FreedomPop Account Hijacking Flaws Remain Unpatched

  • 3 May 2016
  • 1 reply
  • 114 views

Userlevel 7
Badge +54
By Michael Mimoso May 3, 2016
 
                                                    



It took close to two months, but free wireless and mobile provider FreedomPop has acknowledged reports of a serious vulnerability in its service.

U.K.-based researcher Paul Moore told Threatpost that FreedomPop, which has been operating in the U.K. since last September, finally responded to a bug report that Moore had sent twice since March 24, in addition to an email to its chief technology officer and numerous attempts over Twitter.

Moore on Monday published a blog post explaining the critical nature of the vulnerabilities in FreedomPop and how they can be combined with unrelated bugs on the Halifax bank website to put customers’ accounts at risk.
 
Full Article

1 reply

Userlevel 7
Sounds like someone was in denial over this and has finally had to face up to the facts...and at what potential cost to its 'customers'/users? :(

Reply