Joshua Drake, the security researcher who discovered the flaw, told Forbes that the only thing a hacker would need to send out exploitations would be phone numbers. Attackers could then send messages to those numbers with bad code packaged in that would allow them to access the receiving device and steal data.
10 replies (most recent on top)
IT's the bury head in the sand crowd or maybe mud
Sure looks like it.
Its Randal's secretary trying to change the subject.
Who cares about a virus this is a layoff forum dingos
I believe There's a problem with the way AT&T sends out customer alerts via text message: They're too easy to mimic., With little effort, and some knowledge, anybody could send you alerts that look just like the real thing. Click on a link and the hacker will grab your login credentials -- or fool you into giving up your credit card too.
It's yet another phishing scheme. But instead of email, hackers can target you with texts.
The problem stems from AT&T not making its real alerts look legitimate enough, said Dani Grant, the computer programmer who noticed the flaw.
"If the official texts look like phishing, it's impossible for the customer to distinguish between what's phishing and what's not,"
First, AT&T's alerts come from a weird, four-digit "short code" number. Anyone can buy a short code (charities do it all the time). And even more confusing, different AT&T customers see different short codes.
Second, some of AT&T's real links are funky. Some point to att.com while others take you to dl.mymobilelocate.com.
Third, the text messages don't even have a consistent format. Sometimes they start in all capital letters: "AT&T FREE MSG." At other times they're lowercase: "AT&T Free Msg."
If you download a virus on your computer you don't blame your isp. AT&T (or Verizon, t-mobile, sprint, etc. for that matter) is in this case the isp.
If they are not responsible, why do the sell cellphones to be used in their network?
I did not work in IT, but I'm a very good programmer and I could not believe how easy it was to hack into any part of AT&T's network. It was really quite easy. It would make sense if those flaws were built in on purpose because otherwise they're the result of some insanely lazy security.
The flaws are built in and required by the NSA. They will never be truly fixed; I know as I help to place them there. Sorry.
Sounds like a device manufacturer problem more than a carrier problem. The makers of those vulnerable android phones should be correcting the issue...if they haven't already.