Marriott says 5.2M guests exposed in new data breach
reuters.com
reuters.com
The practice won't stop until consumer data becomes a liability for any business touching it. At that time, only businesses that are actually able to utilize the data to derive revenue sufficient to compensate the liability will continue to collect it. Hopefully, in many cases the revenue would come about as a result of creation of some value for the consumer.
I'm always wondering why a random service would need a date of birth (apart from validating "the person is an adult"). Some of them give you a special promo for your birthday, but I guess I can live without that.
Except banking & government services, I typically provide a fake one if required, because, WTF?
All you need to prove is your age, but the company that puts the scanner in place (in the case of bars and restaurants) collects all the info on the DL. Walgreens collects all the info and correlates it with your CC if you don’t pay by cash. Etc.
Any major hotel will simply swipe your DL and will populate the guest record with its info.
I assume it's to help them track you down if you cancel your credit card, trash the room, and flee.
I mean, I would imagine a TON of places have my birthday now. How valuable is that information really?
Same goes for the phone number that some website registrations demand. It's not to call you, it's to lookup your name and address and annual income.
Maybe I’m just so used to being asked for my ID I didn’t notice.
Full DOB can probably isolate you from other people with same name for other marketing purposes.
They do have 'adult v child' stuff so they for sure have legit reasons for wanting to know in addition to sleazy reasons.
John Smith, John Smith Jr...
https://www.theregister.co.uk/2020/01/13/ico_british_airways...
I went to the fedex store in a Marriott a couple of blocks from here to drop off a pre-paid parcel, and they wanted a $20 "convenience" fee to leave it on the desk. Maybe Marriott doesn't need to care about guest infosec because guests are the product, not the customer.
I mean, no one pays $27 of their _own_ money for a continental breakfast...
With that said, this is surprising to me: Information Protection at Marriott was one of the biggest hurdles to get the new version of their .com up and running, and the 2018 hack came from the Starwood Acquisition.
This one? There's really no good excuse for. Well, forcing employees to change their password every 30 days and keeping 12 months of password retention probably didn't help (super common to just suffix the month/year with your known password to get around that check). Either that, or it was a genuine bad actor/employee inside MI. Anything's possible, I guess.
https://wtop.com/business-finance/2020/03/marriott-furloughs...
I guess I'm wondering how good all of these companies are at sharing data between themselves. What kind of data is exposed when I use my primary email to log into Zoom or Spotify on a work computer, or my phone, or one of my relative's computers? To what extent do these companies coordinate and share this data?
It all just seems like a really big unknown to me, and I'm relatively tech savvy.
If you live in the EU or California and didn't send Marriott a GDPR/CCPA deletion request after the first breach please do it now: https://yourdigitalrights.org/?company=marriott.com
https://sensorstechforum.com/500-million-customers-marriott-...
I do not trust Accenture. Fuck them.
You could get more competent people, but they are less likely to follow process (which violates contract terms), and would cost more.
Edit: Also, if you work in one of the big service firms for a US client, you will have to do your day job, and then return to the office later at night to have meetings on US time.
Being able to predict when you might be at a given hotel in the future (which is possible from one's stay history, e.g. a conference you attend every year) is tremendously useful for blackmailers, kidnappers, and the like.
I personally refuse to allow my PII in these databases on these grounds, and these days it's impossible to get a hotel room without an ID, so this is the only option.