Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > United Airlines | MileagePlus
Reload this Page >

UA initiates Account Security Update (Security Q&A authentication added 2016)

Community
Wiki Posts
Search

UA initiates Account Security Update (Security Q&A authentication added 2016)

Thread Tools
 
Search this Thread
 
Old Feb 19, 2016, 10:23 am
  #226  
 
Join Date: Jul 2010
Location: CMH
Programs: UA 1K, 1MM, HH Diamond, Marriott Gold
Posts: 745
PIN still used for GPU

I thought this was interesting. I called in this morning to apply GPUs (had to *GG BUYUP first) and the agent asked for my PIN. I was wondering if she was going to ask for my password but PIN was all she needed.

Don't forget your PIN if you call in for GPUs!
RockinRon is offline  
Old Feb 19, 2016, 10:32 am
  #227  
FlyerTalk Evangelist
 
Join Date: Oct 1999
Posts: 11,468
Decided to wait with update til the dust settles.
But now I am locked out!
I click "accept & update later" and it takes me right back to the login page.
cesco.g is offline  
Old Feb 19, 2016, 10:50 am
  #228  
 
Join Date: Jun 2015
Location: LIM
Programs: United Premier 1K, Hilton Diamond, Bonvoy Gold, AmEx Plat
Posts: 559
I believe that on the email I got it says that the PIN will still be used to identify yourself for phone transactions, so "don't lose track of it juts yet" or something like that.
joseeantonior is offline  
Old Feb 19, 2016, 11:04 am
  #229  
 
Join Date: Sep 2009
Programs: UA 1K, UA 1 MM
Posts: 67
Originally Posted by Silver Fox
Then it didn't go smooth then did it
It seems to be working this morning, after I cleared cache on the browser as has been suggested by others earlier.
flyer_south is offline  
Old Feb 19, 2016, 12:25 pm
  #230  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: DAY
Programs: UA 1K 1MM; Marriott LT Titanium; Amex MR; Chase UR; Hertz PC; Global Entry
Posts: 10,159
Looks like it has affected the MileagePlus shopping portal now.

I keep clicking "Update Later" on United.com, but now I get internal error messages when trying to log into M+ Shopping.
goodeats21 is online now  
Old Feb 19, 2016, 12:49 pm
  #231  
FlyerTalk Evangelist
 
Join Date: Jul 2003
Location: BOS, PVG
Programs: United 1K and 1MM, Marriott Ambassador
Posts: 10,000
Originally Posted by RockinRon
I thought this was interesting. I called in this morning to apply GPUs (had to *GG BUYUP first) and the agent asked for my PIN. I was wondering if she was going to ask for my password but PIN was all she needed.

Don't forget your PIN if you call in for GPUs!
Can you still change PIN?
kb1992 is offline  
Old Feb 19, 2016, 12:53 pm
  #232  
 
Join Date: May 2011
Posts: 5,814
Originally Posted by RockinRon
I thought this was interesting. I called in this morning to apply GPUs (had to *GG BUYUP first) and the agent asked for my PIN. I was wondering if she was going to ask for my password but PIN was all she needed.

Don't forget your PIN if you call in for GPUs!
During the process, it stated that they will still use the PIN for phone based transactions so I don't think it will go away.

Originally Posted by kb1992
Can you still change PIN?
Yup!

https://www.united.com/web/en-US/app...pinChange.aspx

Last edited by edcho; Feb 19, 2016 at 1:02 pm
edcho is offline  
Old Feb 19, 2016, 1:17 pm
  #233  
Company Representative, United Airlines
 
Join Date: May 2006
Location: Chicago, Houston, or somewhere in between
Posts: 2,176
Hi everyone,

We’ve been monitoring this thread and taking your feedback into account and have made some quick changes to fix issues you have identified. We also want to use this as an opportunity to answer some of the common questions we have seen on this thread. If you have any other questions, please let us know and we will work with our IT Security team to address them where possible.

"Why can't I type my own answer?"
-At the beginning of our effort we conducted a great deal of research into the security issues our customers face. We found that the vast majority of security issues that customers have with their accounts can be traced to computer viruses that record your typing.
-We purposely chose to use preregistered answers as our first form of enhanced authentication to protect against this keystroke logging. We need to ensure that all of our customers have a high degree of security and our research also indicated that some customers had self-entered security answers that would be very easy to guess.
-Not all customers are asked the same questions, and not all customers receive the same potential answers to each question. This randomization is on purpose and designed for your safety and security.

"Why aren't you applying Two Factor Authentication (TFA)?"
-We plan to. Two Factor Authentication will be coming this year.

"What about SMS authentication, or Touch ID, or Google Authenticator?"
-We began with security questions first as not all customers can receive SMS messages, use Touch ID, or have an Authenticator app. You should expect some of these options to appear in the coming year.

“Can't these questions be guessed from Facebook?”
-We hope not! We designed the questions to be difficult to answer through your social media accounts, which is why they may seem peculiar. If you're not sure, try to answer two of your own questions selected at random about a Facebook friend of yours selected at random. We played this game quite a bit during the development program and found it very difficult.
-Some of the questions we ask have some obvious answers omitted. This is on purpose and designed for your safety and security.

"Are you using my answers to these questions for Marketing purposes?"
-No. Your answers are stored encrypted and are not accessible for any purpose other than authenticating you.
-Additionally, your password is encrypted in transit and at the point of storage and is not stored in plain text on United's systems under any circumstances.

"Why wasn't I asked to update my password when someone else was?"
-As part of the account security upgrade launched last week, our system would evaluate your encrypted password and not bother you to update your password if it met our criteria. We have taken into account your feedback provided over the last week and the account security upgrade process now asks all customers to update their password. This should assist those customers who cannot immediately recall their password.
-If you forget your password, the forgot password link on United.com should permit you to reset after answering two of your five security questions.

"I am having trouble logging in after going through the account upgrade process. Any ideas?"
-We are actively working on fixes for a very small number of customers who have login difficulty and for another small number of customers who have difficulty setting questions. We should make the necessary improvements soon, but in the mean-time if you clear your browser cookies for United.com we believe you will have better success.

“How can I view the questions I set up?”
-In order to protect the security of your account, we do not display the questions and answers you set during the security upgrade process. You can always update your questions by visiting the “Change Security Questions” page on the Profile Management screen on United.com.

Thank you,

-UA Insider
UA Insider is offline  
Old Feb 19, 2016, 1:39 pm
  #234  
FlyerTalk Evangelist
Four Seasons Contributor BadgeMandarin Oriental Contributor Badge
 
Join Date: Feb 1999
Location: Seat 1A, Juice pretty much everywhere, Mucci des Coins Exotiques
Posts: 34,339
Thanks for listening UA Insider and I look forward to the improvements. For now though I'll stick with the iOS apps. It will be great when those apps have feature parity with the web interface. I hope that is a near term target for UA.

Last edited by stimpy; Feb 19, 2016 at 1:45 pm
stimpy is offline  
Old Feb 19, 2016, 2:08 pm
  #235  
 
Join Date: Nov 2013
Location: NYC / TYO / Up in the Air
Programs: UA GS 1.7MM, AA 2.1MM, EK, BA, SQ, CX, Marriot LT, Accor P
Posts: 6,310
Originally Posted by stimpy
Thanks for listening UA Insider and I look forward to the improvements. For now though I'll stick with the iOS apps. It will be great when those apps have feature parity with the web interface. I hope that is a near term target for UA.
+1 - thanks for taking the time to address what are admittedly serious issues - in the future I'd request that you collect a bunch of FT users as a beta test group before you implement something like this globally.... This was a real mess for your frequent travellers....
bmwe92fan is offline  
Old Feb 19, 2016, 2:32 pm
  #236  
FlyerTalk Evangelist
 
Join Date: Dec 2006
Location: Pacific Northwest
Programs: UA Gold 1MM, AS 75k, AA Plat, Bonvoyed Gold, Honors Dia, Hyatt Explorer, IHG Plat, ...
Posts: 16,843
Originally Posted by UA Insider
.

-Additionally, your password is encrypted in transit and at the point of storage and is not stored in plain text on United's systems under any circumstances.
Do you actually store the password in an encrypted format that easily allows you to reverse the encryption? Or do you store a hash of the password?

"Why wasn't I asked to update my password when someone else was?"
-As part of the account security upgrade launched last week, our system would evaluate your encrypted password and not bother you to update your password if it met our criteria.

-UA Insider
This makes me think that you did (do?) store the password in such a way that you can easily see the clear text password by decrypting it (I assume you didn't try to crack all xx million passwords and only forced a new one for those that you could crack.

Hmmm.
notquiteaff is online now  
Old Feb 19, 2016, 3:03 pm
  #237  
Marriott 5+ BadgeHyatt Contributor Badge
 
Join Date: Jan 2011
Location: HKG • Ex SFO, NYC
Programs: UA 1K, AA EXP; Marriott Amb; Hyatt Globalist; Shangri-la Diamond; IHG SpireAmb; Hilton D; Accor G
Posts: 3,319
Originally Posted by notquiteaff
Do you actually store the password in an encrypted format that easily allows you to reverse the encryption? Or do you store a hash of the password?



This makes me think that you did (do?) store the password in such a way that you can easily see the clear text password by decrypting it (I assume you didn't try to crack all xx million passwords and only forced a new one for those that you could crack.

Hmmm.
That doesn't actually indicate that at all. (I'm an engineer and have designed password storage schemes, so I can speak to this.)

When you log in, you send the cleartext of the password (over SSL) to united. That's also when you're prompted to update the security questions and update your password. Since they have the cleartext during the login procedure, they can test for whether it meets the basic security criteria at that time on the fly.

If UA follows well known security best practices, they'd be storing the password as the result of a cryptographically-secure one-way key-derivation function. (Ideally, pbkdf2, bcrypt, or scrypt.)
helvetic is offline  
Old Feb 19, 2016, 3:43 pm
  #238  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: DAY
Programs: UA 1K 1MM; Marriott LT Titanium; Amex MR; Chase UR; Hertz PC; Global Entry
Posts: 10,159
Originally Posted by helvetic
That doesn't actually indicate that at all. (I'm an engineer and have designed password storage schemes, so I can speak to this.)

When you log in, you send the cleartext of the password (over SSL) to united. That's also when you're prompted to update the security questions and update your password. Since they have the cleartext during the login procedure, they can test for whether it meets the basic security criteria at that time on the fly.

If UA follows well known security best practices, they'd be storing the password as the result of a cryptographically-secure one-way key-derivation function. (Ideally, pbkdf2, bcrypt, or scrypt.)
I know next to nothing about password web stuff, but I think the point was United was able to look at an EXISTING (stored) password and know if it met the "strong" criteria. If so, they were not forcing the user to enter a new password.

It was not referencing anything about transmitting the new password.
goodeats21 is online now  
Old Feb 19, 2016, 3:51 pm
  #239  
Senior Moderator
 
Join Date: Oct 2001
Location: San Francisco, CA
Programs: UA Plat/2MM [23-yr. 1K, now emeritus] clawing way back to WN-A List; MR LT Titanium; HY Whateverist.
Posts: 12,396
With one minor glitch, was able to do the security update, including signing back in with the new PW, after logging out. First cleared all UA cookies, then went through the guided process. Before the security Qs. came up, I did get an error failure message to call web support, but hit the "back" button and was able to continue without further error message.

However, was unable to complete an online renewal of my United Club subscription using funds from my united.com/club bank account. Don't know if this is related to the security update process or is an independent problem. After waiting >15 mins. to talk to an agent at the UC Svc. Ctr., decided to just try to renew next week while at a Club.

[Update: referring to my ApplePay acct., shows that the Club renewal using united.com/club $$$ bank DID go through - x3: once for each attempt the website said failed to go through! Now will have to see if this is reconciled by UA and/or the CC issuer.]

Last edited by Ocn Vw 1K; Feb 19, 2016 at 4:18 pm Reason: Update
Ocn Vw 1K is offline  
Old Feb 19, 2016, 3:59 pm
  #240  
Moderator: United Airlines
 
Join Date: Jun 2007
Location: SFO
Programs: UA Plat 1.995MM, Hyatt Discoverist, Marriott Plat/LT Gold, Hilton Silver, IHG Plat
Posts: 66,850
My thanks to all the beta-testers

I waited until today to do the password change and all when well.
Logged back in afterwards and was able to construct and fare lock an itin.
WineCountryUA is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.