Go Back  FlyerTalk Forums > Travel&Dining > Travel Tools
Reload this Page >

AwardWallet Hack

Community
Wiki Posts
Search

AwardWallet Hack

Thread Tools
 
Search this Thread
 
Old Aug 1, 2015, 9:22 am
  #46  
 
Join Date: Sep 2012
Posts: 4,431
Originally Posted by veresch
The majority of the 250 accounts had the same username and password, we know what passwords they were trying to submit from the logs. They tried passwords like "password" or "1234567890".
I'm shocked that someone with multiple FF and/or hotel accounts would use passwords like this.
DaveInLA is offline  
Old Aug 1, 2015, 5:51 pm
  #47  
 
Join Date: May 2004
Posts: 253
Originally Posted by veresch
The majority of the 250 accounts had the same username and password, we know what passwords they were trying to submit from the logs. They tried passwords like "password" or "1234567890".
You log the failed passwords from failed login attempts in a log in clear text? That's not something you should be able to see. What about successful attempts, are those passwords logged as well?
lopinc1 is offline  
Old Aug 1, 2015, 11:06 pm
  #48  
Suspended
 
Join Date: Feb 2015
Location: The electrified part of North Carolina
Programs: UA GM, AA GM, DL GM
Posts: 4,157
For the FT members who have posted that their AW account was hacked, were you using "password" or "Password" as your account password, or was your password the same as your user name...?
UA1K_no_more is offline  
Old Aug 2, 2015, 2:07 pm
  #49  
Company Representative - AwardWallet
 
Join Date: Oct 2007
Posts: 56
Originally Posted by lopinc1
You log the failed passwords from failed login attempts in a log in clear text? That's not something you should be able to see. What about successful attempts, are those passwords logged as well?
Yes as soon as we noticed what what happening we started logging everything from those IPs.
veresch is offline  
Old Aug 3, 2015, 5:46 pm
  #50  
 
Join Date: Jan 2009
Location: Phoenix, AZ
Programs: AA lifetime Gold, United Gold, Marriott Gold, IHG Spire, Hertz Gold
Posts: 410
I was starting to sign up when I decided to look at Flyertalk real quickly to get feedback. Glad I did so...I will take a pass for now.
chrisphx is offline  
Old Aug 6, 2015, 1:08 am
  #51  
 
Join Date: Aug 2013
Location: USA
Programs: IHG/Spire Amb., Hilton/Diamond, SPG/Gold, Marriott/Gold, AA/Plat, Southwest/CP
Posts: 270
I was also a victim of this hack, and admittedly, I had a VERY insecure password.

I was aware of the dangers of giving it access to my accounts. There's no way it would be able to use those passwords repeatedly to get your balances if they weren't stored in a plain text format that the system could use to login to check those balances. It was my fault for not changing my AW password to something more secure after I started adding those.

I appreciated that AW caught this quickly and notified me before any damage was done. Good on them.
LaphroaigAndRibeye is offline  
Old Aug 6, 2015, 3:17 am
  #52  
 
Join Date: Jun 2004
Posts: 3,774
Originally Posted by Steven6702
I was also a victim of this hack, and admittedly, I had a VERY insecure password.

I was aware of the dangers of giving it access to my accounts. There's no way it would be able to use those passwords repeatedly to get your balances if they weren't stored in a plain text format that the system could use to login to check those balances. It was my fault for not changing my AW password to something more secure after I started adding those.

I appreciated that AW caught this quickly and notified me before any damage was done. Good on them.
Thanks for posting and sharing your experience. I'm a fairly new AW user and have strengthened my password based on the information in this thread.

One thing I wish AwardWallet had done was email all users that there had been a very limited security breach and suggesting that all users reinforce good password practice.

Had I not read this on FT, I would not have known and may have been the next victim. I understand why they may have only wished to notify the 250 affected account holders as they didn't want to generate massive panic, but I would have very much appreciated an approach of full disclosure so other potential victims would have time to take appropriate action to secure their accounts.
SusanDK is offline  
Old Aug 25, 2015, 12:43 am
  #53  
 
Join Date: Sep 2004
Posts: 973
Has my award wallet account been hacked??

Today I received an email from award wallet advised changes to scheduled flight times for JL flight from ICN to NRT next March. Howevever I checked JAL website and AA website (I booked tickets thru AA) and there was no such changes!

Has anyone received such strange email?
A1pax is offline  
Old Jan 4, 2016, 8:31 pm
  #54  
 
Join Date: Apr 2001
Location: Austin
Programs: AA P4L, WN, BA, DL, UA, HHonors, IHG
Posts: 3,485
How to Turn Off 2-Factor Authentication?

A few weeks ago I turned on 2-factor in AW, but now I'd like to turn it back off. How can that be done?

ANSWER: Ten minutes before posting this, an email was sent to me from Award Wallet stating that 2-factor had been turned off. Does someone there have psychic powers??

Last edited by Middle_Seat; Jan 4, 2016 at 8:47 pm
Middle_Seat is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.