Virgin Mobile Vulnerability Leaves 6 Million at Risk

Latest Videos FromTom's Hardware
TOPICS
Jane McEntegart
Contributor

Jane McEntegart is a writer, editor, and marketing communications professional with 17 years of experience in the technology industry. She has written about a wide range of technology topics, including smartphones, tablets, and game consoles. Her articles have been published in Tom's Guide, Tom's Hardware, MobileSyrup, and Edge Up.

  • Jim_L9
    Ouch, that stinks!
    Reply
  • snowzsan
    Considering I personally use Virgin, that kinda blows.

    But in the same respect, I don't associate anything of any monetary value to anything I could so easily lose, or in this case, could be easily accessed by malicious means.

    In general, this is just further proof that the best defence is your own. Be smart with your money and where you put it.
    Reply
  • teh_chem
    I also use VM, and I was concerned about this since the get-go.

    What bothers me more is that when you call and speak with CS, in order to access your account, they ask for your password. UMMMMM...isn't that ALSO a bad thing? Why should "real" customer support on the inside of the system require my password that I use to log in from the outside? IIRC, people have verified that they require your password because they essentially log in to your account as you in order to see the information on your account (not to actually verify your identity). I'd be more worried about that first than some brute-force password crack.

    @snowzsan--do you use their option for automatic payments?
    Reply
  • COLGeek
    Pretty (as in VERY) loose security model (not!) there. Accounts are sure to not remain "virgins" to nefarious uses. Not good, Virgin, not good at all.
    Reply
  • Old_Fogie_Late_Bloomer
    I'm waiting for Virgin Mobile to sue this guy for going public about a massive security flaw that they're refusing to fix...
    Reply
  • ddpruitt
    I guess it's time for me to switch to someone else. False security is worse than no security.
    Reply
  • rantoc
    Now when media know of it they will say they take all users security as highest priority and change it, not a second before.... bastards!
    Reply
  • kelemvor33
    I always thought it was lame that VM just used a 6 digit PIN. Especially with all the sites getting hacked into lately and things like that, you'd think they'd change their system. Maybe they will now that this has gone public...
    Reply
  • teh_chem
    I think another good question is, while it's clear that their extent of password security is terribad and needs to change, what is the real likelihood that you're going to get hacked? People would have to have your cell phone number AND know that you're a VM user. Is it possible to extract carrier from cell phone number?

    I'm not defending the situation, but the real chance of brute-forcing an account is dependent on knowing the specific cell phone number = and knowing that it's a VM account. Think about myself, the only people I can think of who know that much about my cell phone are probably just my friends and family--I doubt they're going to try to brute force into my account.

    Regardless, it should be fixed--I wonder if a petition is going to start up? Also, is there a stipulation of site access security that the FCC presides over? Can one lodge a complain on these grounds?
    Reply
  • Vorador2
    How hard is to change a password system? Really, Virgin?
    Reply