Menu
Email accounts exposed in Verizon My FiOS mobile app

Email accounts exposed in Verizon My FiOS mobile app

Verizon has now fixed the flaw in the API of My FiOS, according to a software developer

Randy Westergren

Randy Westergren

Verizon fixed a serious vulnerability in its My FiOS mobile application that allowed unfettered access to email accounts, according to a developer who found the problem.

Randy Westergren, a senior software developer with XDA Developers, looked at the Android version of My FiOS, which is used for account management, email and scheduling video recordings.

"Since Verizon has a good amount of my information, I thought it would be a good candidate for research," Westergren wrote on his personal blog. "I was right, and the results were astonishing."

The flaw, contained in the application's API, could have allowed an attacker to read individual messages from a person's Verizon inbox and even send emails from an account, he wrote.

Westergren looked at the traffic sent back and forth between My FiOS and Verizon's servers. He found My FiOS would return the content of someone else's email inbox by simply substituting a different user ID in a request.

He contacted Verizon on Thursday, which acknowledged the problem a day later. Verizon issued a fix on Friday, Westergren wrote.

"Verizon's security group seemed to immediately realize the impact of this vulnerability and took it very seriously," Westergren wrote. "They were very responsive during this process and even arranged for a free year of FiOS Internet service as a token of their gratitude."

Verizon officials couldn't immediately be reached for comment Sunday.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags securityExploits / vulnerabilitiesVerizon Communications

Featured

Slideshows

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

​Synnex and Lenovo hosted 18 resellers for an action-packed weekend adventure in RotoVegas, taking in white water rafting on the Kaituna River, as well as quad biking and dinner at Stratosfare​, overlooking Lake Rotorua at the top of Mount Ngongotaha​. Photos by Synnex.

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip
Show Comments