Categories
Close
Menu
Menu
Close
Search
Search

Featured Articles

News

Security flaw on Immobilise mobile phone database is now fixed

Mark

Share:

Print

Rate article:

No rating
Rate this article:
No rating

The Immobilise.com online database, which helps people to store their mobile phone’s IMEI number and record other valuable items, has had a significant security flaw fixed this week.

Users are able to see an online ‘certificate’ that includes their name, address and details of the property they’d registered.

However, security consultant Paul Moore discovered that changing the numbers in a web address for this certificate could reveal information about other people’s valuables.

He described it as “a nice shopping list for a would-be burglar”.

Mr Moore had contacted Recipero, the company behind the Immobilise and CheckMEND sites, in 2013 to warn them about the vulnerability. He made the news public this week after realising that the security flaw still hadn’t been fixed.

Since publicising the issue, the vulnerability has been removed.

In a statement on the Immobilise.com website, Recipero said “We confirm that a vulnerability in a website feature was highlighted to us on 3rd January. If exploited this could have allowed a third party to view details associated with an item registration. The vulnerability was in a feature intended for use by insurers when confirming the validity of an ownership certificate given to them by a claimant. The feature was removed within 30 minutes of us becoming aware. A thorough review of our records reveals no evidence of any data leakage and therefore no requirement to contact any individual Immobilise users.”

[BBC News; Paul Moore website]

Comments

Collapse Expand Comments (0)
You don't have permission to post comments.

Opinion Articles

ExclusiveEricsson will 'muddle through' as income falls

Mark Bridge writes:

I spend much of my time writing about telecommunications and technology. I spend a fair amount of time dealing with big technology-related companies. Yet although I understand many aspects of telecoms, I certainly wouldn’t want to run one of those businesses. It’s a question of relevant experience.

ExclusiveApps World 2012: something for everyone... and for every platform

Apps World 2012 takes place on Tuesday 2nd October and Wednesday 3rd October at the Earls Court 2 exhibition centre this year. It combines an exhibition with workshops and conference sessions designed for mobile developers, marketers, network operators, manufacturers and other mobile industry professionals.

In addition, there’s an award event - the Appsters awards - with a drinks reception and party at The Roof Gardens in Kensington on the Tuesday night.

ExclusiveLast week at The Fonecast: 16th July 2012

Mark Bridge writes:

BlackBerry and bad news seem inextricably linked at the moment. RIM’s CEO admits he’s “not satisfied” with recent company performance and warns of challenging times ahead... and then the company is hit by a $147 million dollar damages order for patent infringement.

Mind you, Research In Motion wasn’t the only mobile company bringing disappointment into the mainstream news last week.

Application review for CamScanner

ExclusiveApplication review for CamScanner

Mark Bridge writes:

Every so often, I see a new product that I’d like to review. I’ll usually send a note to the relevant company, borrow a review copy and send it back when I’ve finished.

And every so often I’ll be approached by a company that wants me to review a product. Sometimes I’ll say yes, sometimes I’ll say no. It all depends whether or not I think I’m the right person for the job.

When IntSig offered me a copy of a mobile application called CamScanner, I wasn’t too sure. It seemed very clever... but I wasn’t convinced I’d have much use for it.

ExclusiveIan Brown, CEO of Axell Wireless, talks about underground mobile phone coverage

Mark Bridge writes:

Just a few weeks ago WiFi was made available on a number of London Underground stations - yet mobile coverage still stops when you go down the escalator.

So why is it taking so long for us to get mobile phone service on the Tube?

For an insight into some of the challenges and the possible solutions I spoke to Ian Brown, CEO of Axell Wireless. The company is a leader when it comes to providing additional wireless coverage in confined spaces - from tunnels to sports stadiums - and is currently involved in the project to install mobile phone service on the Channel Tunnel.

RSS
First3536373840424344Last

Recent Podcasts

ExclusivePodcast from Mobile World Congress 2015

Mark Bridge learns about the mobile technology trends at Mobile World Congress 2015 by chatting to James Rosewell of 51Degrees, Dr Kevin Curran from the IEEE and Chris Millington of Doro.

They talk about wearable devices, wireless charging, mobile operating systems and much more... including some of their favourite products from the exhibition.

ExclusiveLooking back at February: from security scares to multiple MVNOs

We're taking a look back at the biggest mobile industry news stories from February 2015, including allegations that the UK's security service tried to breach SIM card security by hacking into one of the world's biggest SIM producers.

We also talk about the planned BT and EE merger, the creation of two new UK virtual networks, some acquisitions in the mobile payment arena and a new Ubuntu smartphone.

ExclusiveA month of mobile: O2 counts on 3, Microsoft counts to 10 and Apple counts its profits

We're back with a month of mobile industry news, including takeover talks and takeover rumours. O2 and Three are said to be discussing a merger... but is there any truth in the suggestions that BlackBerry could be up for grabs?

We also discuss Apple's record-breaking quarterly figures, the highlights of CES and the launch of Microsoft Windows 10, as well as saying farewell to the current version of Google Glass.

RSS
12345678910Last

Follow thefonecast.com

Archive Calendar

«May 2026»
MonTueWedThuFriSatSun
27282930123
45678910
11121314151617
18192021222324
25262728293031
1234567

Archive