AT&T iPad Hacker's Real Crime Was Embarrassing the Wrong People | Wired ...

AT&T iPad Hacker's Real Crime Was Embarrassing the Wrong People | Wired ...

Disclosing a flaw in a widely used system without making someone at least a little angry requires a delicate touch. But Andrew Auernheimer, a.k.a. “Weev,” a 26-year-old finder of security vulnerabilities, is anything but delicate.Two years ago, Auernheimer and a friend made a surprising discovery about the way AT&T was protecting its web database of iPad cellular data accounts: That is, AT&T wasn’t protecting it at all. Any customer could access his or her account data by going to an AT&T URL containing their iPad’s unique numerical identifier. No password, cookie, or login procedure was required to bring up a user’s private information. Auernheimer

Who influenced this selection?What is this?

What the influencers are saying

  1. Robert McMillan

    171.0 days ago

    "How can our delicate security ecosystem survive if embarrassment becomes a crime?" Well asked, @mattblaze http://t.co/jELjyXPB

  2. Chris Wysopal

    171.0 days ago

    RT @bobmcmillan "How can our delicate security ecosystem survive if embarrassment becomes a crime?" http://t.co/wBlsWvQP < It can't.

  3. attrition.org

    171.0 days ago

    AT&T iPad Hacker’s Real Crime Was Embarrassing the Wrong People - http://t.co/l5GCcEgv (by @MattBlaze)

  4. briankrebs

    171.0 days ago

    RT @bobmcmillan: "How can our delicate security ecosystem survive if embarrassment becomes a crime?" Well asked http://t.co/40GLBz8O

  5. Web Security News

    171.0 days ago

    AT&T iPad Hacker’s Real Crime Was Embarrassing the Wrong People http://t.co/Qus5sxxU



Related Reading




InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.