Community
Wiki Posts
Search

New Marriott Security Measures

 
Thread Tools
 
Search this Thread
 
Old Jul 17, 2015 | 2:33 pm
  #31  
 
Join Date: Jan 2011
Location: Buffalo, NY
Programs: Marriott Plat, Delta Gold, United Silver
Posts: 66
Originally Posted by KRSW
My gripe is that most 2-factor auths are done via SMS(Text message for the Yanks). Nice if I'm in my home country, but if I'm abroad I usually have yanked the SIM on my mobile and am using a local SIM instead. Also, depending on what I'm working on, my mobile phone might not be allowed to be carried with me.
So you are in an environment where a cellphone (oh, sorry, mobile phone for you non yanks ) is not allowed...I get that, I've been there, but access to Marriott.com in that same secure zone is not an issue? Not likely.
jesternl is offline  
Old Jul 17, 2015 | 2:49 pm
  #32  
FlyerTalk Evangelist
20 Years on Site
 
Join Date: Nov 2003
Location: South Florida
Programs: AA LTG (EXP), Hilton Silver (Dia), Marriott LTP (PP), SPG LTG (P) > MPG LTPP
Posts: 11,329
Originally Posted by KRSW
...
My gripe is that most 2-factor auths are done via SMS(Text message for the Yanks). Nice if I'm in my home country, but if I'm abroad I usually have yanked the SIM on my mobile and am using a local SIM instead. Also, depending on what I'm working on, my mobile phone might not be allowed to be carried with me.
If this is a frequent issue, then maybe look into using a Google Voice number as your MR contact. I do believe you can pick up and send SMS messages via your laptop should the phone not be working or available.

I'm hoping the 2FA will be limited to redemptions only. Otherwise, it's an overkill for a loyalty program.
RogerD408 is offline  
Old Jul 17, 2015 | 10:08 pm
  #33  
10 Countries Visited
20 Countries Visited
30 Countries Visited
10 Years on Site
 
Join Date: Jul 2011
Location: Waxahachie, TX
Programs: WN 3 Million Miler, MR Lifetime Titanium, HH Diamond, IHG Plat, AA Silver, United never again
Posts: 509
I put a PIN on my account after a friend lots points for some bogus reservations. It isn't 2FA but it adds a slight delay for the question to be asked and answered.

I don't foresee a problem except overseas or in secure installations.
Texas Booster is offline  
Old Jul 19, 2015 | 12:38 pm
  #34  
1P
All eyes on you!
25 Years on Site
 
Join Date: Apr 2000
Location: LAX and LHR. UA lifetime Gold 1.9MM 1K , DL Gold Medallion, HHonors Gold, Marriott Gold, Avis President's Club
Posts: 3,654
Originally Posted by Kingston
Whether you use it or not, your UA account has a 4 digit PIN associated to.
All of them do, even if you didn't set it.
That 4 digit number and your MP # are all it takes to get in to your account.
This is completely untrue. United have spent the past year and more trying to
persuade me and many others to add a PIN to our accounts instead of/in addition to a password, just because pre-merger Continental customers had them. We have steadfastly refused to do so on security grounds. We have never had PINs and will not agree to invent them. My pre-merger United 2-digit 6-letter password is infinitely better security than any 4-digit PIN.

Last edited by 1P; Jul 19, 2015 at 1:00 pm
1P is offline  
Old Jul 19, 2015 | 3:19 pm
  #35  
30 Countries Visited
2M
100 Nights
20 Years on Site
 
Join Date: Feb 2005
Location: PHL
Programs: AA EXP MM, HHonors Lifetime Diamond, Marriott Lifetime Ti, UA Silver
Posts: 5,216
Originally Posted by jesternl
So you are in an environment where a cellphone (oh, sorry, mobile phone for you non yanks ) is not allowed...I get that, I've been there, but access to Marriott.com in that same secure zone is not an issue? Not likely.
It happens. A lot more often than you might imagine.
PHLGovFlyer is offline  
Old Jul 20, 2015 | 6:43 am
  #36  
A FlyerTalk Posting Legend
20 Countries Visited
3M
Conversation Starter
20 Years on Site
 
Join Date: Aug 2002
Programs: UALifetimePremierGold, Marriott LifetimeTitanium
Posts: 74,162
Originally Posted by Texas Booster
I put a PIN on my account after a friend lots points for some bogus reservations. It isn't 2FA but it adds a slight delay for the question to be asked and answered.

I don't foresee a problem except overseas or in secure installations.
I added the 4-digit PIN security pin to my Marriott account so if someone (including me) tries to reserve an award ressie via phone then they have to provide the PIN. My password is also really long.

Originally Posted by 1P
This is completely untrue. United have spent the past year and more trying to
persuade me and many others to add a PIN to our accounts instead of/in addition to a password, just because pre-merger Continental customers had them. We have steadfastly refused to do so on security grounds. We have never had PINs and will not agree to invent them. My pre-merger United 2-digit 6-letter password is infinitely better security than any 4-digit PIN.
Agree. I've never had a PIN on my United account, although I heard that CO had them. My United password is really long & contains #s/letters. Will it totally protect against a brute force attack? No, but mine has a better chance of surviving it than someone who just has a PIN.

Cheers.
SkiAdcock is offline  
Old Jul 20, 2015 | 8:00 am
  #37  
FlyerTalk Evangelist
10 Countries Visited
20 Countries Visited
30 Countries Visited
20 Years on Site
 
Join Date: Jun 2004
Location: MSP
Programs: DL PM, MM, NR; HH Diamond, Bonvoy LT Gold, Hyatt Explorist, IHG Diamond, others
Posts: 12,163
Originally Posted by SkiAdcock
So basically Marriott is asking you to provide a phone number and email to get ready for their new authentication. Presumably if you already have that and you'r e happy with it there should be no problem.

Fwiw - I thought Marriott was going to ask for a stronger password. If hackers can already access my account, they'd already have my email and phone number.
There's a major difference between someone having (knowing) my phone # or email address, and them being able to read texts sent to them.
sethb is offline  
Old Jul 20, 2015 | 11:59 am
  #38  
 
Join Date: Jan 2006
Posts: 134
Originally Posted by 1P
This is completely untrue. United have spent the past year and more trying to
persuade me and many others to add a PIN to our accounts instead of/in addition to a password, just because pre-merger Continental customers had them. We have steadfastly refused to do so on security grounds. We have never had PINs and will not agree to invent them. My pre-merger United 2-digit 6-letter password is infinitely better security than any 4-digit PIN.
If you say so. It's the same IT system. My money is on you having one, whether you added one or not.
Kingston is offline  
Old Jul 21, 2015 | 4:03 pm
  #39  
1P
All eyes on you!
25 Years on Site
 
Join Date: Apr 2000
Location: LAX and LHR. UA lifetime Gold 1.9MM 1K , DL Gold Medallion, HHonors Gold, Marriott Gold, Avis President's Club
Posts: 3,654
Originally Posted by Kingston
If you say so. It's the same IT system. My money is on you having one, whether you added one or not.
My money says that if I tried to add my own, and I did actually already have one, the system would then lock me out....
1P is offline  
Old May 11, 2016 | 3:40 pm
  #40  
All eyes on you!
20 Years on Site
 
Join Date: Mar 2003
Location: SAN
Programs: AS Titanium (100K), Hyatt Globalist, Marriott Lifetime Titanium Elite, UA 1MM,
Posts: 1,841
I attempted a password reset and the whole "we will email you a code" thing put me in an errored loop. Now, when I attempt either the new or old password, I get an error message that they are experiencing technical difficulties.
JC5280 is offline  
Old May 11, 2016 | 3:50 pm
  #41  
All eyes on you!
20 Years on Site
 
Join Date: Feb 2006
Location: Cockeysville, MD
Programs: Marriott Rewards Lifetime Titanium, Amex Plat, Hertz Gold 5*, National Exec, AA Plat
Posts: 9,502
Originally Posted by JC5280
I attempted a password reset and the whole "we will email you a code" thing put me in an errored loop. Now, when I attempt either the new or old password, I get an error message that they are experiencing technical difficulties.
I am in good company. Same here. I called MR Cust Svc. Too much website traffic crashing servers. They can't tell me which password will work. Just that it should all shake out tomorrow.
Mr. Vker is offline  
Old May 12, 2016 | 6:18 am
  #42  
20 Countries Visited
1M
All eyes on you!
15 Years on Site
 
Join Date: Dec 2009
Location: PEK & MKE
Programs: Amex-gold, Hainan-gold, Mrt-LT Titanium
Posts: 1,534
+3, so true

Originally Posted by Jiatong
+3

Damn those web based MBA consultants who work for Mrt, they know how to run the meter !
Damn the MBA's at Mrt !
Jiatong is offline  
Old May 12, 2016 | 7:05 am
  #43  
 
Join Date: Apr 2016
Programs: IHG Rewards Club, Marriott Rewards
Posts: 78
I wish these loyalty programs had a way to disable "shop" redemptions, like buying a computer with points for example. I will NEVER trade my IHG or Marriott points for something like that.
StevensFirstPrints is offline  
Old May 12, 2016 | 7:27 am
  #44  
FlyerTalk Evangelist
20 Years on Site
 
Join Date: Nov 2003
Location: South Florida
Programs: AA LTG (EXP), Hilton Silver (Dia), Marriott LTP (PP), SPG LTG (P) > MPG LTPP
Posts: 11,329
Originally Posted by StevensFirstPrints
I wish these loyalty programs had a way to disable "shop" redemptions, like buying a computer with points for example. I will NEVER trade my IHG or Marriott points for something like that.
I doubt we will ever see a "build your own" program. I agree those are not great payback options. But I can see someone that has earned mega points and finds they have no way to burn them on stays, they may choose to use them to get something they don't want to spend $s.

Everyone has their own pluses and minuses. No need to cancel something just because it's no use to you. I'm not likely to stay at a RC property, so should they drop the brand?
RogerD408 is offline  
Old May 12, 2016 | 2:38 pm
  #45  
 
Join Date: Apr 2016
Programs: IHG Rewards Club, Marriott Rewards
Posts: 78
Originally Posted by RogerD408
I doubt we will ever see a "build your own" program. I agree those are not great payback options. But I can see someone that has earned mega points and finds they have no way to burn them on stays, they may choose to use them to get something they don't want to spend $s.

Everyone has their own pluses and minuses. No need to cancel something just because it's no use to you. I'm not likely to stay at a RC property, so should they drop the brand?


Just an idea, though I do think its a good one.
StevensFirstPrints is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.