Wrinkle in iPad security case

The New York Times has more        that it exposed the security
details on the iPad security       vulnerability on the
breach that led to the arrest      company’s site to alert it to
of two men yesterday. Andrew       the problem. The flaw allowed
Auernheimer, of Fayetteville,      anyone to discover e-mail
and another man were charged       addresses by submitting
with fraud and conspiracy to       potential iPad identification
access a computer without          numbers to the site. The
authorization. The men were        group’s post said that “all
part of a group called Goatse      data was gathered from a
Security that found a weak         public Web server with no
spot in AT&T's website that        password, accessible by
allowed them to gain access        anyone on the Internet."...
to personal information from       Richard Wang, manager of the
over 100,000 iPad users.           security firm SophosLabs in
The Goatse Security group          the United States, said there
informed AT&T back in June         was “criticism to be leveled
that there was a security          at both sides” in the case.
flaw that allowed anybody          “AT&T’s site wasn’t
with a web connection to get       sufficiently secure,” Mr.
those passwords, no hacking        Wang said. The company may
required. Instead of giving        have felt pressure to take
them a medal, they got busted.     strong action, he said,
The Goatse Security group          considering the data leak
originally maintained, in an       involved a prominent business
open letter to AT&T in June,       partner.                      

Tags: , , ,

Related posts: