Community
Wiki Posts
Search

Whoa! Password Reset WAY too easy

Thread Tools
 
Search this Thread
 
Old Dec 10, 2018, 3:06 pm
  #1  
Original Poster
 
Join Date: Jun 2009
Location: SAN
Programs: DL DM / 2MM - Marriott Ambassador
Posts: 1,515
Whoa! Password Reset WAY too easy

So I could not find a place to change my password online. I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password. I did not even have to know my existing password. This was WAY too easy and doesn't this just make it that much easier to hack someones account? WTH?
lucycan is offline  
Old Dec 10, 2018, 3:43 pm
  #2  
Moderator, Marriott Bonvoy & FlyerTalk Evangelist
 
Join Date: Oct 2002
Location: McKinney, TX, USA
Programs: United Silver; AA Plat/2MM; Marriott LT Titanium; Hilton Gold
Posts: 11,727
You should set up a PIN for your account. Then before the agent could even pull up your account, you have to provide them with your PIN.
hhoope01 is offline  
Old Dec 10, 2018, 5:09 pm
  #3  
A FlyerTalk Posting Legend
 
Join Date: Aug 2002
Programs: UALifetimePremierGold, Marriott LifetimeTitanium
Posts: 71,107
Originally Posted by hhoope01
You should set up a PIN for your account. Then before the agent could even pull up your account, you have to provide them with your PIN.
This. I've had a PIN on my account for years.
SkiAdcock is offline  
Old Dec 10, 2018, 7:27 pm
  #4  
FlyerTalk Evangelist
 
Join Date: Jan 2007
Location: BOS/UTH
Programs: AA LT PLT; QR GLD; Bonvoy LT TIT
Posts: 12,753
Originally Posted by lucycan
I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password.
What were the questions?
Dr. HFH is offline  
Old Dec 10, 2018, 7:34 pm
  #5  
FlyerTalk Evangelist
 
Join Date: May 2015
Location: BOS, YVR, ZRH
Programs: *G
Posts: 17,392
Originally Posted by lucycan
So I could not find a place to change my password online. I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password. I did not even have to know my existing password. This was WAY too easy and doesn't this just make it that much easier to hack someones account? WTH?
If knowing your existing password was required to reset your password.... that'd be problematic
Smiley90 is offline  
Old Dec 10, 2018, 7:40 pm
  #6  
 
Join Date: Apr 2007
Location: Australia
Posts: 6,338
Originally Posted by Smiley90
If knowing your existing password was required to reset your password.... that'd be problematic
This. I have ONLY ever wanted to reset a password after forgetting the current one!
trooper is offline  
Old Dec 10, 2018, 8:08 pm
  #7  
 
Join Date: Dec 2009
Location: COS
Programs: UA Gold/1.5MM (several years running now!), Marriott LTTE, Hertz Prez
Posts: 1,899
Originally Posted by trooper
This. I have ONLY ever wanted to reset a password after forgetting the current one!
Well to be fair, the rationale here probably has to do with resetting the password due to the massive data breach, not so much having forgot it.
CCIE_Flyer is offline  
Old Dec 10, 2018, 8:29 pm
  #8  
 
Join Date: Dec 2007
Location: SFO
Posts: 4,912
Originally Posted by lucycan
So I could not find a place to change my password online. I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password. I did not even have to know my existing password. This was WAY too easy and doesn't this just make it that much easier to hack someones account? WTH?
so they sent you a link to your email address on file or an email you provided during the call? If on file, then it’s like any other password reset I’ve seen (non 2 factor resets)
smc333, CPRich and writerguyfl like this.
myperks is offline  
Old Dec 10, 2018, 10:04 pm
  #9  
Marriott Contributor Badge
 
Join Date: Jan 2009
Location: TUL
Programs: AA EXP 2MM; Marriott Titanium; Hilton Diamond; Hyatt Explorist; Vistana 5* Elite; Nat'l Exec Elite
Posts: 6,177
This is what I'm most concerned about.

Originally Posted by lucycan
So I could not find a place to change my password online.
1) Sign into your account.
2) Click on your name in the upper right corner.
3) Click on "Profile".
4) Click on "Change Password"

That's all folks!
controller1 is offline  
Old Dec 10, 2018, 10:07 pm
  #10  
 
Join Date: Mar 2002
Location: London, Vancouver, Tokyo, San Francisco, NYC
Posts: 265
The problem is when your email is hacked
cozysuite is offline  
Old Dec 11, 2018, 1:10 am
  #11  
FlyerTalk Evangelist
 
Join Date: Apr 2009
Location: India
Programs: Bonvoy Lifetime Titanium, IHG Plat, HH Gold, Trident Plat, DL Diamond, AI Maharajah
Posts: 29,668
Originally Posted by lucycan
So I could not find a place to change my password online. I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password. I did not even have to know my existing password. This was WAY too easy and doesn't this just make it that much easier to hack someones account? WTH?
isn't think what pretty much every company does????they ask you a couple of security questions to verify your identity & then send you a link on your registered email address....
margarita girl and CPRich like this.
Keyser is online now  
Old Dec 11, 2018, 7:20 am
  #12  
FlyerTalk Evangelist
 
Join Date: Nov 2003
Location: South Florida
Programs: AA LTG (EXP), Hilton Silver (Dia), Marriott LTP (PP), SPG LTG (P) > MPG LTPP
Posts: 11,329
Originally Posted by cozysuite
The problem is when your email is hacked
Nothing is 100% foolproof. Many sites I use allow a request to reset the password without any challenge and an email shows up minutes later. Until someone gets burned, computer security rarely gets an afterthought.
RogerD408 is offline  
Old Dec 11, 2018, 9:40 am
  #13  
 
Join Date: Aug 2007
Programs: DL DM
Posts: 1,079
Originally Posted by lucycan
So I could not find a place to change my password online. I called the Plat line and they asked two very simple questions (that anyone would probably know) and sent me a link directly to reset the password. I did not even have to know my existing password. This was WAY too easy and doesn't this just make it that much easier to hack someones account? WTH?
Originally Posted by Smiley90
If knowing your existing password was required to reset your password.... that'd be problematic
It would certainly make the resetting process more secure
cre95 is offline  
Old Dec 11, 2018, 10:13 am
  #14  
 
Join Date: Nov 2008
Programs: SPG-Plat, Hilton-Diamond, Club Carlson-Silver, Cathay-Diamond, Virgin-Gold
Posts: 2,183
Sorry if the link was sent to your email on file there really is no issue here as most companies will do that just by clicking reset password, so by having 2 questions to answer it was actually more difficult than most!
UKTraveller4Fun is offline  
Old Dec 13, 2018, 1:34 pm
  #15  
 
Join Date: Jun 2009
Location: LAX
Programs: UA 1K/MM, Marriott Gold
Posts: 132
Originally Posted by controller1
This is what I'm most concerned about.



1) Sign into your account.
2) Click on your name in the upper right corner.
3) Click on "Profile".
4) Click on "Change Password"

That's all folks!
I just found this thread after searching issues changing Marriott passwords.

When I go to my profile get the following message: We're temporarily unable to display the information requested"

I mean really. Huge data breach - a link to change your password should be on the front page. I'm changing my password as this breach finally made me make the move to a password manager so I need to change all my passwords.

After 10 minutes on the phone with Marriott (mostly on hold) they sent me a link to reset my password. No security questions nothing. I have the same concerns as the OP.
elynchking is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.