Hacker News new | past | comments | ask | show | jobs | submit login

Doesn't work with United MileagePlus accounts, they only allow multiple choice answers!



Yep. I believe when I created my account, I picked ones that were definitely not real answers, ie. "What's your favorite sport?" answer "lawn darts".


Even if you picked a fake answer, that doesn't stop someone from brute-forcing it, which is made very easy by the limited range of possible options.


Any social engineers reading this? :)


Just give the wrong answer and keep track in your password tracker. At least social engineers can't figure that out.


Contact their tech group and then contact their CEO and show them this article. :)


That's just appalling.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: