OT: Holiday Inn screwup

Sep 17, 2022 Last reply: 3 years ago 34 Replies

See:



formatting link
If you're planning to stay at an HI in the future, I'd pay cash.



If you've stayed there in the past, make sure they don't have any of your data.


Its not only HI its the whole IHG group. You may not be able to pay cash. Most Hotels want a card they can charge against damages etc.

It looks like that is likely they won't...

Dave

Qwerty1234, eh? I must remember that next time I need a password.

Why? The credit card companies will sort any fraud losses out for you in the unlikely even that your card details become stolen.

How are you going to do that?

If you have ever paid by credit card chances are your personal data is lurking in their systems or their archives somewhere.

It beggars belief that a major organisation has password Qwerty1234 I suppose Pa55w0rd would have been worse - but not by much...

OTOH high entropy ones changed too frequently are just as bad. I have seen master passwords with near omniscient powers on post-its attached to very senior (not especially computer literate) managers screens :(

And it was the password for ... the password vault.

My comment *was* slightly tongue-in-cheek. But all these outfits swear blind that they take security *extremely* seriously, yet time and time again, we hear about these hacking cases.

This is the crucial question.

Well it's a question of access really. And security by obscurity. I mean, we all keep our bunches of keys indoors relatively hidden, as opposed to hanging up on a nail outdoors in the front porch. Don't we?

I really don't like sites that force you to open an account to do something with them. I don't mind the slight inconvenience of repeating my info for another purchase. Trouble is, I'm not convinced they wipe the "single use" data.

At least you haven't had a to devise yet another password.

I've just had an interesting one. Late evening Thursday.

£6.00 purchase from TLC direct. Punched in the card data and sorted the authentication. Site then displayed a message suggesting I checked the card data and implied the bank might be withholding payment.

Tried again with a different card and got the same result.

Mail from TLC asking why I had not completed the purchase...

Phoned head office the next morning who were equally mystified but put the order though as cash on collection.

>

I try to pay cash for *everything* and if I can't do that, I go elsewhere. A cashless society like they're trying to foist onto us is nothing short of tyranny.

Correct.

Can't see how that works with debit cards and maxed out credit cards where you ensure that they can only get what their stated rate is in it. Can't see how they could slug the card for an amount that would cover any possible damage that might occur at checkin time and not find that most don't have that available on the card.

But that is because you are a tax cheat.

Only for tax cheats.

I know one or two IT security people and the joke is that they last about as long in an organisation as anyone in original series Star Trek who beams down to the planet surface wearing a red T-shirt and isn't called Scotty. Unappreciated doesn't begin to describe their problems.

It is invariably the most senior individuals in an organisation that CBA with all this security palaver and break the rules. It is a brave IT security person that goes toe to toe with a CEO. I know I have done it.

Too many people have a spare key under a flowerpot somewhere.

Have you read any of Feynman's books about the time when he was a physicist in the Manhattan Project during WW2? He'd visit these senior generals' offices, where the commanding officer would have a safe. The general then boasted about the safe as being super secure. Feynman would then astonish the general by opening it - acheieved because the fatheads hadn't changed the safe's code from factory default. I think there were two or three such defaults and Feynman knew 'em all. Or the code was set to the general's birthdate, or, if the safe was in the office of a mathemtician (say), the code might be a few digits of e or pi.

He could also pick locks, as I recall.

We used to keep ours actually buried in the back garden. Then we made it so secure that we couldn't get in.

These days it's 'unlock by phone' with 2FA. I am confident since it's my own software and hardware.

Until you can't get parts any longer.

No need for parts and even if there is a need for parts, you can just get them now so they are available if needed.

Well, no. I'll just build a new one.

Not if you've become a doddering old fossil, you won't.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required