Reply to topic  [ 3 posts ] 
Ryanair - Others Can Edit Your Flight Booking 
Author Message
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
Economy airline Ryanair's online booking system allows for flight amendments and the addition of extra services for their associated fees. According to a report by Berlin newspaper Der Tagesspiegel (German language link), it's easy for an outsider to gain access to the system using just a reservation number or email address along with the flight date as well as the departure and destination airports. This data can be found out quite easily, for example by asking people about their holiday plans via Facebook. It's therefore relatively easy for anyone to maliciously manipulate Ryanair bookings.

Update: While other airlines require either a password or a unique booking number to access their booking systems, Ryanair's spokesman Daniel de Carvalho apparently considers this as dispensible. In a statement to Der Tagesspiegel he waved off concerns issued by experts consulted by Der Tagesspiegel. In direct communication with The H in response to the original wording of this last paragraph of our report, Ryanair's PR forwarded the full statement in English: "Your ‘experts’ are talking complete rubbish. If someone’s lunatic ex-partner wants to access a flight booking and pay for priority boarding or extra baggage for the person they just split up from then they all have a lot more to worry about than a simple amended flight booking. It is everyone’s individual responsibility to keep their personal information personal."

http://www.h-online.com/security/news/i ... 81896.html

FYI...

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Thu Feb 03, 2011 11:34 pm
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
El Reg CLICKY
Quote:
Daniel de Carvalho, a spokesman for Ryanair, dismissed concerns that extra (or as he put it "superfluous"1) security to its booking system might be needed in defence against possible attacks. He told Der Tagesspiegel that it's up to passengers to keep their information secure, implying it's a passenger's hard luck if something goes awry.

But as web developer Thomas Cannon points out, email addresses are freely handed out on business cards and seldom kept secret. Once an email address is known then it becomes a simple exercise in scripting to try every possible combination of flight for a particular day.

"If we knew someone’s email address and were to write a script that programatically submitted requests to the Ryanair website at a relatively slow rate of four per second, it would take just over 10 minutes to check every flight permutation for a flight on a single date," Cannon argues. "To brute force every permutation against an email address for the whole of next month it would take just over five hours."

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Fri Feb 04, 2011 1:04 am
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:10 pm
Posts: 5490
Location: just behind you!
Reply with quote
Ryanair will only do something when forced to by the courts.
They seem to have the attitude [LIFTED] the customer.
Every flight I have taken, if I could of taken a Ryanair flight I would of been charged more and usually to go to a more out of the way inconvienant airport..
Im sure if they thought they could get away with it they call Newcastle airport as London: north!

_________________
johnwbfc wrote:
I care not which way round it is as long as at some point some sort of semi-naked wrestling is involved.

Amnesia10 wrote:
Yes but the opportunity to legally kill someone with a giant dildo does not happen every day.

Finally joined Flickr


Fri Feb 04, 2011 8:44 am
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 3 posts ] 

Who is online

Users browsing this forum: No registered users and 40 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.