3 ms·
I used to work for an airline that used Amadeus and was fairly familiar with it. Every booking agent had access to a terminal connection to the mainframe (simil
by jdmath 10y ago
I used to work for an airline that used Amadeus and was fairly familiar with it. Every booking agent had access to a terminal connection to the mainframe (similar to ssh or telnet). Everyone had unique login credentials and every action can be tracked through the booking history.
Here are a few notes:
- Credit card numbers are obfuscated right after they are first used. Only certain back offices have unrestricted access.
- Viewing all the travel information in the PNR is important. For example, if a flight is arriving late, it can be useful to know that the passenger has a connecting flight with another airline on the same ticket to arrange for another connecting flight.
- Reservations are archived after a certain amount of days after the last flight. They can be retrieved in view only mode but you have to specify a date range.
- Most tickets and vouchers are non-transferable (at least for the airline I worked for) . Even changing a name on a reservation is a pain. You either have to make a new booking and re-issue the ticket or get a support desk to change the name on the current reservation and re-issue the ticket. A regular agent changing more than 3 letters of a name will result in a cancelled itinerary.
- It is possible to enter restricted comments on a PNR. You can even set who can view them. Agency only, Airline only even a specific office.
I get that he was saying that the system is unsafe but a lot of it is only in relation to the web interfaces. You can't get direct GDS access unless you're working directly for an airline or travel agency. Those people definitely need to see most of the information on the record.
Anyways, just thought I would provide some info.
- atomwaffel 10y ago> I get that he was saying that the system is unsafe but a lot of it is only in relation to the web interfaces. I think that was the point though: when these systems were being built in the 70s (i.e. pre-internet), the security measures they had – many of them based on trust – were perfectly reasonable. You'd need to have physical access to a machine connected to this closed network to even do so much as look at a reservation. And then the internet comes along and these companies (with no experience in web security) hook up their closed, tightly controlled network to an open, not-at-all controlled network with virtually no additional security. I guess it's fair to say that trust alone doesn't work too well on the internet. > You can't get direct GDS access unless you're working directly for an airline or travel agency. Those people definitely need to see most of the information on the record. Yes, but the researchers addressed this in their talk about 14 minutes in. The authentication isn't hard to crack: it consists of an agent ID and a password, often in a format like WS<DDMMYY> (where <DDMMYY> is the date of first access to the system). These credentials are shared by the same office at the very least, and I have a sneaky feeling that I might find a conspicuous post-it note on a computer screen if I visit a few of my local travel agents.
- germanier 10y agoIf I recall correctly, he said that travel agencies often have their own system (with individual passwords) hooked up to the GDS using a shared login which was set up once long time ago and then forgot.