Skip to content

Comment on It's time to publicly shame United Airlines' so-called online security

Comments

It's entirely their prerogative as to whether or not they provide a decent level of security, and it's entirely up to consumers to choose whether or not to work with them.

The vast majority of people do not know what 2fa is, and sure as hell don't care to know, so the only people irked by their misleading messaging are IT professionals, who, again, can fly with someone else.

Essentially, there is clearly no incentive for them to improve their security unless it hurts their bottom line - and there's no point from their perspective in investing in something which makes no money.

Of course, if they have a major hack there will be some brief PR damage (none of the high profile hacks of major companies seem to have inflicted any reputational damage - instead the public blame the "terrorist hackers" the media parade), and their insurers will cover any direct losses, including those as a result of a class action, which they're probably indemnified against anyway.

In short, they have no reason to change, so probably won't. If anything, they'll be upheld as the golden standard, because legislators will buy into their PR, not being in any way technical themselves. Perception is reality.

It's entirely their prerogative as to whether or not they provide a decent level of security, and it's entirely up to consumers to choose whether or not to work with them.

Entirely? Does the security of their website rank anywhere in the top ten of reasons anyone chooses an airline?

The vast majority of people do not know what 2fa is, and sure as hell don't care to know, so the only people irked by their misleading messaging are IT professionals, who, again, can fly with someone else.

And it is the IT professionals who might raise the bar, and protect those who do not 'care to know'.

Of course, if they have a major hack there will be some brief PR damage (none of the high profile hacks of major companies seem to have inflicted any reputational damage - instead the public blame the "terrorist hackers" the media parade), and their insurers will cover any direct losses, including those as a result of a class action, which they're probably indemnified against anyway.

So all that matters is PR damage, and anything that someone is willing to sue for?

Entirely?

Yes, entirely. It is up to them how they choose to operate their business, so long as it is within the bounds of law.

And it is the IT professionals who might raise the bar, and protect those who do not 'care to know'.

Correct, but how will you raise the bar or protect other passengers, if United do not care about your opinion, as you are a small minority? Unless you can hurt their bottom line by persuading people to not fly with them, they won't budge - and just you try persuading aunt Tilda not to fly with United because their website security is poor, even though their tickets are $200 cheaper than $competitor. I mean, that television ad said they had the best security in the business. Why would they lie about something like that, and what do you know about it anyway?

so all that matters is PR damage, and anything that someone is willing to sue for?

To them, absolutely.

Yes, entirely. It is up to them how they choose to operate their business, so long as it is within the bounds of law.

I guess the law needs to change then. A shop cannot sell you an item of food that might seriously harm you, because it's unreasonable for the average consumer to carry out the required testing on every piece of food they purchase for consumption. Ultimately (I'm not saying this can necessarily happen overnight), the same should go for online security. Now, it's a difficult-enough thing that responsibilities need to be very carefully defined; every mom-and-pop site should do the reasonable minimum themselves, but a good centralised system should be available for them to use for the trickier aspects.

I guess the law needs to change then.

I couldn't agree more - but then, what incentive is there for legislators who are technically illiterate, and have attended many cheque-laden seminars in which airline lobbyists have told them they don't need to do anything about that nasty regulation stuff. Imposing strict universal security requirements would be deemed anti-competitive, and could potentially result in businesses suing the federal government for loss of profits.

Personally, I think the future comprises a frothing sea of crapware, leaky everything everywhere, and nobody taking responsibility. The most probable ultimate response will be a "war on hackers", after someone pulls something spectacular off, which will generate trillions of dollars in profits for enforcement agencies, and give the public that warm fuzzy "somebody is being bombed and it isn't me" feeling.

"According to the new TSA's new Airline Security Regulation, your password must be between 12 and 16 characters long, and must contain an uppercase character, a lowercase character, a numeral, and a special character. The following characters are forbidden: \/'";(){}[]|*. All characters must be unique. You must change your password every 30 says. For each failed attempt you will be charged a $1 password processing fee."

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.