Language Selection

English French German Italian Portuguese Spanish

Glitch on Verizon Wireless Web Site Left Data at Risk

Filed under
Security

Verizon Wireless said yesterday that computer programming flaws in its online billing system could have allowed customers to view account information belonging to other customers, possibly exposing limited personal information about millions of people.

A spokesman for the Bedminster, N.J., company, a joint venture between Verizon Communications Inc. and Vodafone Group PLC, declined to say how many of the company's 45 million subscriber accounts were at risk. Verizon Wireless said the problem appeared to be limited to accounts for customers in the eastern United States who had signed up for its "My Account" feature.

There was no indication that anyone took advantage of the flaws or that any customer financial information, such as Social Security or credit card account numbers, was disclosed, Verizon Wireless spokesman Tom Pica said. The flaws also did not allow access to phone numbers associated with customers' incoming and outgoing calls, and "no customer data could be manipulated and changed in any way," Pica said.

Verizon Wireless said it had corrected the problem as of 2 a.m. yesterday. Pica said the company was still assessing whether it would notify customers about the situation.

The "My Account" feature has been available on the Verizon Wireless Web site for five years. Pica said the company does not yet know how long the flawed coding had been in place.

Pica confirmed the Web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle. Two other flaws could have exposed data about a customer's general location -- city and state -- and the make and model of phone the customer uses, Pica said.

The flaw that exposed account information was reported to Verizon Wireless by Jonathan Zdziarski, a software developer from Milledgeville, Ga., who said he discovered it while writing a computer program that would automatically query his account online and report the number of minutes he had used from his wireless plan.

Zdziarski found that by simply entering another subscriber's wireless phone number on a particular portion of the site, he could pull up some information about that person's account.
Pica said the flaws did not expose customer account balances or latest payment information. But Zdziarski provided washingtonpost.com with a screenshot showing that the vulnerabilities exposed account balances and the date of the most recent payment, a claim that Pica said the company could not confirm.

After Zdziarski's alert, Verizon Wireless technicians reviewed other portions of the company's billing system and fixed one flaw but disabled the feature that allowed viewing of customer location until technicians could figure out a way to secure it, according to Pica.
Zdziarski said he later conducted other tests and found that the problem he discovered also could be exploited to transfer one customer's account to another handset, a technique known as "cloning."

The user of a cloned phone can intercept all of the victim's incoming wireless calls and make calls that would be billed to the victim's account. Zdziarski said he was prevented from fully testing whether the flaw could be used to clone Verizon Wireless phones because the service that allows customers to map existing phone numbers to new handsets appeared to be offline when he reported the flaw.

"This was a very easy hack to do," Zdziarski said. "I'm sure if I've discovered it, then certainly your typical 'script kiddie' could figure it out."

Pica said company technicians were unable to reproduce the phone-cloning scenario described by Zdziarski.

One of Verizon Wireless's competitors, Bellevue, Wash.-based T-Mobile International, disclosed in January that a security hole in its Web site exposed data on at least 400 customers, including a Secret Service agent. This year, a group of hackers used other flaws in T-Mobile's site to break into the phones of dozens of celebrities in an incident that exposed racy photographs and personal notes and contacts for hotel heiress and socialite Paris Hilton.

By Brian Krebs
The Washington Post

More in Tux Machines

Linux Foundation introduces the LF Networking Fund, harmonizes​ open source, open standards

The Linux Foundation is taking the first step to bring some commonality across its myriad network efforts by creating the LF Networking Fund (LFN). By creating a combined administrative structure, Linux Foundation said LFN will provide a platform for cross-project collaboration. LFN will form the foundation for collaboration across the network stack: the data plane into the control plane, to orchestration, automation and testing. Read more

Openwashing Surveillance

  • Facebook Open Sources Detectron Object Detection
    The way big companies are open sourcing significant AI is both gratifying and slightly worrying. AI is the biggest revolution since we discovered fire and started making tools. FaceBook AI Research has added to the list of what is available by open sourcing its Detectron project.
  • Facebook open-sources object detection research
    Facebook's artificial intelligence research (FAIR) team today announced it would open-source its object detection platform Detectron, as well as the research the team has done on it.
  • Facebook open-sources object detection work: Watch out, Google CAPTCHA
    acebook has brought us one step closer to a Skynet future made a commitment to computer vision boffinry by open-sourcing its codebase for object detection, Detectron. Written in Python and powered by the Caffe2 deep learning framework, the codebase – which implements object-sniffing algos such as Mask R-CNN and RetinaNet – is available under the Apache 2.0 licence.

Exploring Linux containers

They're not quite virtual systems, since they rely on the host OS to operate, nor are they simply applications. Dan Walsh from Red Hat has said that on Linux, "everything is a container," reminding me of the days when people claimed that everything on Unix was a file. But the vision has less to do with the guts of the OS and more to do with explaining how containers work and how they are different than virtual systems in some very interesting and important ways. Read more

Media Covers WINE Running on Android

  • Wine 3.0 released, lets you run Windows apps on Android smartphones
    Wine 3.0, which is a compatibility layer for Linux-based systems has been released. The version brings the ability to run Windows apps on your Android device. Until now, Wine allows users to run Windows apps on Linux and other Unix-like OS.
  • Running Windows apps on Android is slowly getting there
    Our smartphones are getting so powerful that they’re being used for sometimes crazy things, like bitcoin mining or running as a desktop. How about running a desktop? Been there, done that, at least as far as Linux is concerned. But running Windows programs on Android, without tricks like remote desktops or virtual machines, is a different thing entirely. It could, however, be close to becoming reality thanks to the latest WINE 3.0 release, which paves the way for running Windows win32 programs on Android almost natively.
  • Linux Windows emulator Wine now available on Android
    Wine, the Windows emulator that (typically) runs on Linux is coming to Android. The open-source compatibility layer has been a mainstay of Linux since 1993, enabling users to deploy applications built for Microsoft's ubiquitous operating system without having to install the OS itself - notwithstanding The newly-released Wine 3.0 includes graphics drivers that extend this functionality to Android.