Slashdot Mirror


FTC Files Complaint Against Wyndham For Hotel Data Breaches

coondoggie writes "A little over a month after the FBI warned travelers of an uptick in data being stolen via hotel Internet connections, the Federal Trade Commission has filed a complaint against Wyndham Worldwide Corporation and three of its subsidiaries for alleged data security failures that led to three data breaches at Wyndham hotels in less than two years."

1 of 46 comments (clear)

  1. Re:So fine them money they already didn't spend? by BaileDelPepino · · Score: 5, Informative

    I actually read some of the complaint. Surprisingly, it has nothing to do with the fact that they only offer unencrypted WiFi. It's the fact that they actually lied to consumers, saying they use "industry standard practices" to protect customers' privacy, but actually do nothing of the sort. In fact, their level of incompetence seems impressive.

    Here are some of the salient details from the giant list of Wyndham security screwups (ellipses and emphases mine)

    a. failed to use ... firewalls
    b. allowed ... storage of payment card information in clear readable text;
    ...
    d. ... permitted Wyndham-branded hotels to connect insecure servers to the ... network, including servers using outdated operating systems that could not receive security updates or to address known security vulnerabilities;
    e. allowed ... well-known default user IDs and passwords ... easily available to hackers through simple Internet searches;
    f. ... did not require the use of complex passwords for to ... property management systems ... Defendants used the phrase “micros” as both the user ID and the password;
    g. failed to adequately inventory computers connected to the ... network;
    h. failed to ... conduct security investigations;
    i. failed to ... monitor ... network for malware used in a previous intrusion; and
    j. failed to adequately restrict third-party vendors’ access to ... property management systems ...

    --
    Miren al Pepino! Los vegetales invidian a su amigo, como él quieren bailar. Pepino Bailarín!