Search:  

 
 
   News
newer
story category Sprint Security Questions Ridiculously Easy To Guess
Assuming you don't actually own a Porsche...
01:13PM Wednesday Apr 09 2008 by Karl Bode
tags: business · wireless · Sprint Broadband Direct
Click for full size
Some of the security questions Sprint uses to confirm user identity are pretty easy to guess, notes the Consumerist. The questions, designed to prevent identity theft or fraud, are automatically generated and fairly easy to circumnavigate with a modicum of common sense. One asks the user to select the brand of the car you own, but puts your model up against choices like Lamborghini and Lotus.

Someone logging into your Sprint website account only has to get two out of the three questions correct, according to a follow up post by a Sprint employee. Another common question can be circumnavigated "99% of the time" by choosing the final option, "none of the above."

Sprint says they outsource the system to a third party operation, but insists they've alerted them "so that it can make the necessary adjustments to ensure that our customer verification process remains secure". Remains secure?

Related:
  1. Which 3G Network is the Best?
  2. Sprint Broadband Direct Goes Offline July 31
  3. Sprint Revives Nextel's Push-to-Talk Innovation
  4. Stats Released on 10 Largest Wireless Carriers
  5. Sprint's Instinct Reaches Record Sales
  6. Sprint WiMax: Less Than $50
  7. Sprint Reduces EVDO 'Phone As Modem' Fee
  8. Xohm Deployment Ahead of Schedule
Forums » Sprint Security Questions Ridiculously Easy To Guess
view: topics flat text 
Post a:
jc100

join:2002-04-10

sigh

Noticed this too.. O well... Get what you pay for. They are liable for any identity theft and or unauthorized changes so hope they correct the issue.
SilverSurfer

join:2007-08-19

Re: sigh

said by jc100 See Profile :

They are liable for any identity theft and or unauthorized changes so hope they correct the issue.
Who says so?
jc100

join:2002-04-10

Re: sigh

If someone breaches their system, then they are liable. Same goes if you use your credit card at a store, and someone hacks the system. I'm sure you recalled that happening all not long ago =).

insomniac
Oh Yeah
Premium
join:2002-09-22
Naperville, IL
clubs:
·AT&T Midwest


edit:
April 9th, @02:46PM

Re: sigh

Not if you agreed to hold them harmless simply by using their service... which you likely did. Sorry, Sprint is going to leave you out in the cold on this one--and I say this as a longtime Sprint customer.

I'd say your bank is more liable than the company is, since they're the ones who will end up eating any unauthorized charges. But good luck suing them.
--
If everything seems to be going well, you've obviously overlooked something.

tc1uscg

join:2005-03-09
Saint Clair Shores, MI
·Comcast
·WOW Internet and C..
·VoiceEclipse

Re: sigh

said by insomniac See Profile :

Not if you agreed to hold them harmless simply by using their service... which you likely did. Sorry, Sprint is going to leave you out in the cold on this one--and I say this as a longtime Sprint customer.

I'd say your bank is more liable than the company is, since they're the ones who will end up eating any unauthorized charges. But good luck suing them.
Name me one company (wireless) that WON'T leave you in the cold?
tick tock tick tock.. BZZZZZ times up.
NONE!
jc100

join:2002-04-10
·RoadRunner Cable

Re: sigh

Well no company is going to admit fault, unless it serves to benefit them. When several companies had their billing systems breach, they too proactive measures. They came out looking "better" by notifying customers and offering credit monitoring. This probably mitigated their damage. However, if there ended up being charges, the CC company could go after the business for the costs.. CC companies are good about not sticking it to the consumer when it comes to fraud. They more than make up for it with their interest rates though.
SilverSurfer

join:2007-08-19

said by jc100 See Profile :

If someone breaches their system, then they are liable. Same goes if you use your credit card at a store, and someone hacks the system. I'm sure you recalled that happening all not long ago =).
I'm not disputing that a degree of liability exists. I'm just saying that it may not be as extensive as you assume. A substantial portion depends on what the state law is because the feds are severely remiss when it comes to data breaches of servers and ID theft.

Jameson
Premium
join:2004-05-28
Fallbrook, CA
clubs:
·Sprint Mobile Broa..
·HughesNet Satellit..
·surpasshosting

Something I noticed

I noticed that the other day when I had to re-login to my account and forgot the new password they made me set. Funny thing is that everything has to be so secure on your account (password containing uper and lower case letters and numbers) yet they have insecure security questions..
--
Sprint EVDO| 3.2GHZ Intel | BFG GF 6800 OC | Win XP Pro SP2/98SE/ Macbook Pro OS X Tiger | PCs connected via Linksys WRT54G | DD-WRT firmware: DD-WRT v24 Beta (01/18/07) std

KrK
Heavy Artillery For The Little Guy
Premium
join:2000-01-17
Tulsa, OK

Ahahahahaha ROFL

Ahh that's GREAT

Lamborghini, Lotus, Honda, or Fiat. LOL!!!

Archivis
Your Daddy
Premium
join:2001-11-26
Earth

Re: Ahahahahaha ROFL

Whatever dude. I have like 3 Lamborghini's in my back yard.
jc100

join:2002-04-10

Re: Ahahahahaha ROFL

LOL only 3? Peasant!! I've got a museum full.

en102
Canadian, eh?

join:2001-01-26
Valencia, CA
I have a Yugo, Lada and Fiat
Lada = Its a 'Lada' trouble to get it fixed.
--
Canada = Hollywood North

dadkins
Living on a Blu Planet
Premium,MVM
join:2003-09-26
Hercules, CA
·Comcast


edit:
April 9th, @02:17PM

Re: Ahahahahaha ROFL

said by en102 See Profile :

I have a Yugo, Lada and Fiat
Lada = Its a 'Lada' trouble to get it fixed.
Yaris FTW!

Actually, I don't own a car... good thing I don't use Sprint, huh?
--
Think outside the Fox... Opera

KrK
Heavy Artillery For The Little Guy
Premium
join:2000-01-17
Tulsa, OK
·Cox HSI
·AT&T Southwest

said by Archivis See Profile :

Whatever dude. I have like 3 Lamborghini's in my back yard.
This a picture of one of em in your backyard?


NowVOIP
In the beginning there was POTS

join:2006-03-05
Round Lake, IL

Re: Ahahahahaha ROFL

Dude that's my car! What did you do to it? lol!

tc1uscg

join:2005-03-09
Saint Clair Shores, MI
YUGO..
AMC
EAGLE
PACKARD

Chuckles
Premium
join:2006-03-04
Saint Paul, MN

Just keeping up...

You cant make 'em too hard or too many customers would be calling in.
--
kustomerservice.net

AZ_OGM

join:2007-01-12
Phoenix, AZ

Re: Just keeping up...

Why not a question everybody should know.
Like "What is the airspeed velocity of an unladen Swallow?"
atsmia
Premium
join:2004-06-15
Miami, FL

Re: Just keeping up...

eastern or european?

Yaco
Yaco
Premium
join:2001-10-13
Allendale, NJ

Re: Just keeping up...

You beat me too it
bruzr
Premium
join:2007-05-05
Essex Junction, VT

Re: Just keeping up...

Please guys, review the tape - it's "African or European"

Yaco
Yaco
Premium
join:2001-10-13
Allendale, NJ

Re: Just keeping up...

I know what I'm watching Saturday night
LOL
Lee

Yaco
Yaco
Premium
join:2001-10-13
Allendale, NJ
·Verizon FIOS

Don't bash too much

Hi,
I just upgraded a Credit card and the options where similar.
For instance, It asked for 3 locals banks HSBC,CitiBank,Commerce. It asked for Cars too Fiat, Chevy, Ford.
So while not trying to be a Sprint Fanboy. I think the they should opt out of that method and go with something a little more difficult.
Lee
--
"I Don't feel Tardy"
"When Clinton Lied, All that was left was a stained dress.
When Bush lied, all that was left was 4000 less US Soldiers..

ureihcim
Freshly made

join:2007-12-16
Miami, FL

Re: Don't bash too much

I don't believe in security questions because they give out too much information even as stupid as they seem.

I actually would prefer to opt out, so you can't really guess to obtain access. If you forget your password the only way to get it changed is to visit a Sprint Store where they can do it for you, that basically is just a random generic password.

I don't see what is so hard about remembering a l/p or even several. This is a wide spread problem though, the only difference is that this some offer choices to your answer, while others simply ask you to type in your answer.
rahvin112

join:2002-05-24
Sandy, UT

Difficult questions people don't remember and a lot of the more personal questions can be answered with access to many of the databases of personal information that are maintained in this country. The point of the questions is to be easy to remember but of such a common nature that you would really have to know the person, not have access to their credit file, to answer.

The questions in this case are far to easy, but ideally you want something so unimportant that it doesn't make it in a database, but when combined with a few other questions like it, becomes completely unique to you. All the tricks the banks used to use to secure access are actually easy to acquire if not a public record. Mother's Maiden name is trivial to acquire through a genealogy research site. Where you lived, went to school and most of the details of your life are kept in a database that all you need is $$ to access. It's much easier to design security questions if you make the assumption that there is no such thing as private information anymore, only information that's too trivial to index.

Some of the better security simply has you pick a picture and phrase to show you every time you log in so you know you aren't on a phising site. Simple, impossible to fake on a large scale (can't figure it out with a database) and easy to remember.

SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
·Comcast Formerly ..

Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

Weak questions

In other systems (my CC) one of the questions is "Favorite color" This is also an inherently very weak questions, because there are probably less than 10 colors to check (few primary colors, black, white, pink, ... and if the guy works for UPS, maybe "brown").

How many people answer with "periwinkle" or "transparent"?

KA3SGM
- -... ...- -
Premium
join:2006-01-17
West Chester, PA
clubs:
·Verizon FIOS

Re: Weak questions

»www.youtube.com/watch?v=Wpx6XnankZ8


What Is Your Name?? "Sir Lancelot"

What Is Your Quest?? "To Seek The Holy Grail"

What Is Your Favorite Color?? "Blue"
--
"Lithium is no longer available on credit"
samrocks
Premium
join:2003-07-30

My Account through phone, another security threat on sprint!

I have a palm centro on sprint and when I go to my account through my phone and click on payment due, I can type in my username and type in any password I want and it will let me view my balance.
I am supposed to type in my username and password on my online account but it lets me in with any password.
I figured out this when I typed in the password wrong one day, and it let me in.

I did call sprint corporate and let them know and the guy just said thank you and hang up.
Anyone else having this problem?

lolsprint

@tmodns.net

Re: My Account through phone, another security threat on sprint!

said by samrocks See Profile :

I have a palm centro on sprint and when I go to my account through my phone and click on payment due, I can type in my username and type in any password I want and it will let me view my balance.
I am supposed to type in my username and password on my online account but it lets me in with any password.
I figured out this when I typed in the password wrong one day, and it let me in.

I did call sprint corporate and let them know and the guy just said thank you and hang up.
Anyone else having this problem?
Ha. I just tried the same exact thing. I typed random characters in as the password. Let me in with my total due, billing preference, etc. Pathetic.

sdsdsss

@pacbell.net

said by samrocks See Profile :

I have a palm centro on sprint and when I go to my account through my phone and click on payment due, I can type in my username and type in any password I want and it will let me view my balance.
I am supposed to type in my username and password on my online account but it lets me in with any password.
I figured out this when I typed in the password wrong one day, and it let me in.

I did call sprint corporate and let them know and the guy just said thank you and hang up.
Anyone else having this problem?
Yup, same thing. I entered a bogus password, and got right in
slckusr

join:2003-03-17
Maumee, OH
·AT&T Midwest
·AT&T Yahoo


edit:
April 10th, @06:41AM

easy questions ?

They always ask me my favorite restaurant.

Not sure how that would be an easy question to guess.

they also ask for some numbers that i have trouble remembering. /shrug the questions are fine, the people giving the answers are the problem.
Forums » Sprint Security Questions Ridiculously Easy To Guess


Friday, 05-Sep 19:13:24 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole