It’s time to publicly shame United Airlines’ so-called online security

Comment

Image Credits: Lasse Fuss (opens in a new window) / Wikimedia Commons (opens in a new window) under a CC BY-SA 3.0 (opens in a new window) license.

Jon Evans

Contributor

Jon Evans is the CTO of the engineering consultancy HappyFunCorp; the award-winning author of six novels, one graphic novel, and a book of travel writing; and TechCrunch’s weekend columnist since 2010.

More posts from Jon Evans

Dear executives of United Airlines, I have some advice for you. 1: Fire whoever is in charge of your online security. 2: Burn down the building in which they worked; it may be tainted. 3: Salt the ground so nothing ever grows there again, to be safe. 4: Hire somebody competent who will not infuriate your users while simultaneously compromising their security.

I know I probably sound like a disgruntled passenger who just had an unpleasant airline experience. Not so! I am actually fond of United, have flown hundreds of thousands of miles with them, and have upper-tier status with them. But I’m also an engineer who writes about security.

It was bad enough when they replaced their free-form password security questions with drop-down selections — I am not making this up — for “Your favorite artist,” “Your favorite pizza topping,” etc., citing — I am still not making this up — the threat of keylogging malware.

This has already been appropriately eviscerated by Josephine Wolff in Slate, and, in fairness, it’s a kind of idiocy that seems to be common to large organizations. Citibank UK did the same thing for years, before they realized how dumb it was.

The thing that bumbling bureaucrats like United’s security team never seem to realize is: you don’t make your systems more secure by making them hard to use. They will react by trying to make it easy again — by, for instance, picking the first answer in every option, rather than trying to remember both questions and answers that they did not devise and have no resonance for them.

(Similarly, you should not force your users to change passwords frequently, or their passwords will grow weaker, they will write them down in multiple places, etc. I’m looking at you, AOL-which-owns-TechCrunch.)

But even that was merely bad, eyeroll-provoking, frustration-inducing; whereas this week’s compounding sin provoked something more like righteous fury. This week they sent me an email saying:

Your security questions will also be used as part of upcoming two-factor authentication to further protect your account — you’ll be asked to answer your security questions the first time you sign in from a device that we don’t recognize.

For fuck’s sake, United.

https://twitter.com/arirubinstein/status/763414363403329536

First, you are compounding your flawed-because-user-hostile security problems by forcing people to use it more often. Second, you are calling that “two-factor authorization,” because, I don’t know, you believe in some kind of cargo cult? You have adopted security Dadaism, or security Situationism, rather than security engineering? (That would explain the pizza-topping question too, come to think of it.)

Two-factor authorization has a specific meaning: most often, it’s “something you know, something you have.” It actually does make you much more secure! (Even if you use SMS, which you probably shouldn’t, because SS7 flaws, etc.) Two-factor authentication is not “enter your password, then answer stupid arbitrarily / externally chosen security questions.”

So, just to summarize, United has:

  • Compromised its users’ security by adopting a terminally stupid threat model (keystroke loggers), and …
  • in response to that threat model, implemented infuriatingly counterintuitive, hard-to-use security questions, rather than…
  • something which actually would address that threat; two-factor authentication! Instead they…
  • …doubled down on their stupid security questions and called that two-factor authentication.

So I stand by my original suggestions. Sack them, burn it, and salt the remains. There’s nothing worth salvaging here.

More TechCrunch

Google DeepMind has taken the wraps off a new version AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only more…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Kyle Kuzma is a lot of things. He’s a forward for the Washington Wizards NBA team and a 2020 NBA champion. He’s also a style icon — depending on who…

NBA champion Kyle Kuzma looks to bring his team mentality to Scrum Ventures

Lipids are fatty, waxy or oily compounds that, for instance, typically come in the form of fats and oils. As a result they are heavily used in the production of…

After a $20M Series A funding, Germany’s Insempra plans eco-friendly lipid production

Tesla CEO Elon Musk has said that lidar sensors are a “crutch” for autonomous vehicles. But his company has bought so many from Luminar that Tesla is now the lidar-maker’s…

Tesla is Luminar’s largest lidar customer

U.S. realty trust giant Brandywine Realty Trust has confirmed a cyberattack that resulted in the theft of data from its network. In a filing with regulators on Tuesday, the Philadelphia-based…

Brandywine Realty Trust says data stolen in ransomware attack

Rivian lost $1.45 billion in the first quarter, showing that its recent company-wide cost-cutting measures have a ways to go before it can approach profitability. The EV-maker brought in $1.2…

Rivian loses $1.45B as cost-cutting measures continue

Meta is rolling out an expanded set of generative AI tools for advertisers, after first announcing a set of AI features last October. Now, instead of only being able to…

Meta’s AI tools for advertisers can now create full new images, not just new backgrounds

On April 29, Senators Jon Ossoff (D-GA) and Marsha Blackburn (R-SC) proposed a bipartisan bill to protect children from online sexual exploitation. President Biden officially signed the REPORT Act into…

Biden signs bill to protect children from online sexual abuse and exploitation

The pandemic ushered in an e-bike boom. But like so many other pandemic trends, that boom didn’t last. The last year has seen e-bike startups VanMoof and Cake file for…

Bloom is reinventing how e-bikes are made in the US

At its iPad-focused event on Monday, Apple announced a new and improved Magic Keyboard, its keyboard accessory for iPad. The Magic Keyboard has been “completely redesigned” to be much thinner…

Apple unveils a new Magic Keyboard at iPad event

Apple isn’t yet ready to unveil its broader AI strategy — it’s saving that for its Worldwide Developer Conference in June — but the tech giant did make sure to…

Apple highlights AI features, including M4 neural engine, at iPad event

The New York Times Games announced on Tuesday that it’s launching a Wordle archive, offering subscribers access to more than 1,000 past Wordle puzzles. The company has started rolling out the Wordle…

NYT Games launches a Wordle archive with access to more than 1,000 past puzzles

Robert Kahn has been a consistent presence on the Internet since its creation — obviously, since he was its co-creator. But like many tech pioneers his resumé is longer than…

Crypto? AI? Internet co-creator Robert Kahn already did it … decades ago

Amazon is launching a new tool, Bedrock Studio, designed to let organizations experiment with generative AI models, collaborate on those models, and ultimately build generative AI-powered apps. Available in public…

Bedrock Studio is Amazon’s attempt to simplify generative AI app development

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the first months of 2024. Smaller-sized…

23 hours ago
A comprehensive list of 2024 tech layoffs

Oyo, the Indian budget-hotel chain startup, is negotiating with investors to raise a new round of funding that could cut the Indian firm’s valuation to $3 billion or lower, three…

India’s Oyo, once valued at $10B, seeks new funding at 70% discount

Five takeaways from the indictment of Dmitry Yuryevich Khoroshev, the hacker who U.S. and U.K. authorities accuse of being the mastermind of the LockBit ransomware gang.

What we learned from the indictment of LockBit’s mastermind

Jumia’s revenue and gross merchandise volume showed growth despite a decrease in quarterly active customers, according to its Q1 2024 report. Revenue increased by 19% year-over-year (57% in constant currency)…

Jumia is back, growing total sales and orders in Q1 2024

Welcome to TechCrunch Fintech! This week, we’re looking at Mercury’s latest expansions, wallet-as-a-service startup Ansa’s raise and more! To get a roundup of TechCrunch’s biggest and most important fintech stories…

Inside Mercury’s competitive push into software and Ramp’s potential M&A targets

Today is Apple iPad Event day, and we bring you all the iPad goodness you can stand, including if some of the rumors are true of what’s coming, like a…

Here’s everything Apple just announced at its Let Loose event, including new iPad Pro with M4 chip, iPad Air, Apple Pencil and more

TikTok is suing the United States government in an effort to block a law that would ban TikTok if its parent company, ByteDance, fails to sell it within a year.…

TikTok sues the US government over law that could ban the app

Meta is encouraging more users to post to its X rival Threads. In its latest experiment, the company is providing an easy toggle for users to cross-post from Instagram to…

Threads is testing cross-posting from Instagram globally

Apple just updated its two high-end tablets: the iPad Air and the iPad Pro. While the entry-level iPad didn’t receive an update, the company lowered its price, too. And of…

Here’s Apple’s new iPad lineup