Virgin Mobile Warned About Security Issue, Doesn’t Bother Fixing It

Recommended Videos

There’s something to be said for concerned customers that contact companies in order to help them solve problems inherent in their systems. This is what Kevin Burke, one such concerned customer that just so happens to be a coder, did with Virgin Mobile USA back in August. After taking the matter seriously at first, it appears that the company ultimately did nothing about the fact that their account authentication can be easily be forced.

To prove his point, Burke created a script to brute force his own account by guessing each and every possible combination. Accounts only required six digits as a pin. It should come as no surprise that his attempt was successful. Failed authentication will lock potential miscreants out of the account, but that’s only if they’re amateurs and attempt the process through a browser or with cookies enabled.

So far, Burke has only confirmed the vulnerability with Virgin Mobile USA accounts. The company’s international accounts appear to use a different code base that is more secure to serve their customers. So, good job, international Virgin Mobile folks.

What can be accessed through this exploit? Everything a user might be able to access in their Virgin Mobile account. Malicious hackers can view the call history, change the handset tied to the account, purchase an entirely new handset, and cause the typical damage of resetting any information associated with the account. You know, just a few minor things. Clearly, this doesn’t deserve any further authentication.

As it stands, the first line of defense here would see Virgin Mobile USA implement tougher passwords. By expanding the number of digits to eight and allowing specific casing, letters, and numbers, it would potentially allow for 218,340,105,584,896 different combinations. That’s a bit tougher to crack.

(Kevin Burke via Wired, image via Brian Klug)

Relevant to your interests


The Mary Sue is supported by our audience. When you purchase through links on our site, we may earn a small affiliate commission. Learn more
related content
Read Article ‘Mamma Mia!’ Star Sara Poyzer Says a BBC Production Replaced Her With AI
Sara Poyzer performs at the Magic at the Musicals event in 2019
Read Article In Moment of Unbelievable Irony, Midjourney Accuses Stability AI of Image Theft
Spider-Man pointing at another Spider-Man, who is pointing back.
Read Article Elon Musk May Be the Lesser of Two Evils in This Legal Battle With OpenAI
Elon Musk at the 2022 Met Gala
Read Article A.I. Scammers Are Impersonating Real Authors to Sell Fake Books
A robotic hand holds a pencil.
Read Article Sexist Trolls Drive Away Twitch’s Top Female Streamer After 10 Years
Imane "Pokimane" Anys at the 2023 Green Carpet Fashion Awards
Related Content
Read Article ‘Mamma Mia!’ Star Sara Poyzer Says a BBC Production Replaced Her With AI
Sara Poyzer performs at the Magic at the Musicals event in 2019
Read Article In Moment of Unbelievable Irony, Midjourney Accuses Stability AI of Image Theft
Spider-Man pointing at another Spider-Man, who is pointing back.
Read Article Elon Musk May Be the Lesser of Two Evils in This Legal Battle With OpenAI
Elon Musk at the 2022 Met Gala
Read Article A.I. Scammers Are Impersonating Real Authors to Sell Fake Books
A robotic hand holds a pencil.
Read Article Sexist Trolls Drive Away Twitch’s Top Female Streamer After 10 Years
Imane "Pokimane" Anys at the 2023 Green Carpet Fashion Awards