Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Hilton | Hilton Honors
Reload this Page >

FD Agent Apparently not Familiar with AAA Membership...

Community
Wiki Posts
Search

FD Agent Apparently not Familiar with AAA Membership...

Thread Tools
 
Search this Thread
 
Old Nov 25, 2014, 7:08 am
  #16  
Original Poster
 
Join Date: Feb 2013
Location: DCA
Posts: 7,770
Originally Posted by sjpmurph01
The fact that this hotel was supposedly able to take your full unencrypted CC info from a dummy reservation and apply it to your existing reservation is incredibly concerning. If I'm interpreting your description correctly, and this is actually what happened, then both this hotel and the Hilton website/reservation system in general are far out of compliance with PCI-DSS and PA-DSS standards. At no point should anyone, let alone a front line desk clerk at a local hotel, be able to access the full credit card information stored in Hilton's reservation system. Identifying information like the last-4 of the card number or expiration date can be accessible as a reference, but at no time should the full credit card details be so easily retrievable... which I'm assuming they were if this employee was able to "move" your card details from one res to another.

I'm not usually an alarmist about this kind of stuff, but this is a very serious security vulnerability if true, especially in light of the other ongoing HHonors account hacking saga that I still can't believe hasn't gotten more publicity (on FT or otherwise).
I'm not sure I'd read too far into that because it wasn't clear exactly what was going on there. The FD manager was involved at that point, FWIW, and it turns out that they may not have needed the dummy reservation. I made it (from up in my room, using the hhonors app) but then the FD manager said just afterwards that they ended up finding "another way" to get the CC information into the existing reservation. It may have been that it was just a back-end transfer - take data field X out of my profile and transfer to data field Y in the reservation - without them ever seeing anything but asterisks. Idk if that in itself should be concerning.

That said, I have trouble getting too worked up by people who handle physical credit cards all day being able to see...credit card information. Maybe I'm behind the times.
arlflyer is offline  
Old Nov 25, 2014, 1:37 pm
  #17  
 
Join Date: Jul 2012
Posts: 233
Originally Posted by sjpmurph01
I'm surprised nobody else has commented on this part of your story yet...

The fact that this hotel was supposedly able to take your full unencrypted CC info from a dummy reservation and apply it to your existing reservation is incredibly concerning. If I'm interpreting your description correctly, and this is actually what happened, then both this hotel and the Hilton website/reservation system in general are far out of compliance with PCI-DSS and PA-DSS standards. At no point should anyone, let alone a front line desk clerk at a local hotel, be able to access the full credit card information stored in Hilton's reservation system. Identifying information like the last-4 of the card number or expiration date can be accessible as a reference, but at no time should the full credit card details be so easily retrievable... which I'm assuming they were if this employee was able to "move" your card details from one res to another.

I'm not usually an alarmist about this kind of stuff, but this is a very serious security vulnerability if true, especially in light of the other ongoing HHonors account hacking saga that I still can't believe hasn't gotten more publicity (on FT or otherwise).
I'd guess that the "dummy reservation" was actually made the actual reservation and the original without the CC info was cancelled. If not, it's possible that they changed to a different guest's profile/removed honors and then changed back to the original OP/profile that would then reload all the stored CC info.


If not, then they are indeed out of compliance.
jabbered is offline  
Old Nov 25, 2014, 2:40 pm
  #18  
Original Poster
 
Join Date: Feb 2013
Location: DCA
Posts: 7,770
Best I could tell, they ended up not needing the dummy reservation, so it may be the trick that you describe.
arlflyer is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.