FlyerTalk Forums - View Single Post - 2014 UA Issued Awards on Air China (CA) Are Mysteriously Being Canceled (Hacked?)
Old Apr 22, 2014, 6:30 pm
  #509  
pdx1M
 
Join Date: May 2001
Location: Portland, OR, USA
Programs: UA 1K 3 Million/ex-many year GS, AA PLT/2 Mil, AS MVPG, HH Dia, Starwood Life Plat, Hertz PC
Posts: 1,401
Originally Posted by DaviddesJ
He's talking about referring the cancellation of CA award travel to the Department of Homeland Security, because of its obvious security implications. Feel free to explain what those are.
I agree that contacting DHS would be pretty far over the top. However, I will observe in a more level manner that UA definitely represents critical infrastructure within the US in the sense that a massive disruption of UA services would cost the US economy quite a lot. The type of security hole that this seems to represent (i.e., unprotected cancellation of other people's reservation) isn't limited to award tickets issued with CA segments. It is a general security hole. Were someone able to get a list of RLs/Names one could certainly create havoc for a day or two with business travel even within the US. The safeguard would seem to be that you can't get that list unless you have segments on other carriers that do not safeguard that information. However, since I doubt that anyone has seriously considered RL/Name pairs particularly sensitive information (private sure but sensitive likely less so) it is hard to know how difficult/easy acquiring such a list would be. This is why I noted earlier that UA is operating here with well below what I would call industry standard practice security. Doing that, at the least, exposes UA to sanctions either via legal processes or via DOT, but moreover it creates unnecessary risk to the larger transport system integrity were someone to get such a list and do mass cancellations.
pdx1M is offline