and info sec team but they’re pretty unwilling to fix this. They do agile but no one wants to own this, especially in December since they have change freezes and this will affect the yearly and monthly issues.<p>I would advise submitting this is the state of Washington and DOT federal and state.<p>Technically this is a data breach. Atg.wa.gov I would submit a data breach notification this will force them to actively fix it this month otherwise they will sit on it and push it off per agile sprint and do it when it’s convenient for the airline. Post holiday rush.
评论 #42348154 未加载
solardev5 months ago
Support won&#x27;t know what to do. Have you tried their cybersec form? <a href="https:&#x2F;&#x2F;www.alaskaair.com&#x2F;content&#x2F;about-us&#x2F;site-info&#x2F;report-site-security-issues" rel="nofollow">https:&#x2F;&#x2F;www.alaskaair.com&#x2F;content&#x2F;about-us&#x2F;site-info&#x2F;report-...</a>
评论 #42347618 未加载
Neff5 months ago
I have connections with people at Alaska. I will send this their way and hopefully someone will reach out. Make sure there is contact info in your bio
评论 #42348216 未加载
madaxe_again5 months ago
You need to be very, very careful about posting this, depending on your jurisdiction - in most western countries this disclosure is illegal, and you can be criminally prosecuted for providing information about accessing personal information, and you are also admitting that you knowingly accessed the personal information of other customers - in fact, airline passengers, who there are additional privacy laws for.<p>What you’ve done here is a criminal act according to the CFAA, and your exploration of their site could also be construed as wire fraud. As you’ve done this across state lines this is also a federal felony. You’re also in violation of the GLBA, as you’re disclosing the availability of airline customer information. You could also fall foul of the FTC and the wiretap act.<p>I have seen people (Weev, Michael Brown, numerous others) go to prison for similar, and this lot could win you years in a federal penitentiary.<p>Please, consider the legal consequences this could bring upon you.<p>I would simply forget about it and promptly delete this - it’s their problem, not yours, and by posting about it here, they could decide to make it your problem.
评论 #42348129 未加载
评论 #42349167 未加载
underdeserver5 months ago
They have a bug. Serious one, yes, but they listened and gave you points for reporting it. Seems to me at least the support staff are trying (even if they aren&#x27;t quite able to get it fixed).
评论 #42347859 未加载
StressedDev5 months ago
The OP can report the security problem by going to <a href="https:&#x2F;&#x2F;www.alaskaair.com&#x2F;content&#x2F;about-us&#x2F;site-info&#x2F;report-site-security-issues" rel="nofollow">https:&#x2F;&#x2F;www.alaskaair.com&#x2F;content&#x2F;about-us&#x2F;site-info&#x2F;report-...</a> . I think this is probably the best way to get Alaska Airlines to fix the problem.
评论 #42348404 未加载
Terr_5 months ago
Perhaps some sort of UUID collision in terms of cookies&#x2F;sessions?
评论 #42347543 未加载
Dalewyn5 months ago
&gt;I&#x27;ll refrain from posting it here so it&#x27;s not as easy to exploit.<p>I commend your ethics, but I&#x27;m going to be straight with you: Alaska isn&#x27;t going to do anything until tangible harm and damage occurs. The cost to address the problem is higher than the cost to just ignore it. Alaska probably won&#x27;t think this even is a problem yet, for that matter.<p>If you still want to be an unwarranted gentleman, I would report this again but put a firm deadline to disclosure and say &quot;No&quot; is not an answer. Also have a lawyer handy if you choose to make this a problem for them.
评论 #42348145 未加载
评论 #42347926 未加载
solardev5 months ago
OP did they ever write back?
ratg135 months ago
load balancer &#x2F; caching issues