TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

SMS Vulnerability in Twitter, Facebook, and Venmo

42 点作者 Titanous超过 12 年前

7 条评论

badclient超过 12 年前
<i>Right now, most people use Tent to share short 256 character long status posts with friends. Many independent developers are building other apps that use the Tent protocol.</i><p>The author should disclose if his start-up potentially competes with Twitter.
评论 #4867198 未加载
adrianpike超过 12 年前
You can spoof sender information even when you're running through a shortcode gateway, so short of requiring some sort of authentication on every transaction, there's no real way around this.<p>Just like email, you should never trust the remote identity.
评论 #4867921 未加载
kashiparekh超过 12 年前
Almost two years ago: <a href="http://www.ahmedabadmirror.com/article/3/20101125201011250211352165d14fe53/Who-updated-your-Facebook-status.html" rel="nofollow">http://www.ahmedabadmirror.com/article/3/2010112520101125021...</a>
sgtpepper超过 12 年前
I thought this sounded familiar:<p><a href="http://www.oreillynet.com/onlamp/blog/2007/04/twitter_and_jott_vulnerable_to.html" rel="nofollow">http://www.oreillynet.com/onlamp/blog/2007/04/twitter_and_jo...</a><p><a href="http://voices.washingtonpost.com/securityfix/2009/03/twitter_security_h.html" rel="nofollow">http://voices.washingtonpost.com/securityfix/2009/03/twitter...</a>
snoble超过 12 年前
best and scariest quote of the post<p><pre><code> Twitter has a PIN code feature that requires every message to be prepended with a four-digit alphanumeric code. This feature mitigates the issue, but is not available to users inside the United States. </code></pre> So they fixed the problem... but are withholding the fix from tons of users?
评论 #4867066 未加载
josh2600超过 12 年前
You can spoof outbound numbers for voice or sms.<p>As I've said previously, phone number is not identity and confusing the two is foolish.<p>What'sApp uses your phone number as the username and your IMEI backwards as the password, so I'd say they're a tad more insecure than even these folks.
badclient超过 12 年前
Twitter has a huge engineering department. I just don't know what they do.