Identify theft protection service LifeLock reportedly exposed customer email addresses

  发布时间:2024-09-21 22:51:34   作者:玩站小弟   我要评论
Symantec's identity theft protection service, LifeLock, has reportedly exposed millions of customer 。

Symantec's identity theft protection service, LifeLock, has reportedly exposed millions of customer email addresses due to a website bug.

LifeLock's email marketing webpage was taken down briefly after alerted by security journalist and researcher Brian Krebs, who published the flaw on his blog.

SEE ALSO:Google announces its first foray into the security key market

The vulnerability allowed anyone with a web browser to collect customer email addresses by changing a number in the URL, which is used to unsubscribe from LifeLock's communications.

Each sequential number corresponds to a customer record, and changing that number revealed an email address on the webpage.

Krebs was alerted of the flaw by another researcher, Nathan Reese, who was able to create a script which pulled emails from the website. Reese managed to retrieve 70 emails before stopping.

It's an attractive vulnerability to phishers wanting to target LifeLock customers, who come to the service to protect their personal data.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

When Mashable attempted access of the flaw, the vulnerability was no longer working, with the webpage requiring an email to unsubscribe from LifeLock's communications.

A Symantec spokesperson explained via email that the "issue was not a vulnerability in the LifeLock member portal."

"The issue has been fixed and was limited to potential exposure of email addresses on a marketing page, managed by a third party, intended to allow recipients to unsubscribe from marketing emails," the statement added.

"Based on our investigation, aside from the 70 email address accesses reported by the researcher, we have no indication at this time of any further suspicious activity on the marketing opt-out page."

Back in 2015, LifeLock paid $100 million to settle Federal Trade Commission contempt charges after failing to secure consumers’ personal data, and allegedly engaging in deceptive advertising.

LifeLock has more than 4.5 million users, according to a 2017 press release. It was acquired by Symantec in 2016 for $2.3 billion.

UPDATE: July 26, 2018, 3:34 p.m. AEST Added a statement from Symantec.


Featured Video For You
Scooby Doo Syndrome (Or why founders need to move on)
  • Tag:

相关文章

  • Table tennis star Shin Yu

    South Korean table tennis player Shin Yu-bin eats a banana before her women's singles semifinal
    2024-09-21
  • 一校一亮点 夯实学校育人阵地

    参会人员正在芦阳三小劳动实践基地参观。为进一步推进全市示范性标准化学生食堂创建工作,全面加强学生宿舍、绿化、节能、劳动实践基地等建设,12月5日,我市示范性标准化学生食堂创建暨学校后勤工作现场会在芦山
    2024-09-21
  • 院士领衔!这9场论坛会议吹响全国水产种业人“集结号”

    院士领衔!这9场论坛会议吹响全国水产种业人“集结号”_南方+_南方plus3天时间, 超2万平方米展览规模,9场高水平论坛会议,多项水产关键技术发布,院士、专家、科研学者、企业代表等齐聚一堂.....
    2024-09-21
  • 全市校园大力开展绿色文化建设

    雅安日报/北纬网讯近日,记者从市教育局获悉,近年来,我市立足教育灾后重建和县域义务教育均衡发展的巨大投入,大力开展校园绿色文化建设,着力培养学生爱绿、护绿的行为习惯,取得了一定的成果。据悉,全市以县域
    2024-09-21
  • The Measurers

    Fiction
    2024-09-21
  • 三年重建提升 三年跨越发展

    花凰路灾后重建已建成通车。龙苍沟道路B段。平整顺畅的兰家山公路。蜿蜒的道路连通城乡。三年前,“4·20”芦山强烈地震突发,一时间山河破碎,路桥受损。在艰苦卓绝的灾后重建中,荥经交通将一条条新路定格在荥
    2024-09-21

最新评论