Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

The Armageddon Of Stupidity: SMS Password Management SNAFU

November 17, 2018 by Marc Handelman in Which Way To The Bunker?

via Zack Whittaker, reporting at Techcrunch, comes what may be the Armageddon (or should be) of SMS Messaging to facilitate password resets, password modifications, and two-factor authentication codes. The stunning level of incompetence displayed by the owners, managers and administrators of the system under scrutiny is quite simply astounding (No server level password, database open to the internet, et cetera). And... Then There's This.

"The exposed server belongs to Voxox (formerly Telcentris), a San Diego, Calif.-based communications company. The server wasn’t protected with a password, allowing anyone who knew where to look to peek in and snoop on a near-real-time stream of text messages." - via Zack Whittaker, writing at Techcrunch, comes this astounding story of incompetence and a nearly complete lack of security...

November 17, 2018 /Marc Handelman
Which Way To The Bunker?
  • Newer
  • Older