Go Back  FlyerTalk Forums > Miles&Points > Discontinued Programs/Partners > Marriott | Rewards
Reload this Page >

New "enhancement" - Marriott arbitrarily changes password

Community
Wiki Posts
Search

New "enhancement" - Marriott arbitrarily changes password

 
Thread Tools
 
Search this Thread
 
Old Feb 27, 2014 | 6:45 am
  #1  
Original Poster
30 Countries Visited
50 Countries Visited
3M
20 Years on Site
 
Join Date: Aug 2004
Location: DCA, EGE, IAD
Programs: MR LTT, BA Gold, AA LTP, UA Silver
Posts: 6,094
Exclamation New "enhancement" - Marriott arbitrarily changes password

OK, I did a search on "password" before posting this. Another amazing enhancement brought to us by the idiots at Marriott.

My password was changed from a mix of lower and upper case to all upper case (and numbers). I have been using this password for a few months, logging in numerous times each week, so it's not like I forgot it. Today I was unable to log in. Had them email me my password and it was identical to my password, but all in upper case.

Just a heads up for rest of you.
aaupgrade is offline  
Old Feb 27, 2014 | 8:06 am
  #2  
FlyerTalk Evangelist
40 Countries Visited
5M
100 Nights
20 Years on Site
 
Join Date: May 2002
Location: Pittsburgh
Programs: MR LT Titanium, AA LT PLT, UA SLV, Avis PreferredPlus, HH Gold, Hertz PC, National Executive, etc.
Posts: 31,687
It must be something special for you, because mine is fine.
CPRich is offline  
Old Feb 27, 2014 | 8:09 am
  #3  
FlyerTalk Evangelist
20 Countries Visited
2M
All eyes on you!
15 Years on Site
 
Join Date: Mar 2010
Location: DAY
Programs: UA 1K 1MM; Marriott LT Titanium; Amex MR; Chase UR; Hertz PC; Global Entry
Posts: 11,458
Originally Posted by aaupgrade
OK, I did a search on "password" before posting this. Another amazing enhancement brought to us by the idiots at Marriott.

My password was changed from a mix of lower and upper case to all upper case (and numbers). I have been using this password for a few months, logging in numerous times each week, so it's not like I forgot it. Today I was unable to log in. Had them email me my password and it was identical to my password, but all in upper case.

Just a heads up for rest of you.
That seems rather bizarre. Any chance you have been taken in by phishing or other type of scam?

I would browse securely and directly to the Marriott site and change my password if I were in your shoes. Also, keep an eye on account activity, balances and the like.

Good luck.

Last edited by goodeats21; Feb 27, 2014 at 2:19 pm
goodeats21 is offline  
Old Feb 27, 2014 | 8:24 am
  #4  
All eyes on you!
20 Years on Site
 
Join Date: Oct 2001
Programs: LTP, PP
Posts: 9,110
Mine is fine too, that seems odd. When sites force you to change a password, they normally lock you out until you select another of your choosing.

Definitely sum ting wong...
joshua362 is offline  
Old Feb 27, 2014 | 8:48 am
  #5  
FlyerTalk Evangelist
20 Years on Site
 
Join Date: Nov 2003
Location: South Florida
Programs: AA LTG (EXP), Hilton Silver (Dia), Marriott LTP (PP), SPG LTG (P) > MPG LTPP
Posts: 11,329
Actually, I remember hitting something like this not too long ago. It turns out Marriott passwords are CASE INSENSITIVE! I get so frustrated by sites coming up with password rules that you must write passwords down to be able to remember them if you don't use them everyday.

I just tried three possibilities for my password, as entered, all upper-case, and all lower-case. Even mixed case worked! They all allowed me into my account.

I guess that goes along with their process of flagging my account because my email user name is Marriott. I was told I can't use that... ummmm
RogerD408 is offline  
Old Feb 27, 2014 | 9:16 am
  #6  
All eyes on you!
10 Years on Site
 
Join Date: Feb 2012
Location: Helsinki (Finland)
Programs: IHG Plat, Marriott Plat
Posts: 486
Originally Posted by CPRich
It must be something special for you, because mine is fine.
Marriott has more than two Rewards members.

Anyways, mine is fine, too.

Couple of months back they had somehow activated my old password even if I had changed it several months earlier and used many times.
FinnishFlash is offline  
Old Feb 27, 2014 | 9:20 am
  #7  
All eyes on you!
10 Years on Site
 
Join Date: Feb 2012
Location: Helsinki (Finland)
Programs: IHG Plat, Marriott Plat
Posts: 486
Originally Posted by aaupgrade
Had them email me my password and it was identical to my password, but all in upper case.
Did they really e-mail you your password?

Reason for all being upper case is probably because their database where passwords are stored is case-insensitive, ie when they pull up your data, it's all in upper-case and when you log in the case doesn't seem to matter at all. Any case seems to be ok as long as you enter right characters.

E: RogerD408 actually told all this already but still, I think it's a breach of security to not store, and use, passwords with case-sensitivity.

Last edited by FinnishFlash; Feb 27, 2014 at 9:27 am
FinnishFlash is offline  
Old Feb 27, 2014 | 10:35 am
  #8  
 
Join Date: Apr 2001
Posts: 1,386
Mine hasn't changed, either.

However, about a year ago I was prompted to change mine, from all letters to something that was either a minimum length or that had at least one non-letter. I forget the exact details but I was able to change it from (for example) "freak" to "freak12". It was definitely after I had logged in under my old password.
Frequent Freak is offline  
Old Feb 27, 2014 | 12:48 pm
  #9  
10 Years on Site
 
Join Date: Nov 2013
Programs: HH Diamond, IHG Spire, Marriott Gold, AA Plat. Pro
Posts: 401
Originally Posted by aaupgrade
OK, I did a search on "password" before posting this. Another amazing enhancement brought to us by the idiots at Marriott.

My password was changed from a mix of lower and upper case to all upper case (and numbers). I have been using this password for a few months, logging in numerous times each week, so it's not like I forgot it. Today I was unable to log in. Had them email me my password and it was identical to my password, but all in upper case.

Just a heads up for rest of you.
How did they email you your password? There should be no way they can see your password. And if they emailed it, which is completely against IT best practices, I would change it to something completely different.

If they can view your email in plain text that's a huge security issue.
HansGruber is offline  
Old Feb 27, 2014 | 12:57 pm
  #10  
10 Years on Site
 
Join Date: Nov 2013
Programs: HH Diamond, IHG Spire, Marriott Gold, AA Plat. Pro
Posts: 401
Originally Posted by RogerD408
Actually, I remember hitting something like this not too long ago. It turns out Marriott passwords are CASE INSENSITIVE! I get so frustrated by sites coming up with password rules that you must write passwords down to be able to remember them if you don't use them everyday.

I just tried three possibilities for my password, as entered, all upper-case, and all lower-case. Even mixed case worked! They all allowed me into my account.

I guess that goes along with their process of flagging my account because my email user name is Marriott. I was told I can't use that... ummmm
I just tried the same thing. Case sensitivity isn't a huge security issue but I'd be curious if they are stored in plain text, which is.
HansGruber is offline  
Old Feb 27, 2014 | 1:17 pm
  #11  
Original Poster
30 Countries Visited
50 Countries Visited
3M
20 Years on Site
 
Join Date: Aug 2004
Location: DCA, EGE, IAD
Programs: MR LTT, BA Gold, AA LTP, UA Silver
Posts: 6,094
You can click on forgot password and there is an option for them to send you your password. I copied ad pasted the password from their email in order to log on.

Marriott not requiring passwords to be case sensitive is totally against IT best practices. It explains why my password appeared in upper case in their email. But why couldn't I log in, 3 attempts, with it in mixed case? That's a rhetorical question. Yes, caps lock was off on all 3 attempts.

As others have noted, emailing password is is also against IT best practices.

I work in the IT field, and yes I have changed my password to something completely different.

FWIW, the first thing I checked was mileage balances, reservations, etc and all were fine. As far as phishing, I NEVER click on any links in email, so little chance of me be phished.

Perhaps this is just an isolated case of their security being down for a breif period when I was attempting to log in. Anyway, thought I should mention it to the forum just in case it wasn't.

At least it did alert us to their shoddy security practices. Of course as many of use old timers are aware that doesn't come as a surprise with the inept Marriott Marketing, oops I mean IT department. Even though their web site comes up lacking from a functional and user friendly perspective, at least it looks good and requires lots of scrolling down and extra mouse clicks, and we all know that is all that matters to Marriott.
aaupgrade is offline  
Old Feb 28, 2014 | 8:48 am
  #12  
 
Join Date: Dec 2004
Location: AUS
Posts: 690
Originally Posted by aaupgrade
Marriott not requiring passwords to be case sensitive is totally against IT best practices.
Case-insensitive passwords aren't a huge problem. (It's about the same as a password one letter shorter.) American Express does the same thing. (IHG doesn't even do passwords, just four-digit PIN numbers, with the obvious result.)

As others have noted, emailing password is is also against IT best practices.
Yes, this is the really stupid part.

Originally Posted by joshua362
When sites force you to change a password, they normally lock you out until you select another of your choosing.
That's probably the main concern. If they did a standard password reset (where the old password stops working immediately) then customers without access to their email account (while traveling in a foreign country) would be up the creek if anyone reset their password.
Moriens is offline  
Old Feb 28, 2014 | 10:59 am
  #13  
A FlyerTalk Posting Legend
40 Countries Visited
60 Nights
5M
15 Years on Site
 
Join Date: Sep 2009
Location: Minneapolis: DL DM charter 2.3MM
Programs: A3*Gold, SPG Plat, HyattDiamond, MarriottPP, LHW exAccess, ICI, Raffles Amb, NW PE MM, TWA Gold MM
Posts: 102,617
Originally Posted by Frequent Freak
Mine hasn't changed, either.

However, about a year ago I was prompted to change mine, from all letters to something that was either a minimum length or that had at least one non-letter. I forget the exact details but I was able to change it from (for example) "freak" to "freak12". It was definitely after I had logged in under my old password.
I remember having to pick a new password with at least eight characters, but symbols weren't allowed.
MSPeconomist is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.