ALH
Established Member
- Joined
- Apr 22, 2012
- Posts
- 1,123
- Qantas
- Platinum
- Virgin
- Gold
re: Qantas launches "Aquire" business frequent flyer program.
Correct. Password wasn't visible, and it was my own ABN on display. As I said, I would feel uneasy if my details were available to the next person who logged in.
To be fair, the password isn't visible and - as mentioned in ALH's initial post - the ABN (which was the original ABN entered by the applicant) doesn't match the company displayed upon hitting the "back" button.
But, yeah, I agree. Company name (from which the ABN can be quickly found), the Acquire programme's contact's full name and role (owner/director etc), phone number, email address, Qantas FF number and - most crucially - security question and answer (which would most likely be used to reset the password either online and/or via phone, depending on the procedures established) are details not quite as easily deduced as some self-styled hackers might think.
As well the possible exposure to the Acquire accounts that are in play now, the security questions posed are generic enough that they could conceivably be used to hack other systems as well. Ie, many websites use "Mother's maiden name", "Favourite colour", "Town of birth" etc to enable access in the event of a forgotten password, or even forgotten email address.
But hopefully the exposure was/is minimal and the hole quickly closed.
Correct. Password wasn't visible, and it was my own ABN on display. As I said, I would feel uneasy if my details were available to the next person who logged in.