Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > United Airlines | MileagePlus
Reload this Page >

Suspended MP Accounts / Username Access Disabled / 3rd Party Security Breach-Dec 2014

Suspended MP Accounts / Username Access Disabled / 3rd Party Security Breach-Dec 2014

Old Dec 27, 14, 10:30 pm
  #16  
Moderator: Smoking Lounge; FlyerTalk Evangelist
 
Join Date: Feb 2004
Location: SFO
Programs: Lifetime (for now) Gold MM, HH Gold, Giving Tootsie Pops to UA employees, & a retired hockey goalie
Posts: 28,728
No email for me either and I am unable to log in using any combination of my mp#/email/username and password/pin nor can I log in for goalie-dad, goalie-mom and goalie-sis using their creds (mp#/email/username and pin/password)
goalie is offline  
Old Dec 27, 14, 11:40 pm
  #17  
 
Join Date: Dec 2002
Location: SFO
Posts: 3,571
There's an entire thread dedicated to this topic
malgudi is offline  
Old Dec 28, 14, 12:35 am
  #18  
Moderator: United Airlines; FlyerTalk Evangelist
 
Join Date: Jun 2007
Location: SFO
Programs: UA Plat 1.85MM, Hyatt Discoverist, Marriott Plat/LT Gold, Hilton Silver, IHG Plat
Posts: 59,475
Originally Posted by malgudi View Post
There's an entire thread dedicated to this topic
No sure they are the same -- the UA notice refers to approximately 24 Dec and the other thread was much earlier in the month. I suggest we keep these threads separate until we know one way or the other.

WineCountryUA
UA coModerator
WineCountryUA is offline  
Old Dec 28, 14, 4:22 am
  #19  
 
Join Date: Jun 2005
Posts: 4
Better check your PayPal account

Originally Posted by villox View Post
Here's the full email. I actually took the email to mean they had detected that someone had specifically accessed my account. I also thought I was going to have to change the password via the agent, but all the agent did was re-activate my account so I could quickly login and change everything myself.
What those email notifications probably mean is that you are on a list somewhere that has been taken from another website (3rd party).

Do you use the same user ID (i.e. email address) and password for multiple accounts?

I would strongly suggest you check and change any other accounts where you have used that same login. Many companies won't be sophisticated enough to identify this type of threat. And some may not be as concerned as they should be since it isn't really their system being compromised.

http://mashable.com/2014/09/10/5-mil...asswords-leak/
http://www.dailydot.com/politics/ano...-credit-cards/
http://www.forbes.com/sites/adamtann...e-been-hacked/

Last edited by cosiz; Dec 28, 14 at 6:04 am
cosiz is offline  
Old Dec 28, 14, 8:22 am
  #20  
 
Join Date: Jun 2010
Location: Minneapolis, MN
Programs: DL, AA, UA, SPG Gold, HH Gold, IHG Platinum, Marriott Silver
Posts: 471
Originally Posted by Phanto View Post
Here's the kicker..

I have a VERY secure username AND password set on my account, BUT I can't use them! The only thing that works and allows me to login is my MP account # and my super lame 4 digit PIN! I should be able to say allow access via one or the other, but not BOTH or in my case simply the MP/PIN combo since my account/pass don't work anyway. Why am I even able to set them if I can't use them AND you still allow the other to login anyway??

It seems that a number of airlines do this, why is their security SOOOOO crappy??

Ya know, I'm in a mood so I'm going to write them a nice little note!

-Phanto
I have the same situation as you. Can login using MP # and pin, but cannot use username and password (changed both). Is this an ongoing tech issue or a security concern? I never received any email saying my account was compromised so I'm not sure how to proceed.
greenythebeast is offline  
Old Dec 28, 14, 8:25 am
  #21  
 
Join Date: Jun 2010
Location: Minneapolis, MN
Programs: DL, AA, UA, SPG Gold, HH Gold, IHG Platinum, Marriott Silver
Posts: 471
Is anyone else not able to login using their username and password? I can only login using my MP # and PIN.
greenythebeast is offline  
Old Dec 28, 14, 9:51 am
  #22  
A FlyerTalk Posting Legend
 
Join Date: Apr 2013
Location: PHX/SFO
Programs: AA EXP; AS 75K; WN A List; UA 1K 1MM; Hyatt Globalist; Marriott AMB; Hilton Diamond (Aspire)
Posts: 49,949
I just got red text stating:

(username and e-mail address sign-on are currently unavailable)

Still able to sign in with MP number and PIN.
Kacee is offline  
Old Dec 28, 14, 11:17 am
  #23  
 
Join Date: Dec 2014
Location: IAH
Programs: UA 1K, Marriott Plat, Global Entry
Posts: 7
Originally Posted by iquitos View Post
I didn't get the email but I tried to log on and was directed to provide MP number and four digit pin rather than email....

MileagePlus Number (username and e-mail address sign-on are currently unavailable)
No email for me, just same error message as above when I tried to login using my username this morning. Switched to MP# and logged in no problem.
FlyingVeggie is offline  
Old Dec 28, 14, 12:40 pm
  #24  
 
Join Date: Jan 2007
Location: NYC
Posts: 298
I hope this incident serves as a wake-up call for United and that they finally allow some way to disable the 4-digit PIN code entirely. It's absurd in this day and age that such a shoddy security mechanism is in place and enforced.
rmannion is offline  
Old Dec 28, 14, 12:57 pm
  #25  
 
Join Date: Apr 2014
Posts: 121
Originally Posted by greenythebeast View Post
I have the same situation as you. Can login using MP # and pin, but cannot use username and password (changed both). Is this an ongoing tech issue or a security concern? I never received any email saying my account was compromised so I'm not sure how to proceed.
I'd just contact them and say what's going on and how lame their security is. Maybe if enough people complain they'll actually get their act together..

I highly doubt it though, but it's worth a shot..
Phanto is offline  
Old Dec 28, 14, 1:01 pm
  #26  
 
Join Date: Dec 2011
Location: DSM
Programs: UA 1K, AA EP, DL PL, HH Dia, Marriott Gld, Hertz PC
Posts: 695
Originally Posted by rmannion View Post
I hope this incident serves as a wake-up call for United and that they finally allow some way to disable the 4-digit PIN code entirely. It's absurd in this day and age that such a shoddy security mechanism is in place and enforced.
Agree completely ^
dorisrpas is offline  
Old Dec 28, 14, 1:06 pm
  #27  
A FlyerTalk Posting Legend
 
Join Date: Apr 2004
Location: GVA (Greater Vancouver Area)
Programs: DREAD Gold; UA 1.024MM; Bonvoy Au-197; PCC Elite+; CWC Au-197; CCC Select; WoH Dis
Posts: 50,911
Since the timing pretty closely corresponds to iDine changing their login system to directly use your MP information, I'd lay odds that's where the breach happened.

It looks like they've disabled access using usernames and email addresses. You have to log in using your MP number.
mahasamatman is offline  
Old Dec 28, 14, 1:13 pm
  #28  
A FlyerTalk Posting Legend
 
Join Date: Apr 2001
Location: NYC
Posts: 69,210
Originally Posted by mahasamatman View Post
Since the timing pretty closely corresponds to iDine changing their login system to directly use your MP information, I'd lay odds that's where the breach happened.
Except that they use an oAuth-esque system which prevents iDine from ever seeing your real credentials. UA handles the authentication and passes a token to iDine.

Or are you suggesting the issue happened on the old iDine platform and this triggered the change?
sbm12 is offline  
Old Dec 28, 14, 1:19 pm
  #29  
A FlyerTalk Posting Legend
 
Join Date: Apr 2004
Location: GVA (Greater Vancouver Area)
Programs: DREAD Gold; UA 1.024MM; Bonvoy Au-197; PCC Elite+; CWC Au-197; CCC Select; WoH Dis
Posts: 50,911
Originally Posted by greenythebeast View Post
Can login using MP # and pin, but cannot use username and password (changed both).
Perhaps the message on the login page in red bold should have been a dead giveaway?

Originally Posted by Phanto View Post
The only thing that works and allows me to login is my MP account # and my super lame 4 digit PIN!
No, you can use your MP number and password. You just can't use your username or email address.

Originally Posted by united.com
(username and e-mail address sign-on are currently unavailable)
mahasamatman is offline  
Old Dec 28, 14, 1:30 pm
  #30  
FlyerTalk Evangelist
 
Join Date: Jul 1999
Location: Ewa Beach, Hawaii
Posts: 10,688
Originally Posted by Phanto View Post
Here's the kicker..

I have a VERY secure username AND password set on my account, BUT I can't use them! The only thing that works and allows me to login is my MP account # and my super lame 4 digit PIN! I should be able to say allow access via one or the other, but not BOTH or in my case simply the MP/PIN combo since my account/pass don't work anyway. Why am I even able to set them if I can't use them AND you still allow the other to login anyway??

It seems that a number of airlines do this, why is their security SOOOOO crappy??

Ya know, I'm in a mood so I'm going to write them a nice little note!


-Phanto
Originally Posted by greenythebeast View Post
I have the same situation as you. Can login using MP # and pin, but cannot use username and password (changed both). Is this an ongoing tech issue or a security concern? I never received any email saying my account was compromised so I'm not sure how to proceed.
See this thread for more info about the login requiring MP# and PIN.

http://www.flyertalk.com/forum/unite...ec-2014-a.html
Baze is offline  

Thread Tools
Search this Thread