BoingBoing reader Steve Parkinson has discovered a customer data security hole in the automated phone care system for Sprint Wireless.

Here's how it works. You dial a certain toll-free Sprint customer service line (doesn't matter what number you're dialing from), then punch in the cellphone number of a Sprint Wireless subscriber (not necessarily yours). The Sprint voice-bot reads back to you the full name and street address of the accountholder associated with that number. Could be you, could be someone else.

Steve discovered that under certain circumstances, at a later stage in the call process, this service will also read read back to you the names of other residents at that same address.


Oh, that's just brilliant. The more I learn about information security in the US, the more I fear for the human race.
Tags:
This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

.

Profile

sigma7: Sims (Default)
sigma7

Most Popular Tags

Powered by Dreamwidth Studios

Style Credit

Expand Cut Tags

No cut tags