Originally Posted by
sigbjod
Do you know where I could do this? When going through the award ticket booking process, I can't find any box to enter the FB number of the person flying (if the trip is for someone else than the FB account owner). I'm also unable to find where I could add the FB number myself once the booking is done.
I usually do this for a paid ticket here:
http://www.airfrance.nl/cgi-bin/AF/N...icket-plane.do
When you have logged in with the PNR number it will probably say: "Your reservation cannot be completed in this country, please click here, if you wish to make changes to your reservation."
When you click the link a "modify" button appears under the section "Passengers". There you can add/change the FF number
The same computer was used, but I used different browsers to avoid mixing cookies and sessions. Thus the accounts have never been used in the same environment at the same time willingly. It clearly shows that there's room for improvment when it comes to handling FB accounts and reservations.
Regarding the security risk, I don't know if it's that a big problem since people usually don't have the habit of ordering tickets for complete strangers. In addition, when looking for bookings you'll need the reservation code which, I suppose, is matched with your name so the possibility of exploiting this on a bigger level seems rather limited.
For my part, I could hypothetically spend the miles available in the other person's account without him knowing it, but at some point in time (it's family after all) I'd have to explain myself.
Yes, but what if you accidentally lose your BP at the airport, or, after the flight. I agree its a bit of a stretch, but somebody who picks up the BP can then abuse this issue and spend the award miles. Following your steps one only has to change the FF number to ones own, login with your own FB account and click on the reservation. You have now hijacked the account of the person owning the original BP.
Having said all that..practically it might not be as easy, for one, I dont think you can put a random FF number in the booking if the names dont match. But still..