phreaking out

posted by tom / February 22, 2005 /

If you've been doing your duty as an American media consumer, you're aware of the following recent developments:

Yes yes, it's all very titillating, but what about the cell phone?!?!

Well, the Sidekick hacking thing happened because SK data is mirrored to T-Mobile's servers. It's a neat feature that lets you use your phone's address book over the web and ensures that you'll never lose your data. Someone broke into that server and could consequently help themselves to a copy of the data on an SK user's phone. The hack affected all T-Mobile SK users, so yes, I too am dreading seeing Gawker post that photo of Aaron bowling I took that one time. I'm sure they'll get to it any day now, and it will be devastating.

But now Paris' voicemail has been hacked, too. Or, more accurately, phreaked, the term of art for hacking phone systems. Interestingly, this was done through means unconnected to the SK data theft. And unsettlingly, the exploit used might be applicable to your voicemail, too.

Kevin Rose has the scoop, but it's simple enough to summarize. There exist various services allowing users to fake Caller ID information -- you dial into a system and it places a call with customized caller ID info, then connects you. This can make for some great pranks.

Unfortunately, Caller ID appears to be the security measure used by T-Mobile, Sprint and perhaps others to let users avoid entering their PIN every time they call to check their messages. So if you want to get into someone's messages you just need to place a spoofed call from their number into the voicemail system -- usually accessible by calling the mobile number in question when you know it won't be picked up. Oof. Not great, guys.

More worrying: the fact that credit card activation is frequently confirmed via Caller ID. Businesses might want to think about leaning on this insecure system a bit less. In the meantime, you might want to turn off automatic voicemail login if you've got any messages you don't want to share with nosy friends.

Comments

ack! ACK! need NSFW alert.
also, what, i get no love for informing you of the jennifer aniston lesbian meme?

Posted by: catherine on February 22, 2005 12:16 PM

Okay, I added a (NSFW).

And I apologize, I should have credited you. Although, like I said to you earlier, I think original sourcing for this Aniston/lesbian story has to go to my subconscious circa 1995.

Posted by: tom on February 22, 2005 12:25 PM

Post A Comment

Name


Email Address


URL


Comments


Remember info?



Google Analytics