• The TUGBBS forums are completely free and open to the public and exist as the absolute best place for owners to get help and advice about their timeshares for more than 30 years!

    Join Tens of Thousands of other Owners just like you here to get any and all Timeshare questions answered 24 hours a day!
  • TUG started 30 years ago in October 1993 as a group of regular Timeshare owners just like you!

    Read about our 30th anniversary: Happy 30th Birthday TUG!
  • TUG has a YouTube Channel to produce weekly short informative videos on popular Timeshare topics!

    Free memberships for every 50 subscribers!

    Visit TUG on Youtube!
  • TUG has now saved timeshare owners more than $21,000,000 dollars just by finding us in time to rescind a new Timeshare purchase! A truly incredible milestone!

    Read more here: TUG saves owners more than $21 Million dollars
  • Sign up to get the TUG Newsletter for free!

    60,000+ subscribing owners! A weekly recap of the best Timeshare resort reviews and the most popular topics discussed by owners!
  • Our official "end my sales presentation early" T-shirts are available again! Also come with the option for a free membership extension with purchase to offset the cost!

    All T-shirt options here!
  • A few of the most common links here on the forums for newbies and guests!

Marriott admitted to falsely claim encryption protocols

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
Basically they lied about using a stronger level of encryption when in fact Marriott used a weaker encryption protocol.
 

LeslieDet

TUG Member
Joined
Jun 16, 2017
Messages
520
Reaction score
407
Points
173

LeslieDet

TUG Member
Joined
Jun 16, 2017
Messages
520
Reaction score
407
Points
173
All in the same Family of corporate entities.
No it isn't. LOL - check out ticker symbols MAR vs VAC. Entirely different companies, boards, etc. Yes, Marriott Vacations Worldwide was spun out of Marriott International Inc in 2011, but that was 13 years ago. Why push disinformation? The data breach had absolutely nothing to do with Marriott Vacations Worldwide.
 

bnoble

TUG Member
Joined
Nov 14, 2006
Messages
11,740
Reaction score
5,465
Points
798
Location
The People's Republic of Ann Arbor
If the article is correct, and they were storing SHA-1 hashes of sensitive data rather than the data encrypted via AES, this is a nothingburger. SHA-1 cannot be inverted (because it is a hash) and the best publicly-known algorithm to compute collisions with a given hash (which is to say, discovering the original data) is still computationally infeasible.

I guess the bad news, if there is any, is that the attacker only has to search the space of all valid credit cards, which isn't all that large and therefore has what some might consider a "reasonable" (dollar) cost in terms of computational effort. But given how easy it is to detect fraudulent use of a credit card number, it is probably not worth spending even that much on it because you won't recover that cost before the card is frozen.

Searching all valid passport numbers might also be interesting, but I'm not sure what for given that you hand your passport out to dozens of entities--your airline, the hotel front desk when you check in, etc. etc. etc.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
No it isn't. LOL - check out ticker symbols MAR vs VAC. Entirely different companies, boards, etc. Yes, Marriott Vacations Worldwide was spun out of Marriott International Inc in 2011, but that was 13 years ago. Why push disinformation? The data breach had absolutely nothing to do with Marriott Vacations Worldwide.
As far as I am concerned when I check in and verify reservations my PII and CC info is handled by Marriott.

No disrespect or disinformation intentionally floating or pushing. The average person on the street does not care or know the difference.
 

LeslieDet

TUG Member
Joined
Jun 16, 2017
Messages
520
Reaction score
407
Points
173
As far as I am concerned when I check in and verify reservations my PII and CC info is handled by Marriott.

No disrespect or disinformation intentionally floating or pushing. The average person on the street does not care or know the difference.
Whatever. You are pushing this in the MVC based forum. If you are concerned about cross-branded licensing agreements, then you might as well include Hertz and United Airlines in your post. The fact remains that it was not a breach caused by the timeshare company and the timeshare company did not admit anything, as is erroneously implied by your post an the link.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
@LesleiDet

With all due respect I understand you may have a legal background since you have been quoted and replied to matters related to timeshare issues.
I am not a legal expert, however I do understand the impact of data breaches.

May I ask another question? Are you in any way affiliated with Marriott?

With all of the above said and as long as I have been posting and reading here on TUG. More specifically this Marriott Forum it has been an unspoken rule and generally well accepted that when we speak of Marriott there is no unified division between the Hotel Side and Timeshare side.
Marriott is the Brand. The Brand gave birth to timeshare resorts. The timeshare resorts are managed by Marriott. The check-in desk accepts my Marriott Branded Credit Card. The website and backend system integrates hotel and timeshare reservations.

In Corporate Law and legal entities I understand what you are saying.

As I have said previously the guy or gal on the street does not know the difference.

I truly apologize that you are somehow offended by a press release that includes disparaging information regarding the Marriott Brand.
 

LeslieDet

TUG Member
Joined
Jun 16, 2017
Messages
520
Reaction score
407
Points
173
@LesleiDet

With all due respect I understand you may have a legal background since you have been quoted and replied to matters related to timeshare issues.
I am not a legal expert, however I do understand the impact of data breaches.

May I ask another question? Are you in any way affiliated with Marriott?

With all of the above said and as long as I have been posting and reading here on TUG. More specifically this Marriott Forum it has been an unspoken rule and generally well accepted that when we speak of Marriott there is no unified division between the Hotel Side and Timeshare side.
Marriott is the Brand. The Brand gave birth to timeshare resorts. The timeshare resorts are managed by Marriott. The check-in desk accepts my Marriott Branded Credit Card. The website and backend system integrates hotel and timeshare reservations.

In Corporate Law and legal entities I understand what you are saying.

As I have said previously the guy or gal on the street does not know the difference.

I truly apologize that you are somehow offended by a press release that includes disparaging information regarding the Marriott Brand.
I am an owner of MVC timeshares and Westin timeshares. That is the extent of my "affiliation".

Frankly, if there is any sort of TUG "acceptance" that there is no difference between the hotel company Marriott International Inc and the timeshare company Marriott Vacations Worldwide, then that is news to me and a complete disservice to everyone on the forum. The perpetuation of false narratives is an issue in our world these days, and your assumption that it is only a legal technicality is way off base. You are wrong that "Marriott" is managing the timeshare resorts. No, "Marriott" the hotel company has absolutely zero to do with managing timeshare resorts. Marriott International Inc. is a hotel company. It manages hotel flags at hotel brands. It may also own some hotel properties, although it is primarily the flag, meaning that it offers the name brand to a property and then it manages it for a fee.

Whereas, the timeshare resorts are managed by Marriott Vacations Worldwide (ticker symbol VAC). MVW is the entity that sells timeshare ownership to buyers. It is the entity that receives the management fee for managing the timeshare resorts.

Simply because you use a "Marriott branded credit card" is frankly irrelevant. You can use ANY credit card to pay when you check in. You can use a Costco branded VISA or a Discover or a Delta branded AmEx. The credit card is offered by a bank. In the BonVoy branded cards, it is Chase Bank. Chase Bank is not the same as Marriott International, Inc., nor is it the same as MVW. Surely you understand that loyalty programs like United mileage, Delta Airlines, Hilton, and Marriott Hotel's BonVoy brand typically have branded credit cards available. It is good business for the banks and for the brands.

As to reservations, yes, the timeshare reservations show up in your BonVoy account because Marriott Inc and MVC entered into cross-branding licensing agreements. They draw business off of each other. But when you make timeshare reservations, you must call MVC to make the reservations. Just like when you make hotel reservations, you do it on the BonVoy site or you call BonVoy customer service. You can't make a hotel reservation by calling the timeshare company and you can't make a timeshare reservation by calling the hotel company.

The corporate spin off happened in 2011. Prior to that date, Marriott International Inc. did indeed start the timeshare brands named after it and did form the various subsidiaries that were used to develop and manage the timeshares. In fact, in 2010, Marriott International Inc. created the MVC Trust program and started selling points. But, that business was spun off in 2011. The companies are separate. Sure, there is overlap between them, heck, I own stock in both companies, and you can too, but they are not the same company. The "man on the street" needs to understand that, and should understand it. This isn't a difficult concept. While there are more typically mergers and acquisitions, as opposed to spin offs, when spin offs happen the companies are indeed separate.

It isn't that I'm "offended" by a press release disparaging the hotel cyber security. It is that you are pushing disinformation when you accuse the timeshare company of wrongdoing in this context. Timeshare companies do many things wrong. That cyber breach just doesn't happen to be one of those things.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
I am an owner of MVC timeshares and Westin timeshares. That is the extent of my "affiliation".

Frankly, if there is any sort of TUG "acceptance" that there is no difference between the hotel company Marriott International Inc and the timeshare company Marriott Vacations Worldwide, then that is news to me and a complete disservice to everyone on the forum. The perpetuation of false narratives is an issue in our world these days, and your assumption that it is only a legal technicality is way off base. You are wrong that "Marriott" is managing the timeshare resorts. No, "Marriott" the hotel company has absolutely zero to do with managing timeshare resorts. Marriott International Inc. is a hotel company. It manages hotel flags at hotel brands. It may also own some hotel properties, although it is primarily the flag, meaning that it offers the name brand to a property and then it manages it for a fee.

Whereas, the timeshare resorts are managed by Marriott Vacations Worldwide (ticker symbol VAC). MVW is the entity that sells timeshare ownership to buyers. It is the entity that receives the management fee for managing the timeshare resorts.

Simply because you use a "Marriott branded credit card" is frankly irrelevant. You can use ANY credit card to pay when you check in. You can use a Costco branded VISA or a Discover or a Delta branded AmEx. The credit card is offered by a bank. In the BonVoy branded cards, it is Chase Bank. Chase Bank is not the same as Marriott International, Inc., nor is it the same as MVW. Surely you understand that loyalty programs like United mileage, Delta Airlines, Hilton, and Marriott Hotel's BonVoy brand typically have branded credit cards available. It is good business for the banks and for the brands.

As to reservations, yes, the timeshare reservations show up in your BonVoy account because Marriott Inc and MVC entered into cross-branding licensing agreements. They draw business off of each other. But when you make timeshare reservations, you must call MVC to make the reservations. Just like when you make hotel reservations, you do it on the BonVoy site or you call BonVoy customer service. You can't make a hotel reservation by calling the timeshare company and you can't make a timeshare reservation by calling the hotel company.

The corporate spin off happened in 2011. Prior to that date, Marriott International Inc. did indeed start the timeshare brands named after it and did form the various subsidiaries that were used to develop and manage the timeshares. In fact, in 2010, Marriott International Inc. created the MVC Trust program and started selling points. But, that business was spun off in 2011. The companies are separate. Sure, there is overlap between them, heck, I own stock in both companies, and you can too, but they are not the same company. The "man on the street" needs to understand that, and should understand it. This isn't a difficult concept. While there are more typically mergers and acquisitions, as opposed to spin offs, when spin offs happen the companies are indeed separate.

It isn't that I'm "offended" by a press release disparaging the hotel cyber security. It is that you are pushing disinformation you accuse the timeshare company of wrongdoing in this context. Timeshare companies do many things wrong. That cyber breach just doesn't happen to be one of those things.
You would need to explain these details to 99% of the owners and Guests of all Marriott Branded establishments.
They don't know or care to know these details.

Thank you for the eloquent explanation :)
 

dioxide45

TUG Review Crew: Expert
TUG Member
Joined
May 20, 2006
Messages
47,980
Reaction score
19,497
Points
1,299
Location
NE Florida
Resorts Owned
Marriott Grande Vista
Marriott Harbour Lake
Sheraton Vistana Villages
Club Wyndham CWA
I understand that the breach was actually within the old Starwood system as they were merging companies?

Fact remains though that most MVC owners were also registered with Marriott Rewards accounts (the name at the time.) THough since it was really Starwood, I suspect it impacted SPG guests and Starwood (at the time) owners and not as much MVC owners.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
I understand that the breach was actually within the old Starwood system as they were merging companies?

Fact remains though that most MVC owners were also registered with Marriott Rewards accounts at the time. THough since it was really Starwood, I suspect it impacted SPG guests and Starwood (at the time) owners and not as much MVC owners.
Oh Boy! Don't spin this out of control now :)
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
I just wasted five minutes reading this nonsense.
The entire thread should be deleted.
Regardless of the cynical comments.

EVERYONE! should take precaution these days with your identity.

Lock your credit with all 3 credit companies.

Experian, Transunion, Equifax.

Lock your checking info with https://www.chexsystems.com/

Get an IP pin from the IRS when filing your income taxes.

Use long complicated passwords and use a password manager as well.
Avoid storing passwords in your browser.

My underlying agenda here is to make everyone aware of the dangers of Personal Information Data Breaches.
While this content was taken out of context my message about Data and Cyber Security is SERIOUS and should be taken that way.
 

1Kflyerguy

TUG Review Crew: Veteran
TUG Member
Joined
Nov 20, 2012
Messages
3,506
Reaction score
1,580
Points
399
Location
San Jose, Ca
Resorts Owned
HGVC Kings Land, Elara, and Marriott Destination Club Points
Its true these are sperate companies, Marriott, Starwood, and MVC. I think the crossover relevance is that timeshare owners like to travel, and may have been impacted by the breach due to their other travel.

As for the encryption issue, i do wonder if the data did have AES-1 encryption in some of the databases, but also the lower level hash in other others or during transport.
 

Dean

TUG Review Crew
TUG Member
Joined
Jun 7, 2005
Messages
10,063
Reaction score
3,693
Points
698
You would need to explain these details to 99% of the owners and Guests of all Marriott Branded establishments.
They don't know or care to know these details.

Thank you for the eloquent explanation :)
I would like to think that most MVC, Westin, Vistana owners are more informed than you give them credit for, not just the TUG ones. There will always be those that are ill informed and the "don't confuse me with facts" crowd with about every topic.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere
I would like to think that most MVC, Westin, Vistana owners are more informed than you give them credit for, not just the TUG ones. There will always be those that are ill informed and the "don't confuse me with facts" crowd with about every topic.
What percentage of "not just owners?" But Guests and owners do you seriously think would care about these facts?
I will revise my estimate to 75%.
 

billymach4

TUG Member
Joined
Oct 20, 2006
Messages
3,930
Reaction score
1,489
Points
548
Location
Everywhere

Unfortunately Data Security, Info Security, Cyber Security is typically made more aware after a Bad Actor has infiltrated a system.
These hardware keys should be mandatory for all financial and Personal information transactions.

However the reality is that to enforce all Business and Gov't to implement this technology would be a Herculean effort that would eclipse Y2K.

Very few banks, and financial institutions have yet to embrace this technology. Even Gov't entities are playing catch up.
 
Last edited:

Dean

TUG Review Crew
TUG Member
Joined
Jun 7, 2005
Messages
10,063
Reaction score
3,693
Points
698
What percentage of "not just owners?" But Guests and owners do you seriously think would care about these facts?
I will revise my estimate to 75%.
If we narrow it down to what % actually care and are sufficiently ignorant of the issues maybe 2% or less. Still, I don't see it matters as this is not a situation where perception is reality IMO. Every single person who lives with a CC and/or puts their data online in any way knows, or should know, there is risk involved. Then there's the issue of reporters skewing the situation for a number of reasons. Unless I actually have all the facts I'm always hesitant to make too many judgements about specific situations.
 
Top