Marriott hack hits 500M Starwood guests(bbc.co.uk)
bbc.co.uk
Marriott hack hits 500M Starwood guests
https://www.bbc.co.uk/news/technology-46401890
301 comments
Is it time for us to simply accept that it's inevitable that, at some point, everything will be hacked, and hacked often?
Should we be focusing our efforts more on how to make "identity theft" (i.e. fraud) more difficult, even when someone knows all your data?
Something more tied to your physical self, whether 2FA or something else?
Should we be focusing our efforts more on how to make "identity theft" (i.e. fraud) more difficult, even when someone knows all your data?
Something more tied to your physical self, whether 2FA or something else?
"We cannot find any evidence that the stolen information has been misused" - says every company ever, as if that means anything.
I give it 24 hours.
I give it 24 hours.
Not entirely on topic, but Marriott seems to be dealing with some internal phone abuse issues as well - calls going directly to hotel rooms (bypassing the front desk) and asking for card details to fix broken incidentals records. I got a call like this yesterday and found out that it's enough of an issue that they've printed out signs in the lobby warning guests to not hand out information.
Here's a link to the official Marriott release, FWIW: http://news.marriott.com/2018/11/marriott-announces-starwood...
Note: This has affected Marriott's "Starwood" division.
Starwood's hotel brands include W Hotels, Sheraton, Le Méridien and Four Points by Sheraton. Marriott-branded hotels use a separate reservation system on a different network.
Starwood's hotel brands include W Hotels, Sheraton, Le Méridien and Four Points by Sheraton. Marriott-branded hotels use a separate reservation system on a different network.
As a first rough approximation, this figure includes everyone on HN.
It appears to include everyone who's ever stayed in a room at a Marriott, St. Regis, Ritz-Carlton, Bulgari, W Hotel, JW Marriott, The Luxury Collection, Le Meridien, Renaissance, Westin, Tribute Portfolio, Sheraton, Autograph Collection, Design Hotel, Marriott Executive Apartments, Delta Hotels & Resorts, AC Hotels, Element, Gaylord, SpringHill Suites, Courtyard, Residence Inn, Fairfield Inn & Suites, Moxy Hotels, Protea Hotels, TownePlace Suites, Aloft, Four Points by Sheraton, or Marriott Vacation Club property.
For reference, there are under 130M households in the US and around 200M households in the entire EU.
It appears to include everyone who's ever stayed in a room at a Marriott, St. Regis, Ritz-Carlton, Bulgari, W Hotel, JW Marriott, The Luxury Collection, Le Meridien, Renaissance, Westin, Tribute Portfolio, Sheraton, Autograph Collection, Design Hotel, Marriott Executive Apartments, Delta Hotels & Resorts, AC Hotels, Element, Gaylord, SpringHill Suites, Courtyard, Residence Inn, Fairfield Inn & Suites, Moxy Hotels, Protea Hotels, TownePlace Suites, Aloft, Four Points by Sheraton, or Marriott Vacation Club property.
For reference, there are under 130M households in the US and around 200M households in the entire EU.
"It said some records also included encrypted payment card information, but it could not rule out the possibility that the encryption keys had also been stolen."
Oh dear.
Oh dear.
It's like you need to keep a running diary of every single service you've used / every single place you've been so when something happens like this, maybe you can find out if you actually used that service or visited that place.
I think I stayed at a Starwood 2 years ago in PA? But I don't remember if it was a Starwood or some other Marriott brand.
I think I stayed at a Starwood 2 years ago in PA? But I don't remember if it was a Starwood or some other Marriott brand.
History being a guide, Marriott will obtain a contract with some financial security monitoring service, and offer a ~12 month free period for affected consumers. I've always thought these products are b.s. The advertising is scammy. I'm betting they leak even more data, like your purchase histories.
Does anyone know of the efficacy of these monitoring services? If they were really even slightly more effective than even odds, I would say that consumer protection laws should require free monitoring for a longer period, say 24 months or even 36 months. Ironically though, proper monitoring means sharing all of this same personal information with a 3rd party, and then some.
I also wonder if it's just more effective to take advantage of the free credit report freezing feature, since that doesn't require me to share even more personal information with a 3rd party; and actually restricts access to personal information instead of expanding it.
Does anyone know of the efficacy of these monitoring services? If they were really even slightly more effective than even odds, I would say that consumer protection laws should require free monitoring for a longer period, say 24 months or even 36 months. Ironically though, proper monitoring means sharing all of this same personal information with a 3rd party, and then some.
I also wonder if it's just more effective to take advantage of the free credit report freezing feature, since that doesn't require me to share even more personal information with a 3rd party; and actually restricts access to personal information instead of expanding it.
I guess without GDPR there wouldn't have been a push for these companies to notify of breaches so early. We could have found out about it next year.
Also given the potential penalties, probably companies will now start to invest more in proper IT systems.
Also given the potential penalties, probably companies will now start to invest more in proper IT systems.
I recently got added to Starwood Preferred Guest. I still don't know why they have my e-mail (don't seem to have stayed at any of their hotels), but I guess it's out there now, even though it wasn't in HIBP before.
If they didn't keep the data from long ago, then the damage would be much smaller. Such companies definitely need some help from lawmakers. Companies shouldn't keep personal information for years.
A handful of years ago, Paul Ohm wrote about a concept he called the "Database of Ruin" [0]. I think about it every time one of these pieces of news breaks.
"Once we have created this database, it is unlikely we will ever be able to tear it apart."
[0] https://hbr.org/2012/08/dont-build-a-database-of-ruin
"Once we have created this database, it is unlikely we will ever be able to tear it apart."
[0] https://hbr.org/2012/08/dont-build-a-database-of-ruin
>It said an internal investigation found an attacker had been able to access the Starwood network since 2014.
Jebus that seems like a long time before discovering it.
Jebus that seems like a long time before discovering it.
>"We deeply regret this incident happened," the company said in a statement.
This is peak non-apology apology.
This is peak non-apology apology.
... and ... nothing will happen to Marriott.
I just signed in to Marriott.com see what info they have on me that was stolen, and was forced to change my password. It even required email verification, which is good.
Then when I tried to log in with my new password I was rejected, saying my account is 'under audit' for suspicious activity. God dammit.
Is anyone else unable to log in?
Then when I tried to log in with my new password I was rejected, saying my account is 'under audit' for suspicious activity. God dammit.
Is anyone else unable to log in?
The New York Attorney General is opening an investigation into a Marriott data breach that may have affected 500 million guests.
https://twitter.com/NewYorkStateAG/status/106851007239602995...
https://twitter.com/NewYorkStateAG/status/106851007239602995...
Great!
My last stay at a Starwood property was in January 2016 at the Bangkok LeMeridien.
Not that they would bother to set up a call center number for Switzerland.
Do they really expect me to call internationally at my expense to then hang in a loop for an hour or so?
On the plus side: Nothing bad happened since then.
Nevertheless I'm not impressed.
My last stay at a Starwood property was in January 2016 at the Bangkok LeMeridien.
Not that they would bother to set up a call center number for Switzerland.
Do they really expect me to call internationally at my expense to then hang in a loop for an hour or so?
On the plus side: Nothing bad happened since then.
Nevertheless I'm not impressed.
Outside of the privacy problems (which, let's be honest, our data is already out on the web) if you changed your credit card since your last visit you're probably safe on that particular financial attack vector, right?
I'm almost certainly in the database.
So I have to get a new passport, get a new phone number, get a new credit card, change my email address... in the US, can I sue in small claims court to recover the costs of doing these things?
So I have to get a new passport, get a new phone number, get a new credit card, change my email address... in the US, can I sue in small claims court to recover the costs of doing these things?
It said some records also included encrypted payment
card information, but it could not rule out the
possibility that the encryption keys had also been
stolen.
Why did the world end up with a pull-system for payments? Why do I have to give out my credit card number and enable the other side to pull arbitrary amounts as often as they like?This is one of several things crypto currencies got right. You pay by pushing money to the other side.
This was the kick in the pants I needed to finally take the time to freeze my credit. I don't know how much it will help but it can't hurt, I guess.
Is anyone else noticing unusual downvotes on this thread? Anyone think it's plausible a Marriot damage control team is participating on this thread?
How could it affect 500 million? 1 in 16 people worldwide have stayed in a Marriott hotel? That seems like a lot...
I hope they at least hashed the credit card numbers ( ͡° ͜ʖ ͡°)
They still don’t even use https, so this is not surprising.
When you start using Ethereum and web 3.0, the solution to data security becomes quite clear. I'm sure I'm gonna get roasted here for even mentioning this, but you'll all eventually come around.
Why on earth would they hold onto passport numbers? The amount of data companies hold onto is ridiculous. It can't all be necessary.
"Let's immediately set up a separate domain name that looks like ours" remains one of the weirdest antipatterns in incident response.
[1] http://news.marriott.com/2018/11/marriott-announces-starwood...
[2] https://info.starwoodhotels.com/