Skip to main content

Apple Online Store Security Flaw Exposed PINs of T-Mobile Customers

https://ift.tt/2w8HRXS

A security flaw in Apple's online store exposed the account PINs of more than 72 million T-Mobile customers, reports BuzzFeed News.

The vulnerability was discovered by security researchers Phobia and Nicholas "Convict" Ceraolo, who also found a similar flaw in the website for phone insurance company Asurion that exposed AT&T account PINs.

Both Apple and Asurion fixed the website flaws that left the PINs vulnerable after learning about them from BuzzFeed News. Apple opted not to provide further comment on the situation, but told BuzzFeed News that it is "very grateful to the researchers who found the flaw."

The page on Apple's site that let hackers brute force PINs, via BuzzFeed News

PINs, or passcodes, are numbers that are used as an additional account security measure by many carriers in the United States. Mobile device PINs are typically a last line of defense for a cellular account as both carrier websites and support staff will ask for the PIN for confirmation before making account changes.

SIM hacking, which uses social engineering to get carrier support staff to transfer a person's phone number to a new SIM, has become increasingly prevalent due to the number of accounts (bank, email, social media, etc.) that are tied to a person's phone number. A PIN is used as a defense mechanism against SIM hacking, which means exposed PINs can be particularly dangerous.

Accessing the T-Mobile PINs on Apple's website involved a brute force attack where a hacker used software to input multiple different numeric combinations to guess the proper one.

As BuzzFeed News explains, after initiating a T-Mobile iPhone purchase on the Apple online store and selecting monthly payment options through T-Mobile, Apple's site directs users to an authentication form asking for a T-Mobile number and account PIN or last four digits of a social security number (which most carriers use in place of a PIN when one has not been set).

The page allowed for infinite entry attempts into the PIN field, enabling the brute force attack that let hackers guess PINs associated with a T-Mobile phone number.

The security vulnerability appears to have been limited to T-Mobile accounts, as the same validation page for other carriers on Apple's site uses a rate limit that locks access to the form for 60 minutes after five to 10 incorrect entries. Given that the other carrier pages had rate limiting enabled, it's likely Apple made an error on the T-Mobile page.
According to Ceraolo, the vulnerability is likely due to an engineering mistake made when connecting T-Mobile's account validation API to Apple's website.
A similar vulnerability on Asurion's website exposed an unspecified number of AT&T account PINs. An AT&T spokesperson said that it is working with Asurion to investigate the issue and will "take any additional action that may be appropriate."

A phone number was required for both of these attacks, limiting the number of people who may have been impacted, but AT&T and T-Mobile customers who are concerned about their account safety should choose a new PIN.

Tags: T-Mobile, AT&T

Discuss this article in our forums



from MacRumors: Mac News and Rumors - All Stories https://ift.tt/2o8Crrr

Comments

Popular posts from this blog

How to Get a MacBook or MacBook Pro Keyboard Repaired Free Under Apple's Service Program

https://ift.tt/2tocBCJ Apple has initiated a new worldwide service program offering free repairs of MacBook and MacBook models equipped with low-profile, butterfly mechanism keyboards, after the company determined that "a small percentage" of the keyboards may develop one or more of the following issues: Letters or characters repeat unexpectedly Letters or characters do not appear Key(s) feel "sticky" or do not respond in a consistent manner Apple or Apple Authorized Service Providers will service eligible MacBook and MacBook Pro keyboards free of charge. Apple says the process may involve the replacement of one or more keys or the whole keyboard. The following MacBook and MacBook Pro models are eligible for the program: MacBook (Retina, 12-­inch, Early 2015) MacBook (Retina, 12­-inch, Early 2016) MacBook (Retina, 12-­inch, 2017) MacBook Pro (13­-inch, 2016, Two Thunderbolt 3 Ports) MacBook Pro (13-­inch, 2016, Four Thunderbolt 3 Ports) MacBook Pro...

How to like, comment, and add subscribers to shared photo albums on your iPhone, iPad, Mac, or PC

https://ift.tt/2q570On With iCloud Photo Sharing, you can share, like, and comment on photos and videos with friends and family around the world — no social media account needed. Making or subscribing to a shared photo album on iCloud is just the beginning: Once you're part of a shared album with your friends, family, or co-workers, you can add comments, like photos, invite more pals into the fray, and more. iCloud Photo Sharing: The ultimate guide If you want the social media experience without having to plaster your images across the internet, iCloud Photo Sharing offers some great tools for it. Here's how you can like your friends' images, add new people to an existing shared album, and add comment threads to photos and video. How to share albums with people who don't use iCloud How to add someone to a shared photo album How to remove someone from a shared photo album How to let other people add photos and video to your shared photo album How to like...

The Instant Pot Craze and How it's Disrupting Kitchens Everywhere

http://ift.tt/2InTBKj Pressure cooker? Slow cooker? Rice cooker? The Instant Pot is all of these things and more! The Canadian-designed Instant Pot is essentially a roided out slow cooker for half the price of most decent slow cookers on the market. There are several iterations of the Instant Pot, and it may just be able to replace every imaginable kitchen appliance you have. So what's the hubbub? Is the hype real? Let's take a look! See at Amazon What does it do? I think, in terms of kitchen capabilities, the better question is what doesn't the Instant Pot do? The lower-end versions have 6-in-1 functionality, while the Ultra, for example, can be a slow cooker, pressure cooker, rice cooker, yogurt maker, cake maker, egg cooker, sauté cooker, steamer, warmer, and sterilizer. Oh, and the 6-quart Ultra model is only $150 ... Somehow… Basically, the Instant Pot could be your tool for cooker just about everything. With many programmable cooking options, for everyt...