Skip to main content

Telstra fails basic security checks

posted onJuly 30, 2012
by l33tdawg

Telstra is exposing customers' accounts to unauthorised access by failing to ask for passwords over the phone.

In most cases simply a date of birth and full name is required when customers call the telco. Telstra argues it isn't legally required to check passwords, something which James Turner, a security industry analyst at IBRS, says defeats the purpose of allowing account passwords.

"Security is meant to help streamline a process ... whereas this is sounding like it's a process which [Telstra staff are] able to bypass," Turner said. "And that's the thorne in every security practitioners side. Because we don't want security processes that people can bypass at their leisure. That defeats the purpose. If there's the mechanism for a password to be used but nobody's actually using it then that's bypassing the process."

Source

Tags

Australia Industry News

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th