Airline websites don’t care about privacy follow-up: Emirates in full-on denial
medium.freecodecamp.org
medium.freecodecamp.org
Setup a laptop or some other small device that is listening to data being sent over Wifi at an airport. If you're feeling really brave, hide the device inside the airport, plugged in. Every time it picks up anything being sent over http to one of these insecure third parties, look for booking reference numbers and names, then automatically cancel the ticket using those two pieces of data.
If you did that at a major Emirates hub, you could probably cancel a significant number of tickets, impacting the company enough to get them to actually get their act together.
But just a small correction, the third-parties are not on HTTP, it's the email link that it HTTP.
Edited for clarification: thanks, 'kkm!