Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Wide open" is factually incorrect if they still require you to guess the pin.

Why didn't the author also mention that since there's no e-mail address associated with new prepaid accounts you can specify any e-mail you want the first time you try to sign into the website? Seems like an easier exploit to me.

Their network ACLs and support web apps are also swiss cheese. I wouldn't really rely on a VM account for security.



That doesn't make me feel great about two-factor authentication through my VM phone.


Good! This is just a better example of why SMS and non-encrypted-and-authenticated connections for two factor are silly. If you use an HTTPS web app for two-factor (or a pin-generating app, no network required) you should be reasonably secure - unless some Android malware is in your phone.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: