SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    LifeLock Bug Exposed Millions of Customer Email Addresses
Date    Sunday August 05 2018, @04:52PM
Author    martyb
Topic   
from the LifeLock-just-needs-a-data-protection-service dept.
https://soylentnews.org/article.pl?sid=18/08/04/1144255

Fnord666 writes:

Identity theft protection firm LifeLock — a company that's built a name for itself based on the promise of helping consumers protect their identities online — may have actually exposed customers to additional attacks from ID thieves and phishers. The company just fixed a vulnerability on its site that allowed anyone with a Web browser to index email addresses associated with millions of customer accounts, or to unsubscribe users from all communications from the company.

The upshot of this weakness is that cyber criminals could harvest the data and use it in targeted phishing campaigns that spoof LifeLock's brand. Of course, phishers could spam the entire world looking for LifeLock customers without the aid of this flaw, but nevertheless the design of the company's site suggests that whoever put it together lacked a basic understanding of Web site authentication and security.

Source: Krebs on Security


Original Submission

Links

  1. "Fnord666" - https://soylentnews.org/~Fnord666/
  2. "Krebs on Security" - https://krebsonsecurity.com/2018/07/lifelock-bug-exposed-millions-of-customer-email-addresses/
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=28242

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, LifeLock Bug Exposed Millions of Customer Email Addresses on 2023-06-18 07:16:54