FlyerTalk Forums - View Single Post - AwardWallet Hack
View Single Post
Old Jul 30, 2015, 10:55 am
  #15  
nux
FlyerTalk Evangelist
 
Join Date: Jun 2012
Programs: BA Gold, QF WP
Posts: 12,551
Originally Posted by ckpeter
They have already clarified that there was not a system weakness. Given that someone guessed your (weak?) password and got all your account information, I would say AwardWallet would be invaluable in tracking down rogue redemptions.
Yes, but the fact that AwardWallet displays all stored passwords in plain text is a major system weakness. There is no reason to do this.

If the passwords were not displayed in plain text then a hack on AwardWallet accounts would not allow access to the account username/passwords of all accounts tracked within (except if the password for those is the same).
nux is offline