About Gary Leff

Gary Leff is one of the foremost experts in the field of miles, points, and frequent business travel - a topic he has covered since 2002. Co-founder of frequent flyer community InsideFlyer.com, emcee of the Freddie Awards, and named one of the "World's Top Travel Experts" by Conde' Nast Traveler (2010-Present) Gary has been a guest on most major news media, profiled in several top print publications, and published broadly on the topic of consumer loyalty. More About Gary »

More articles by Gary Leff »

Comments

  1. So, what changed to allow them to implement this change? Presumably the worry about identical AA and USAir numbers hasn’t gone away…

  2. If AA IT stumbles on this comment, can you please add arrows to switch origin and destination when searching for flights on the website? The AA app and pretty much every other travel app in the world has it, however, the AA website does not. Thank you.

  3. This was not the reason they implemented it, but it did make security marginally better. Everything else in the world has generally required only a username/password combo. Recently, many companies have been layering on MFA (whether email, SMS, one-time tokens, etc.).

    Just having that slightly different login page (username/password/last name) + extra bit of knowledge (which last name is associated with which username) has probably stopped a large number of attacks on AA accounts. Without that protection, I now expect a large number of *successful* attacks on AA accounts, and for AA to blame customers for having a unique, 30-character password that was randomly generated and used only on AA.com.

    We’ll see how well this works out, but AA IT does not strike me as generally getting the implementation 100% on the first try in past projects (though they actually are notably better than many of their competitors!). Would love to be wrong on this one and have their new MFA program be much safer than single-factor auth!

  4. So the explanation of the two mileage programs and that as the rationale for last name entry makes sense, and I know airline mergers take forever, but NINE years later??!!

    Also, why don’t they get with the times (like decades) of using a username instead of mileage plan number? Especially for AA (who everyone knows is there worst legacy carrier), whose plan “numbers” include random letters in the middle, making recall challenging.

  5. All great comments so far! I didn’t quite understand Gary’s explanation, but I had noticed the lack of the name box. I second the log in on home screen request.

    Also compliment AA for slow removal of Flagship First as I fly next month DCA-JFK-LAX-SYD with meals in Chelsea and Qantas First lounge with a transcontinental nap inbetween. Swivel Seat to downunder all for 75,000 AA Miles Sweet AA

  6. “So, what changed to allow them to implement this change?”

    My guess: more complex password requirements and forced password changes over time have made it pretty much impossible at this point that two accounts share the same password.

  7. Thank you, Gary, for clarifying this. I also appreciate all your updates on FA strike negotiations. I have randomly spoken to FAs about it, and they are serious. I pray that something can be worked out with management. I am not making AA reservations for late July to mid-August, just in case.

  8. Now, if Delta would do the same. (the initial login doesn’t ask for last name until you enter your userid, and then it expands to show the “last name” field that’s required).

  9. @Steve Letwin – they do not have more complex password requirements and they have not forced password changes either. It does seem exceedingly unlikely that 9 years on someone is going to use their own US Airways frequent flyer number that hasn’t worked in so long?

  10. I agree 100% with what @jamesb2147 said here. The addition of a third piece of PII in the login actually made it less likely to be compromised, and it was something I appreciated with the AA login (sans not making readily available from the homepage). It would seem to me that 2FA or MFA options must be implemented now as a matter of BMPs rather than not.

    @Gary Leff – you’re tight, those are not their current IT security practices, and I hate forced password changed, so that’s why I say 2FA/MFA and biometric logins across the board – app, website, etc. Email is notoriously unreliable in terms of timing of delivery because of the infinite variation of the different providers and server configurations. An authenticator/token and biometrics in a Secure Enclave setting would be nice to have.

Comments are closed.