Community
Wiki Posts
Search

Honors Login Update

Thread Tools
 
Search this Thread
 
Old Mar 22, 2015, 1:48 pm
  #301  
 
Join Date: Jan 2015
Programs: HHonors Gold, Delta Skymiles, Amtrak Guest Rewards
Posts: 34
I don't get a password change notifications when I login on a desktop browser, only on the mobile app. Does that mean I should only change it on the app to get the 1000 points. Either way, for some reason when I try to set my username/password info on the mobile app, it throws me an error.
slickguy is offline  
Old Mar 22, 2015, 2:09 pm
  #302  
 
Join Date: Mar 2011
Programs: AA LifeTime PLT (2.982 MM, But 3MM+ Total), HHonors GOLD, IHG AMB
Posts: 787
I did mine on March **. Hope I get my points.

Last edited by Spock Seat; Mar 23, 2015 at 1:26 pm
Spock Seat is offline  
Old Mar 22, 2015, 5:55 pm
  #303  
 
Join Date: Apr 2013
Location: Lehigh Valley, Pennsylvania
Programs: Milege+, SkyMiles, AAdvantage, HHonors Diamond, Marriott Gold
Posts: 1,685
Originally Posted by slickguy
I don't get a password change notifications when I login on a desktop browser, only on the mobile app. Does that mean I should only change it on the app to get the 1000 points. Either way, for some reason when I try to set my username/password info on the mobile app, it throws me an error.
I don't think you need to click through the banner to get 1K points.
eajusa is offline  
Old Mar 23, 2015, 11:22 am
  #304  
 
Join Date: Mar 2015
Posts: 1
I changed (added) my password today (3/23). How long does it take to get the 1,000 bonus points?
1NetworkGuy is offline  
Old Mar 23, 2015, 11:55 am
  #305  
FlyerTalk Evangelist
 
Join Date: Nov 2003
Location: South Florida
Programs: AA LTG (EXP), Hilton Silver (Dia), Marriott LTP (PP), SPG LTG (P) > MPG LTPP
Posts: 11,329
I'm not expecting points until the promo is over and they do a sweep. I don't see them doing it at transaction time and if they did, there would probably be a glitch that would post after each attempt and not limit it to only once. We are talking HH IT after all.
RogerD408 is offline  
Old Mar 23, 2015, 1:14 pm
  #306  
 
Join Date: Feb 2013
Location: Somewhere In The Five Eyes
Posts: 229
Yet another MAJOR hilton.com and hhonors.com login flaw.

https://krebsonsecurity.com/2015/03/...ts/#more-30433

Dear Hilton,

Please hire I/T professionals and security professionals.
gqZJzU4vusf0Z2,$d7 is offline  
Old Mar 23, 2015, 1:46 pm
  #307  
IMH
 
Join Date: Jul 2007
Location: Berlin
Programs: BA Gold; Accor Plat; IHG Diamond-Amb; Meliá & HH & Marriott Gold
Posts: 5,450
Originally Posted by gqZJzU4vusf0Z2,$d7
Yet another MAJOR hilton.com and hhonors.com login flaw.

https://krebsonsecurity.com/2015/03/...ts/#more-30433
When I saw the Krebs report earlier (and posted about it here), I was assuming that it was the same breach -- but looking more closely it would seem that the security weakness reported by Krebs only explains some of the more recent events discussed in this thread, not the initial weakness at the heart of the thread in which I mistakenly posted.

Dear, dear, Hilton.
IMH is offline  
Old Mar 23, 2015, 5:26 pm
  #308  
 
Join Date: Feb 2013
Location: Somewhere In The Five Eyes
Posts: 229
... and over the past several months, Hilton has been unable to fix multiple SSL/TLS encryption defects of their various portals. According to Qualys (ssllabs.com):

hhonors.com -> 159.127.184.216: F
hhonors.com -> 159.127.184.218: F

www.hilton.com -> 23.61.194.250: F (invalid security certificate)
www.hilton.com -> 23.61.194.49: F (invalid security certificate)

hilton.com -> ftcbco.hilton.com -> 167.187.200.23: F

We need a letter grade lower than F.
gqZJzU4vusf0Z2,$d7 is offline  
Old Mar 23, 2015, 7:30 pm
  #309  
 
Join Date: May 2001
Programs: AA PLT 2MM, LH SEN *, HH Gold
Posts: 3,075
Originally Posted by 1NetworkGuy
I changed (added) my password today (3/23). How long does it take to get the 1,000 bonus points?
Earlier in this thread Hilton stated:

"you will receive the 1,000 Bonus Points within six to eight weeks"
Hagbard Viking is offline  
Old Mar 23, 2015, 7:46 pm
  #310  
 
Join Date: Nov 2010
Posts: 646
Soup?
littlesheep is offline  
Old Mar 24, 2015, 8:24 am
  #311  
was jgoggan
 
Join Date: Jan 2012
Location: Michigan, USA
Programs: WN 650k+CP; BA 200k; AA 200k; HHonors 450k; IHG 300k Plat; Bonvoy 250k; Rad 225k
Posts: 203
Just tried to change my password and something is messed up still...

I went to the password change page, it accepted my new password, but when I submitted it to "continue" it took me right back to the password change page as if I hadn't done it.

I put it in again and tried to submit, and got:

"We experienced a temporary technical difficulty. Please try again."

They are really having some issues. This should not be that complex...

- John...
JohnMI is offline  
Old Mar 24, 2015, 5:01 pm
  #312  
 
Join Date: Feb 2013
Location: Somewhere In The Five Eyes
Posts: 229
> This should not be that complex ...

Proper web & I/T security is complex. It's soooo easy to get something slightly wrong ... that can be exploited into something big(ger). But Hilton is not getting things "slightly wrong." The web/IT and security mistakes that we know about ... reveal that things are "seriously wrong" in a number of areas.

Sadly; Hilton execs apparently hire & tolerate mediocrity. Or; Hilton execs are unwilling to pay the going rate for web professionals and I/T security professionals. (Very different skills) Example: Sony

There are so many obvious problems. Some of us have been trying to find someone at Hilton that will listen. I've had no success engaging intelligent life. Given Hilton's I/T history; I have zero.zero confidence that Hilton execs appreciate their situation.

The problems are now simply blood in the water. The crimeware industry is almost certainly dissecting Hilton's web properties. I expect that the exploits will get considerably worse in the short-term.

When their insurance company tires of writing checks to cover the inevitable losses ... perhaps then, Hilton execs will hire the necessary skilled professionals.

Last edited by gqZJzU4vusf0Z2,$d7; Mar 24, 2015 at 5:15 pm
gqZJzU4vusf0Z2,$d7 is offline  
Old Mar 24, 2015, 6:09 pm
  #313  
 
Join Date: Mar 2011
Programs: AA LifeTime PLT (2.982 MM, But 3MM+ Total), HHonors GOLD, IHG AMB
Posts: 787
Originally Posted by littlesheep
Soup?
Ktarian eggs. Second cabinet to the left.
Spock Seat is offline  
Old Mar 24, 2015, 9:17 pm
  #314  
 
Join Date: Feb 2003
Location: Brisbane (BNE), Australia, QF/VA Forums Meeting Organiser
Programs: VA Plat, QF Gold (97.4% LTG), QP Life, AA (66% LTG). HH Diamond. Amex Plat, Visa Plat
Posts: 6,519
Originally Posted by gqZJzU4vusf0Z2,$d7
> This should not be that complex ...

Proper web & I/T security is complex. It's soooo easy to get something slightly wrong ... that can be exploited into something big(ger). But Hilton is not getting things "slightly wrong." The web/IT and security mistakes that we know about ... reveal that things are "seriously wrong" in a number of areas.

Sadly; Hilton execs apparently hire & tolerate mediocrity. Or; Hilton execs are unwilling to pay the going rate for web professionals and I/T security professionals. (Very different skills) Example: Sony

There are so many obvious problems. Some of us have been trying to find someone at Hilton that will listen. I've had no success engaging intelligent life. Given Hilton's I/T history; I have zero.zero confidence that Hilton execs appreciate their situation.

The problems are now simply blood in the water. The crimeware industry is almost certainly dissecting Hilton's web properties. I expect that the exploits will get considerably worse in the short-term.

When their insurance company tires of writing checks to cover the inevitable losses ... perhaps then, Hilton execs will hire the necessary skilled professionals.
Nicely said, agree with all of it. Had to laugh at your Username though
QF WP is offline  
Old Mar 25, 2015, 7:36 am
  #315  
 
Join Date: Nov 2010
Posts: 646
Originally Posted by Spock Seat
Ktarian eggs. Second cabinet to the left.
I've never gotten a mini IQ test 'which pic is soup' before, which came instead of CAPTCHA on the HHonors log-in. it's true that I hate capthcha however it's spelled, but I'm not sure that my ability to log on to Hilton's site should be based on my culinary know-how.
littlesheep is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.