Menu
Email accounts exposed in Verizon My FiOS mobile app

Email accounts exposed in Verizon My FiOS mobile app

Verizon has now fixed the flaw in the API of My FiOS, according to a software developer

Randy Westergren

Randy Westergren

Verizon fixed a serious vulnerability in its My FiOS mobile application that allowed unfettered access to email accounts, according to a developer who found the problem.

Randy Westergren, a senior software developer with XDA Developers, looked at the Android version of My FiOS, which is used for account management, email and scheduling video recordings.

"Since Verizon has a good amount of my information, I thought it would be a good candidate for research," Westergren wrote on his personal blog. "I was right, and the results were astonishing."

The flaw, contained in the application's API, could have allowed an attacker to read individual messages from a person's Verizon inbox and even send emails from an account, he wrote.

Westergren looked at the traffic sent back and forth between My FiOS and Verizon's servers. He found My FiOS would return the content of someone else's email inbox by simply substituting a different user ID in a request.

He contacted Verizon on Thursday, which acknowledged the problem a day later. Verizon issued a fix on Friday, Westergren wrote.

"Verizon's security group seemed to immediately realize the impact of this vulnerability and took it very seriously," Westergren wrote. "They were very responsive during this process and even arranged for a free year of FiOS Internet service as a token of their gratitude."

Verizon officials couldn't immediately be reached for comment Sunday.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags securityExploits / vulnerabilitiesVerizon Communications

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments