TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Critical Vulnerability in Verizon Mobile API Compromising User Email Accounts

78 pointsby rwestergrenover 10 years ago

6 comments

themartoranaover 10 years ago
Can&#x27;t be mad at the speed and outcome of the response. I&#x27;m sure they would have preferred the incident not be published at all...<p>In any case, we&#x27;ve all had &quot;oh shit!&quot; moments before. I&#x27;d love to think this would be a wake up call about quality control, but Verizon is just so freakin&#x27; big, that I can&#x27;t imagine the number of vendors that have contributed to the amount of code Verizon is running at any given time. I can&#x27;t imagine the chore of vetting it all at delivery time, let alone having to go back now, realizing how bad that bug was and assuming other sloppiness likely exists.
评论 #8908060 未加载
评论 #8908234 未加载
cauterizedover 10 years ago
I&#x27;m not generally a fan of Verizon as a corporation, but they deserve kudos for fixing the issue quickly and rewarding the OP for reporting it! This should be the norm. Too many nightmare stories of companies prosecuting users who find and report vulnerabilities.
评论 #8909063 未加载
评论 #8909274 未加载
kevinburkeover 10 years ago
Really glad this ended well for the OP and not with a prosecution for violating the Computer Fraud &amp; Abuse act (something I was deathly scared of last year when testing Virgin Mobile&#x27;s ability to brute force logins).
jmgrosenover 10 years ago
And it&#x27;s all over HTTP, too? Wow... that&#x27;s mighty disappointing.
评论 #8907995 未加载
coldcodeover 10 years ago
Though there are smart people at Verizon, much of their software is outsourced with limited oversight. I once interviewed for what I thought was a dev position but at the end of the interview them tried to slide in that I was really going to be &quot;managing&quot; the outsourced team and would not be allowed to write anything myself. I said no.
homakovover 10 years ago
How one can be that stupid to use params[:username] instead of secure session cookie? It&#x27;s like sending -100 dollars with paypal