A major flaw on T - Mobile ’s website could have allowed hackers to draw out personal selective information belonging to gazillion of customer , according to the research worker who discovered it . The hemipteran was fixed on Friday after the company was come on by a security reporter .
On Tuesday , Motherboard reportedthat it had contacted T - Mobile last week to inquire about a security defect in its website . build up with only a speech sound number , hacker could ’ve exploited the defect , the site say , to enter the personal entropy of T - Mobile reader , include their email addresses , account routine , and their phone ’s IMSI , a unique identifier assign to every twist .
The bug was primitively discover by security department researcher Karan Saini , the beginner of startup Secure7 . There ’s no grounds that it was used for any malicious purpose .

However unlikely — and with access to illegal ( yet surprisingly easy tohomebrew ) technical school , a outlaw could potentially practice a person ’s IMSI number to trail their emplacement or intercept calls , text edition messages , and metadata . Law enforcement and word agencies employ IMSI numbers to name and track cellular phone belonging to person of interest , using a cooking stove of jail cell - site simulators , colloquially have a go at it as “ Stingrays ” after one of the more popular framework . ( Another name for a Stingray is an “ IMSI backstop . ” )
Saini told Motherboard that the glitch would ’ve allowed virtually anyone to write a script that could retrieve those account details , though , as the website noted , neo - Nazi hacker Andrew Auernheimer ( weev ) was put behind bars for basically doing just that back in 2011 — onlywith iPads .
T - Mobile , which offered Saini a $ 1,000 hemipteran bounty as a payoff , had a different horizon of how the fault might be abused , saying that it impact only a small part of customers , not the full 70 - plus million .

The toter take down that the issue was resolved within 24 hours after it was reported — and for that , it merit at least some clapping .
[ Motherboard ]
PrivacySecurityT - Mobile

Daily Newsletter
Get the best technical school , scientific discipline , and polish news in your inbox daily .
News from the future , delivered to your nowadays .
You May Also Like












![]()