FlyerTalk Forums - View Single Post - AwardWallet Hack
View Single Post
Old Jul 30, 2015 | 5:09 pm
  #28  
fartoomanyusers
50 Countries Visited
All eyes on you!
20 Years on Site
 
Join Date: Aug 2003
Location: London, UK
Programs: bmi DC, BAEC
Posts: 1,959
Originally Posted by ckpeter
They have already clarified that there was not a system weakness.
I would say that a failure to require users to set complex passwords is a clear system weakness.

Further comments have highlighted the lack of password re-entry requirement for the display of saved passwords - sounds to me like another system weakness.


Originally Posted by ckpeter
Given that someone guessed your (weak?) password and got all your account information, I would say AwardWallet would be invaluable in tracking down rogue redemptions.
I agree that AW can be incredibly useful. Maybe they should only operate on the "locally saved" password basis. Thankfully I set-up my AW account like that from the start
fartoomanyusers is offline