Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > Air Canada | Aeroplan
Reload this Page >

Email regarding compromised App data

Community
Wiki Posts
Search

Email regarding compromised App data

Thread Tools
 
Search this Thread
 
Old Aug 29, 2018, 7:37 am
  #31  
 
Join Date: Jan 2016
Location: YYZ
Programs: FOTSG Tangerine Ex E35k (AC)
Posts: 5,612
And these updates appear to not include letting one find any flights.

Maybe UA will take my money.
jc94 is offline  
Old Aug 29, 2018, 7:38 am
  #32  
Suspended
 
Join Date: Sep 2014
Programs: AC SE100K-1MM, NH, DL, AA, BA, Global Entry/Nexus, APEC..
Posts: 18,877
Ooooooh, exciting


24left is offline  
Old Aug 29, 2018, 7:42 am
  #33  
 
Join Date: Aug 2014
Location: YQB
Programs: AC SE
Posts: 2,139
Aeroplan.com is completely down now.

Service Temporarily Unavailable

The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
jasdou is offline  
Old Aug 29, 2018, 7:43 am
  #34  
 
Join Date: Dec 2011
Posts: 2,237
Now getting error page when I try to log into Aeroplan

appears they are breaking login security on both systems now

Good thing I don’t want to book flight, today tic tic tic

xLuther is offline  
Old Aug 29, 2018, 7:49 am
  #35  
Suspended
 
Join Date: Sep 2014
Programs: AC SE100K-1MM, NH, DL, AA, BA, Global Entry/Nexus, APEC..
Posts: 18,877
More fun
Got the email I posted just above and also a prompt in the app to reset PWD. So I click to do that and it takes me to this main AC page.
I click the link in the email, I get another email with the PWD reset link and bonus !!!, It also takes me to the main AC page.

Can I laugh now?


24left is offline  
Old Aug 29, 2018, 8:00 am
  #36  
 
Join Date: Jul 2017
Programs: AC SE100K
Posts: 12
I'm curious what the ultimate risk was of someone else logging into our accounts? It seems like if any AC service had to be breached, we'd want it to be the one that gives people almost zero control over the accounts. This and other technical hassles I've had with AC in the past don't give me much faith about the company handling all things Aeroplan. I can see it now...
RobWilliamsTG is offline  
Old Aug 29, 2018, 8:09 am
  #37  
 
Join Date: May 2013
Location: YYT/YYC/TPE
Programs: AC SE, UA, National Exec Elite, Nexus, GE
Posts: 1,810
Must have a crisis before Ben Smith leaves Air Canada.
YYT82 is offline  
Old Aug 29, 2018, 8:09 am
  #38  
Suspended
 
Join Date: Sep 2014
Programs: AC SE100K-1MM, NH, DL, AA, BA, Global Entry/Nexus, APEC..
Posts: 18,877
For fun, I clicked both of the links in the first AC email about resetting PWD

"You can reset your password by following the prompts when you next log‑in to your Air Canada mobile App, or you may reset your password now or you may also go to https://services.aircanada.com/portal-web/mobile/profile?action=resetpwd&locale=en"

RESULT:

Error 500: SRVE0207E: Uncaught initialization exception thrown by servlet
24left is offline  
Old Aug 29, 2018, 8:20 am
  #39  
 
Join Date: Mar 2014
Location: YVR
Programs: AC E75K, WJ Gold, NEXUS, Marriott Gold
Posts: 316
I'm less concerned about the app password itself (I use all different ones) but I don't remember if my Canadian Passport # or NEXUS and birthdate was stored in there or not...
trek604 is offline  
Old Aug 29, 2018, 8:27 am
  #40  
 
Join Date: Jan 2015
Location: YQB
Programs: AC SE100K-1MM, Bonvoy Gold, HHonors Diamond, VIA Premier, NEXUS/GE
Posts: 816
It took a while but I was successful at changing my password (can't remember which link, the one in the app or in the email). I received an email confirming that my password was changed. I thought I was all set.

However, when I use the app, I get the same message about being unable to login and to reset my password
DNAwizard is offline  
Old Aug 29, 2018, 8:30 am
  #41  
Suspended
 
Join Date: Nov 2007
Location: YVR
Programs: Air Canada Super Elite 2+ Million Miles
Posts: 2,478
and why did it take 5 days to advise?

Did AC notice right away and tried to keep this quiet, but found scope too big?

Did AC NOT notice and were asleep at the switch?

As my notice says NOT AFFECTED, I do NOT have standing to complain, but for those of you who have received notice that your affected, may I suggest you make a complaint to the Privacy Commissioner of Canada.

https://www.priv.gc.ca/en/for-individuals/

And let's hang on as just because AC says only 20,000 accounts affected, who knows once this gets more scrutiny.
skybluesea is offline  
Old Aug 29, 2018, 8:31 am
  #42  
 
Join Date: Sep 2014
Programs: AC SEMM
Posts: 1,379
Originally Posted by DNAwizard
It took a while but I was successful at changing my password (can't remember which link, the one in the app or in the email). I received an email confirming that my password was changed. I thought I was all set.

However, when I use the app, I get the same message about being unable to login and to reset my password
The Aeroplan password and the mobile app password are different - perhaps you changed your Aeroplan one
Geoflying is offline  
Old Aug 29, 2018, 8:39 am
  #43  
 
Join Date: Jan 2015
Location: YQB
Programs: AC SE100K-1MM, Bonvoy Gold, HHonors Diamond, VIA Premier, NEXUS/GE
Posts: 816
Originally Posted by Geoflying
The Aeroplan password and the mobile app password are different - perhaps you changed your Aeroplan one
Good idea but no. Aeroplan/ACAltitude/eUpgrade password unchanged. I tested the sites before everything went down.
I was able to login into mobile+ and activate the touch ID using the new password. But I still get asked to change it!
I have no idea what is going on but I won't change anything anymore for the time being.
skybluesea likes this.
DNAwizard is offline  
Old Aug 29, 2018, 8:55 am
  #44  
 
Join Date: Mar 2009
Location: Sudbury-North Shore-Manitoulin
Programs: AP SPG HH
Posts: 631
And this is from the best airline in North America.... ya right....
Northern Canuck is offline  
Old Aug 29, 2018, 8:58 am
  #45  
FlyerTalk Evangelist
 
Join Date: Jun 2003
Location: YYC
Posts: 23,804
So is the CIO going to lose her head, as she should? Or who else will they identify as a scapegoat?

Or in their mind is this a normal thing to happen?

I would suggest affected people look at class action. These things are *NOT* supposed to happen, period.
Stranger is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.