Add Sprint to the list of US carriers whose security shortfalls put customer data at risk. TechCrunch has confirmed that the provider was using two sets of easily-guessed logins that let a security researcher access a company portal with access to customer data, including for Boost Mobile and Virgin Mobile. There were issues within the portal, too. The researcher would only have needed an account holder's phone number and a four-digit PIN to access their data, change plans or swap devices, and there was no limit on the number of PIN guesses.
Source: TechCrunch
Sprint security lapse gave access to customer data posted first on https://www.engadget.com
No comments:
Post a Comment