FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Hilton | Hilton Honors (https://www.flyertalk.com/forum/hilton-hilton-honors-417/)
-   -   Consolidated "CAPTCHA for logging in?" thread (https://www.flyertalk.com/forum/hilton-hilton-honors/1618936-consolidated-captcha-logging-thread.html)

Zeeb Oct 8, 2014 8:13 am

Consolidated "CAPTCHA for logging in?" thread
 
Anybody else getting a CAPTCHA this morning trying to log in to HHonors? Of course, the website was still down afterword. But having the CAPCHA was a first for me. I'm totally okay with it though, since it makes it tougher to brute force passwords and login credentials.

xandern Oct 8, 2014 8:27 am


Originally Posted by Zeeb (Post 23644530)
Anybody else getting a CAPTCHA this morning trying to log in to HHonors? Of course, the website was still down afterword. But having the CAPCHA was a first for me. I'm totally okay with it though, since it makes it tougher to brute force passwords and login credentials.

I noticed the same thing earlier today. It almost certainly has to do with the large number of reports of people having their HHonors account hacked, maybe this simply happened by an automatic system attempting to log in via the outdated and insecure 4 digit pincode system.

fozziedoggie Oct 8, 2014 8:48 am

I think I would rather have the option of using a longer pass-code instead of having to type in a random generated word.

cblaisd Oct 8, 2014 8:58 am

I couldn't even get the sign-in page at the HHonors site, but the Hampton Inn site let me log in and indeed has a captcha. Took three refreshes before I got one that I could actually read.

arlflyer Oct 8, 2014 9:00 am

Oh my. This is truly awful. Hate these things.

sjpmurph01 Oct 8, 2014 9:07 am

I'm getting the CAPTCHA too today. Agreed that it's likely a quick bandaid due to the recent reports of hacked accounts. I'd expect a better long term solution in the not too distant future (e.g. no more 4-digit PINs), but this is just an immediate fix.

dave1013 Oct 8, 2014 10:01 am

Was able to log on to iPhone Hilton app just now without having to navigate the captcha gauntlet.

skunker Oct 8, 2014 10:59 am

This might be a stupid question, but why don't people just use a password instead of a PIN? I've used a password every since signing up for HH.

Abidjan Oct 8, 2014 11:26 am

Yes, indeed - seeing it too.

Points Scrounger Oct 8, 2014 11:54 am

I didn't mind that it was one simple three-digit number; I can't stand it when they ask for two, difficult to make out ones.

fozziedoggie Oct 8, 2014 12:02 pm


Originally Posted by skunker (Post 23645448)
This might be a stupid question, but why don't people just use a password instead of a PIN? I've used a password every since signing up for HH.

Because I believe you are forced to create a four-digit PIN even if you never want to use it. So a PIN or password will work. :td:

The "bad guys" just figure out PIN's and don't bother with a password.

Stripe Oct 8, 2014 1:50 pm

Is Hilton insane? Do they simply want people to stop using their website? Is some sort of a bot automatically logging into Hilton accounts a realistic threat? What could they do even if they did get access?

I can't imagine a customer-facing company with a more incompetent IT department.

sbams Oct 8, 2014 2:06 pm

Personally I have no problem with a captcha. What I am curious about is whether the new log-in page will finally "Remember Me"

Zeeb Oct 8, 2014 2:26 pm


Originally Posted by Stripe (Post 23646467)
Is Hilton insane? Do they simply want people to stop using their website? Is some sort of a bot automatically logging into Hilton accounts a realistic threat? What could they do even if they did get access

http://www.flyertalk.com/forum/hilto...r-changed.html

Yellowjj Oct 8, 2014 2:46 pm

It's probably a temporary fix. My guess is they will remove pin based access soon enough.

Pins are simply too easy to crack compared to words...and most people choose the simplest pin of 0000 or 1234.


All times are GMT -6. The time now is 10:52 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.