I think nonces are generally thought of as numbers, and as a client it might be simplest in some cases to be able to reuse or derive from an existing non-number key.
"The information included names, email addresses, credit card information such as credit card numbers, expiration dates and the three-digit CVV code found on the back of credit cards, although BA has said it did not store CVV numbers."
Is it standard for airlines to handle storing payment card details themselves and hence having to be PCI certified instead of delegating to a PSP?
Someone injected Javascript into their pages which collected this information. But, yes, it's standard practise for airlines to store card information (excluding the 3/4 digit code) in the customers' PNR (Passenger Name Record) in the airline's GDS (Global Distribution System). The details are on this page: https://servicehub.amadeus.com/c/portal/view-solution/965353...
Just a quick clarification, in the case of an airline website, the PNR will not be created through the GDS (too expensive), it will be created directly in the PSS (usually managed by the same company)
For web they create them on 1A, but directly in 1A PSS, not going through 1A GDS (and therefore not paying the GDS fee, just a PSS fee). This is the case for all direct channels (websites or airline call centers) of all airlines
It was stolen via JavaScript injected on the payment page, not from having stored data exfiltrated. This writeup calls it "digital card skimming", which seems to be a good analogy for the attack: https://www.riskiq.com/blog/labs/magecart-british-airways-br...
Given that the airline industry actually runs its own payment card network (UATP, which has been around since 1936 apparently) it does not surprise me at all that airlines do much of their payment card stuff in house.
Maybe, as a first shot, they decided to favour near-instant implementation over usability by simply setting the price for an existing product to $0 and use the existing checkout flow.
Maybe, but it would have been equally as instant to just set all domains as "WhoisGuard purchased until the year 3000" in the database, and much more user-friendly.
If you're registering as a business rather than an individual it looks dodgy to have a whois privacy record instead of your business details. Not necessarily a deal breaker but definitely a single red flag
Because whois, along with the many people who scrape it, provide a public record of my domain ownership. With privacy protection it is a lot harder to prove ownership if the registrar makes a balls up.
One of the declared goals during the initial design phase of the Haskell language
was to "... be usable as a basis for further language research." From "A History of Haskell: Being Lazy with Class" available at https://www.microsoft.com/en-us/research/wp-content/uploads/.... Language pragmas feels like a nice tool to support this goal.
Anyone know of a reference for "The keyboardist Joe Zawinul was aghast at Davis’s ruthless arrangement of “In a Silent Way,”... " part?
It is difficult to prove a statement like "..he pioneered hard bop.." wrong, but it is definitely a new view on the history of jazz in the post bop era.