Virgin Mobile account security a joke? Concerned Developer reveals major security flaw.

by: Andrew GrushSeptember 18, 2012
7 36 1

Virgin Mobile

How important is your phone carrier’s security to you? If you are saying to yourself “very important,”  we have bad news for those that were considering getting Virgin’s Samsung Galaxy Reverb on September 19th, or any other device from the same operator for that matter. According to Twilio developer Kevin Burke, Virgin’s login system has one huge security flaw that makes it vulnerable to attacks. All you need is a 6-pin numerical password, and an account number to get into your account.

This might seem convenient, but it also means that there are only a million different combinations for getting into your account. For a hacker, this could make breaking in a cinch. The fact that it’s a six digit number also means many naive account holders likely use their date of birth as the pin. These types of users are just begging to get hacked.

What happens if someone forces their way into your account? They could charge an expensive phone to your account, read your texts and previous calls and even lock you out of your account by changing the pin.

Kevin Burke claims he reached out to Virgin Mobile repeatedly about the vulnerability, but after realizing that they didn’t take the problem seriously, he went public with the information. Burke’s recommendation is simply to delete credit charge information stored on your account and watch out. Even better, he suggests a change to a different carrier.

That being said, Virgin Mobile has now responded. The carrier has changed its policy to lock you out after just four attempts. There is one big problem with this system, though. The lockout uses cookie information and so any good hacker could easily clear the data and continue attempting long after the fourth try.

We live in a world where online exploits and hacks are very much a common reality for many people. Most carriers are requiring alphanumerical passwords, or even a two-method authentication to make life more secure.

Meanwhile, Virgin Mobile does virtually nothing to help keep users secure, at least in the U.S. What’s your take on the situation?

  • Matt

    Seriously Virgin Mobile? You are going to fix a vulnerability with cookies?
    If they weren’t that much effin cheaper than other carriers, this would be the point I’d switch.

  • Maive

    Not just in US, Australia too

  • Ro

    PLUS if you call or email them for service they ask you your pin over the phone, it is required to get customer service. Your acct number is your phone number BTW. They have really terrible service – it is clear that the executive leadership does not care about their customers, they just do not care.