![]() |
Originally Posted by nux
(Post 25196379)
Yes, but the fact that AwardWallet displays all stored passwords in plain text is a major system weakness. There is no reason to do this.
If the passwords were not displayed in plain text then a hack on AwardWallet accounts would not allow access to the account username/passwords of all accounts tracked within (except if the password for those is the same). |
Originally Posted by nux
(Post 25196379)
Yes, but the fact that AwardWallet displays all stored passwords in plain text is a major system weakness. There is no reason to do this.
If the passwords were not displayed in plain text then a hack on AwardWallet accounts would not allow access to the account username/passwords of all accounts tracked within (except if the password for those is the same). |
Originally Posted by nux
(Post 25196379)
Yes, but the fact that AwardWallet displays all stored passwords in plain text is a major system weakness. There is no reason to do this.
If the passwords were not displayed in plain text then a hack on AwardWallet accounts would not allow access to the account username/passwords of all accounts tracked within (except if the password for those is the same). The plaintext passwords are ordinarily masked. AwardWallet asks for your AW password as a double confirmation before showing them. Of course, if the user password is weak, then the double confirmation doesn't make it any more secure. I think their major mistake was in allowing members to use weak passwords, but I wouldn't blame them on the system design or displaying plaintext password. Both of which appears to be secure, had the user chosen a reasonably strong password. Bottomline - no system in the world is be safe if the user choses a weak password. |
Hmm. I was just able to log in and disable two-factor, without needing my two-factor code.
Kinda defeats the purpose. |
I wasn't one of the 250+ who got the email. Should I change all my passwords too? Or just my AW password?
|
for me I didnt had a weak Password and username.
|
change all passwords and cancell your membership, better to be on the save side than maybe lossing all your hard earned miles.
|
dont forget the massive Iberia and BA Accounts (mine of course too:(
hacked , back in March this year. Which a lot of people think that Award Wallet was the source and got hacked . Think twice before giving away your valuable passwords to a company we dont really know. I myself have learned my lession. |
Originally Posted by veresch
(Post 25194301)
...
(2) accounts whose passwords were not unique to AwardWallet and were already compromised via different website, or passwords that were easily guessable, like abcd. ...
Originally Posted by WORLDWIDE TRAVELER
(Post 25196623)
for me I didnt had a weak Password and username.
|
easy Answer is NO , and I had different Passwords for all of my 73 Accounts stored with them.
|
Originally Posted by josephstern
(Post 25196486)
Hmm. I was just able to log in and disable two-factor, without needing my two-factor code.
Kinda defeats the purpose. The best solution would be if AW requires another prompt for a two-factor password in order to display a clear-text loyalty password. This way even if a user did something dumb like leave their account logged in on a public computer, the clear text password wouldn't be displayed without another two-factor confirmation. Also keep in mind that just because the loyalty passwords are being shown to you clear-text, doesn't mean they are stored that way. They have to be readable so AW can use them to check your points balance, so they can't be hashed, but I'll bet they are stored encrypted in their DB. |
Originally Posted by lopinc1
(Post 25197729)
If you were already logged in (via remembered cookies) then you wouldn't be prompted for the two-factor code. The two-factor code is used when you log in on that browser initially.
This is pretty insecure. |
Originally Posted by ckpeter
(Post 25196305)
They have already clarified that there was not a system weakness.
Further comments have highlighted the lack of password re-entry requirement for the display of saved passwords - sounds to me like another system weakness.
Originally Posted by ckpeter
(Post 25196305)
Given that someone guessed your (weak?) password and got all your account information, I would say AwardWallet would be invaluable in tracking down rogue redemptions.
|
Originally Posted by Andrew.Smith
(Post 25198424)
I would say that a failure to require users to set complex passwords is a clear system weakness.
Further comments have highlighted the lack of password re-entry requirement for the display of saved passwords - sounds to me like another system weakness. I agree that AW can be incredibly useful. Maybe they should only operate on the "locally saved" password basis. Thankfully I set-up my AW account like that from the start :) Just to clarify though, AW does force you to re-enter the master password before displaying your saved account password, so that part is secure. |
Originally Posted by StartinSanDiego
(Post 25196232)
This is serious. How are they able to reassure the rest of us?
But allowing a password to equal your id is simply unacceptable - for both the user and the vendor. |
| All times are GMT -6. The time now is 7:13 am. |
This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.