After three days, Continental Airlines is still trying to fix its website (see earlier post).
However, the problems they experience are worse than just a malfunctioning website. By simply logging in, not only is once record locater (the E-ticket code one gets to check in) exposed in the URL, but by simply changing that record locater, you can merely browse from one reservation to another - and none of them are yours… now that is horrible. I can change these people’s seats, cancel their reservation, etc. Just as if they were mine. I can even upgrade them if they have enough frequent flyer miles.

If you are a continental customer, give it a try. Log in, check a reservation and you get something that looks like this
http://www.continental.com/web/en-US/apps/reservation/flight/
view/default.aspx?
SID=SESSION_ID&CN=RECORD_LOCATOR&IN


Share This

Related Posts

Comments