I’ve been following a story that’s been developing over the weekend about Sprint’s automated system giving out the name and billing address for mobile phones. Reading through the transcript of the phone call, it’s obvious how retarded their “security” is. But, in a later article on Boing Boing, it’s pointed out how bad this can be. The example given was guy who put in a friends phone number.
She is in a battered woman’s program and staying in a “safe house.” When he gave the automated system her phone number, it read out her address.
They’ve also found that by calling a second 1-800 number, you can find out the account balance on the account simply by entering the phone number as well.
While most mobile phone companies use rudimentary security for such things (“Please enter your zip code, followed by the pound sign”), even a little bit helps.