About Gary Leff

Gary Leff is one of the foremost experts in the field of miles, points, and frequent business travel - a topic he has covered since 2002. Co-founder of frequent flyer community InsideFlyer.com, emcee of the Freddie Awards, and named one of the "World's Top Travel Experts" by Conde' Nast Traveler (2010-Present) Gary has been a guest on most major news media, profiled in several top print publications, and published broadly on the topic of consumer loyalty. More About Gary »

More articles by Gary Leff »

Comments

  1. How exactly are the “dates and amounts” of CC bills sensitive? Time to make your tinfoil hat. lol 😉

  2. Hilton Honors is still VERY insecure in that they have no option to remove the 4-digit PIN access from your account. Doesn’t do a lot of good to have an option for a secure password when there isn’t a way to turn off the insecure access. I’ve sent emails, called the Diamond Desk and even written a letter. No change yet. 🙁

  3. The servers that these companies use to store and send emails may be encrypted, but no email that is sent over the internet is encrypted. It’s my understanding that the protocols that email is based on are fundamentally open. All email should be treated the same as a postcard sent in the mail. It can be read by anyone that desires to.

  4. This is why some banks send their sensitive updates via their internal mail system. Chase, for example, always sends me regular (not secure/encrypted) emails along the lines of “you have an email about your account on our secure server.” You then have to login to your account in order to access them.

  5. Does anyone know if google snoops email in corporate accounts (as opposed to free email accounts)?

  6. @easy victor – They most certainly do. See the part about “What kind of scanning/indexing of user data is done?” https://support.google.com/a/answer/60762?hl=en I did read that they’re considering discontinuing that practice since they ended it for Google Apps for Education accounts.

    @mark – This still reveals the time and sender of emails to third parties, but yes, that’s exactly the reason banks have independent “secure messaging” systems.

    @mason – You are confusing issues, i believe. There’s a critical distinction between messages *in transit* and *on the server.* Google’s report shows that many messages are completely unprotected while *in transit.* Truly, email was designed as part of a trusted system, so once they’re on the server, they’re sometimes left unecrypted (it depends on the server’s configuration). However, there’s PGP software that will let users encrypt messages so that even the email admin cannot read them. I’ve only seen PGP used by banks and lawyers, FWIW.

    @Eddy – The owner of the @N twitter handle was hacked because someone found out the last four digits of his credit card number. We, very fortuitously, have legal protections with credit cards. That won’t save you from a hacker with a creative use for your financial data. https://arstechnica.com/security/2014/01/picking-up-the-pieces-after-the-n-twitter-account-theft/

Comments are closed.