3 ms·
That's fair. We don't claim that this is a new problem; we are merely adding evidence and our perspective to a known problem. We do link to others who have repo
by randomwalker 7y ago
That's fair. We don't claim that this is a new problem; we are merely adding evidence and our perspective to a known problem. We do link to others who have reported similar problems when trying to disclose vulnerabilities. The sentence saying we "discovered two wider issues" was worded poorly; in the paper [1] we used the word "encountered", and I've now edited the post to use the same wording. Thanks!
Just as important, the post is a PSA that there are 9 websites whose users remain vulnerable, and people with accounts on these sites should check their 2FA and password recovery settings. The websites are: Amazon, AOL, Finnair, Gaijin, Mailchimp, PayPal, Venmo, Wordpress.com, and Yahoo.
[1] Link to paper: https://www.issms2fasecure.com/assets/sim_swaps-03-25-2020.pdf https://www.issms2fasecure.com/assets/sim_swaps-03-25-2020.p...
- tptacek 7y agoThis is all just message board kibitzing! The blog post is good. I'm just conditioned by other message board threads on this problem. Thanks for writing it.