<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked - Consumerist Comments]]></title>
		<image>
			<url><![CDATA[http://cache.gawker.com/assets/base/img/thumbs140x140/consumerist.com.png]]></url>
			<title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked - Consumerist Comments]]></title>
			<link><![CDATA[http://consumerist.com]]></link>
		</image>
	    	<lastBuildDate><![CDATA[Tue, 15 Apr 2008 23:30:32 EDT]]></lastBuildDate>
	    	<pubDate><![CDATA[Tue, 15 Apr 2008 23:30:32 EDT]]></pubDate>
		<link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked]]></link>
		<description><![CDATA[]]></description>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5212553]]></link>
										
		    <description><![CDATA[<P>Sprint is not the only company using the security process like the above. I called into fidelity investments and said I forgot my pin and the same questions were asked to confim my identity. Cells phones are one thing investment $ is another.</P> <p>cdmarulz</p>]]></description>
			<dc:creator><![CDATA[cdmarulz]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5212553]]></guid>
		    <pubDate><![CDATA[Tue, 15 Apr 2008 23:30:32 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5193646]]></link>
										
		    <description><![CDATA[<P>Okay .. just logged into my STBX account. DA has got a new phone but has no penny to give as spousal support. Sprint still has done nothing about this breach. I could've done some changes to DA's account but didn't feel right.</P> <p>lokofun</p>]]></description>
			<dc:creator><![CDATA[lokofun]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5193646]]></guid>
		    <pubDate><![CDATA[Tue, 15 Apr 2008 03:58:45 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5187731]]></link>
										
		    <description><![CDATA[<p>Just wanted to point out that these sorts of 'security' measures (while not perfect) aren't meant to protect you from people who are 'stalking' you or are good friends who you already know a lot of information about them... It's supposed to protect you from the person who knows nothing about you and has a stack of numbers to go through.  Granted, it sounds like the implementation could use some help (more questions, better 'fake' answers), but the idea at least is an attempt.</p> <p>aaronw1</p>]]></description>
			<dc:creator><![CDATA[aaronw1]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5187731]]></guid>
		    <pubDate><![CDATA[Mon, 14 Apr 2008 18:28:35 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5133673]]></link>
										
		    <description><![CDATA[<p>For 2 days, Sprint has been upgrading  their systems and sprint.com website works 50% of the time.  CSR still hang up on you and are rude.  Managers yell at customers and agents.</p> <p>prescott</p>]]></description>
			<dc:creator><![CDATA[prescott]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5133673]]></guid>
		    <pubDate><![CDATA[Thu, 10 Apr 2008 17:48:03 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5133058]]></link>
										
		    <description><![CDATA[<P>You didn't redact the name on the "Welcome Back to My Sprint" screen -- signed in as "name should have been blacked out"</P> <p>jesuismoi</p>]]></description>
			<dc:creator><![CDATA[jesuismoi]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5133058]]></guid>
		    <pubDate><![CDATA[Thu, 10 Apr 2008 17:17:14 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5120141]]></link>
										
		    <description><![CDATA[<P>So from reading the article, if you're already registered your account online, which I (we, our family)did several years ago then it can't happen to you.</P>
<P>I guess the real question is, how many users haven't registered their account online? There certainly can't be too many that have no online access to their account.</P> <p>scooterge558</p>]]></description>
			<dc:creator><![CDATA[scooterge558]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5120141]]></guid>
		    <pubDate><![CDATA[Thu, 10 Apr 2008 09:18:22 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5118427]]></link>
										
		    <description><![CDATA[<p>""There's also the stalker's wet dream: add GPS tracking to their cellphone and secretly watch their every movement from any computer.""</p>
<p>There is an easy fix on most modern cellphones for this!!!</p>
<p>In your phone setup menu, probably buried, but be thorough through all your menu options.  You will find a setting that closely matches that above quote with two settings:  either global or Emergency 911 only (for USA). Set it to Emergency 911 only.<br>
And pray and hope and check out to see if that 911 system in your area is very modern that can grab that GPS signal from your phone and if not: Raise bloody hell to your local government officials for new 911 system.  It maybe your sister or brother or mother or father or friend who might need that location detection just to get the needed personnel there quickly as possible.</p> <p>Ton80</p>]]></description>
			<dc:creator><![CDATA[Ton80]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5118427]]></guid>
		    <pubDate><![CDATA[Thu, 10 Apr 2008 02:06:01 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5114722]]></link>
										
		    <description><![CDATA[<p>This is rather odd, but probably a result of the Nextel merger. I remember when i signed-up for my Sprint on-line account years ago. As part of the process, they sent me a one-time password to my cellphone. Very simple way to make sure that the person signing-on is the person in posession of the phone.</p>
<p>So all I can gues is when they got all excited about switching to the new platform for consumer access to their Sprint accounts, they yanked out stuff like OTP which couldn' be made to work yet....</p> <p><a href="http://www.afn.org/~riffer/">Jeff the Riffer</a></p>]]></description>
			<dc:creator><![CDATA[Jeff the Riffer]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5114722]]></guid>
		    <pubDate><![CDATA[Wed, 09 Apr 2008 20:04:20 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5106587]]></link>
										
		    <description><![CDATA[<p>Scarily enough, in addition to this, fully registered accounts that are already setup in their Online System are vulnerable via "I Forgot my PIN" which asks the same damned questions.</p>
<p>Mine - Gave me the "which car has been registered" blah blah with the answers being "Fiat, Lancia, Ferrari, and Toyota" An then with the "Which property do you own?" and "Which cities have you lived in?" almost always being "None of the above" and only needing TWO correct answers.</p>
<p>Yep. This sealed it. Getting rid of Sprint, even though they're the only provider with half a decent data network speed in the area.</p> <p>NWSPMP</p>]]></description>
			<dc:creator><![CDATA[NWSPMP]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5106587]]></guid>
		    <pubDate><![CDATA[Wed, 09 Apr 2008 14:33:10 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5099249]]></link>
										
		    <description><![CDATA[<p>Yeah, I had this issue with them. Considering they are still doing this, I canceled my account with them. I like my money to stay with me, thank you.</p>
<p>Moved to another carrier, and have had no problems.</p> <p><a href="n/a">ViperBorg</a></p>]]></description>
			<dc:creator><![CDATA[ViperBorg]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5099249]]></guid>
		    <pubDate><![CDATA[Wed, 09 Apr 2008 10:12:51 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5097595]]></link>
										
		    <description><![CDATA[<P>Sprint isn't the only one using systems like this. I recently had a call from 'fraud prevention' from one of my credit card companies and they asked similar questions. One was which car did I have a car loan on (easy to figure out if you snooped around my house, since I only have one car). Also a list of previous addresses I lived at (again, if you know my car, you might figure this out since I have a sticker on the back from the dealer which is in another state, which was one of the choices).</P> <p>yargrnhoj</p>]]></description>
			<dc:creator><![CDATA[yargrnhoj]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5097595]]></guid>
		    <pubDate><![CDATA[Wed, 09 Apr 2008 07:43:24 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5095813]]></link>
										
		    <description><![CDATA[<P>I am spring customer. I noticed that this week when I logged on they reqquired me to add an authorization number that they sent to my phone, in order to complete my log on.</P> <p>bossco</p>]]></description>
			<dc:creator><![CDATA[bossco]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5095813]]></guid>
		    <pubDate><![CDATA[Wed, 09 Apr 2008 00:48:13 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5095155]]></link>
										
		    <description><![CDATA[<P>All of the above, plus...what a pain in the ass to actually sign up for account access. Now I have a username, password and a PIN to use, plus they'll send me a bunch of emails? And, frankly, what a shitty looking page once I (finally) got in...</P>
<P>The countdown to May 25th (Sprint contract expiration) is on...</P>
<P>Oh, fun. Since they've upgraded me to the new billing system, I can't pay my bill online until after my next billing cycle. So, pay a late fee then or pay a fee to pay my bill at a Sprint store? Sons of bitches!</P> <p>tkerugger</p>]]></description>
			<dc:creator><![CDATA[tkerugger]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5095155]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 23:50:41 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5093840]]></link>
										
		    <description><![CDATA[<p>This is inane. I'm glad I'm no longer a Nextel customer (everything sucked after the merger), but this system is inanely bad. Heads should roll over this.</p> <p>coopjust</p>]]></description>
			<dc:creator><![CDATA[coopjust]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5093840]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 22:13:19 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5092935]]></link>
										
		    <description><![CDATA[<P>Aren't these questions based on public records? So if they're public, even if you can't guess the answers, I'm sure you can look them up...</P> <p>cascascas</p>]]></description>
			<dc:creator><![CDATA[cascascas]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5092935]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 21:09:07 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5092251]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5091509">topeka</a>: Forbes has Sprint listed in there "Hall of Shame."  I had a Sprint account from Jan of 02 until July of 07.  The company went to crap after they joined with Nextel.  As far as the online services; well, that was an absolute nightmare.  I had several phone hardware problems, which they would not address.  I had service issues which never got resolved but the final insult was when I was billed for their "media package."  It was offered and I told the CSR at least 10 times that I did not want it.  But I got billed for it anyway.  When I dropped Sprint last year the supervisor that the CSR connected me with did everything but beg me to stay.  I will never, ever use Sprint again.</p> <p>newfenoix</p>]]></description>
			<dc:creator><![CDATA[newfenoix]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5092251]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 20:17:52 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5091509]]></link>
										
		    <description><![CDATA[<p>www.sprint.com website is unavailable at least 50% of the time.  When you call customer service, you get bad customer service or get hung up on/disconnected, or placed on hold forever.  No one will take the time to listen to you, resolve your issues completely and correctly.  Billing adjustments are  temporary for one day only, then you have to call in every month to adjust the same bill.  There are many managers and supervisors who will talk to you, however, they do not resolve the issues.  The bad customer service agents and bad managers outnumber the good agents and supervisors.  Agents are rushed to get through their phone calls and do not resolve customer's problems.  Sprint customer service and management are the worst in the telecom industry.</p> <p>topeka</p>]]></description>
			<dc:creator><![CDATA[topeka]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5091509]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 19:28:50 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5091205]]></link>
										
		    <description><![CDATA[<p>"Currently, we are not aware of any instances of fraud occurring through the question and answer scenario that you've described..."</p>
<p>Yeah, I'm sure that's true. It's called "plausible deniability." You don't put a system in place to track something you don't want to know about, so you can say you were never aware of it.</p>
<p>Great job, Sprint!</p> <p>Seth_Went_to_the_Bank</p>]]></description>
			<dc:creator><![CDATA[Seth_Went_to_the_Bank]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5091205]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 19:08:39 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5091053]]></link>
										
		    <description><![CDATA[<p>this does not make me feel safe....thanks sprint</p> <p>stephenjames716</p>]]></description>
			<dc:creator><![CDATA[stephenjames716]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5091053]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 19:00:06 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5090736]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5087771">K-Bo</a>: She is new. Only 4 posts since February.</p> <p><a href="n/a">cde</a></p>]]></description>
			<dc:creator><![CDATA[cde]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5090736]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 18:41:31 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5090043]]></link>
										
		    <description><![CDATA[<p>Adding insult to injury, Sprint has a typo in their GPS pitch:: ...provide superiro customer service" ... I'll say.</p> <p>mach1andy</p>]]></description>
			<dc:creator><![CDATA[mach1andy]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5090043]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 18:08:28 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089831]]></link>
										
		    <description><![CDATA[<P>Oh, and you can get someone's email address easy too. Not sure how helpful it can be, but you just need to have the person's cell number and type that into the online account sign on and click, forgot password. It then shows the email address the person used to activate the account..haha</P> <p>think4urself</p>]]></description>
			<dc:creator><![CDATA[think4urself]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089831]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:59:32 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089785]]></link>
										
		    <description><![CDATA[<P>
<BLOCKQUOTE>This anti-fraud tool has been used by numerous industries, as well as the Federal Government...to successfully prevent identity theft and fraud.</BLOCKQUOTE>
<P></P>
<P>Well, that just about explains everything, now doesn't it?</P></p> <p>NotATool</p>]]></description>
			<dc:creator><![CDATA[NotATool]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089785]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:57:21 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089778]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5089246">big keytee</a>:</p>
<p>They've caught on.  How long until that's the new industry-standard catchphrase?</p> <p>TechnoDestructo</p>]]></description>
			<dc:creator><![CDATA[TechnoDestructo]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089778]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:57:00 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089677]]></link>
										
		    <description><![CDATA[<p>Oops, that should say 111111...</p> <p>dragonfire81</p>]]></description>
			<dc:creator><![CDATA[dragonfire81]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089677]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:52:32 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089647]]></link>
										
		    <description><![CDATA[<p>I'm a former Sprint rep, I worked with this "3 questions" system numerous times.</p>
<p>I was shocked at the number of times I was able to access an account by simply guessing the answers. Fortunately I am an ethical person, but if I wasn't I could've done a LOT of damage very easily.</p>
<p>In every question pertaining to cars, it was always three Luxury models plus one typical one (Peugeot, Porsche, Ferrari and Ford for example) which made them stupidly easy to guess.</p>
<p>In addition the "none of the above" answer for "which properties have you owned?" was correct 99% of the time.</p>
<p>On top of that, one thing the article does not mention is that you are only required to answer TWO of the three questions correctly to gain access to an account. The system won't tell you which ones were right and wrong, but you need only answer TWO of three to get access.</p>
<p>This new process is more trouble than it's worth if you ask me and I'd like to find the person who came up with it and give him a good punch to the head.</p>
<p>But don't blame Sprint for all of this, some people truly don't give a crap about the security on their accounts. When asking customers to setup a 6-digit pin number most just wanted to set it to 1111111 or 123456. Pretty secure huh?</p> <p>dragonfire81</p>]]></description>
			<dc:creator><![CDATA[dragonfire81]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089647]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:51:04 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5089246]]></link>
										
		    <description><![CDATA[<p>hey wait, they did not take the matter seriously!  They only said it was a "top priority."</p>
<p>"Customer privacy is a top priority and we appreciate the Consumerist bringing this matter to our attention."</p> <p><a href="http://">big keytee</a></p>]]></description>
			<dc:creator><![CDATA[big keytee]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5089246]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:35:22 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5088626]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5087771">K-Bo</a>: EXACTLY! I didn't want to put it in the comments either, but there it is.  Thanks for the back-up, K-Bo!</p> <p>FightOnTrojans</p>]]></description>
			<dc:creator><![CDATA[FightOnTrojans]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5088626]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 17:12:40 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087771]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5087306">pillow_fight_girl</a>: New around here? Many commenters will hang you from the rafters for admitting something like an overdue account. I wouldn't want the fact I have an overdue account published here.</p> <p>K-Bo</p>]]></description>
			<dc:creator><![CDATA[K-Bo]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087771]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:42:42 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087697]]></link>
										
		    <description><![CDATA[<P>This was the email I got once I re-registered my phone</P>
<P><span class="longWord" title="------------------------------------">------------------------------------...</span>-<BR>Phone Number: **********<BR>IMEI or SIM ID: **********</P>
<P>The Phone Number and IMEI/SIM ID (listed above) that you provided to us during My Sprint registration process has been registered by another Nextel subscriber.If you have not changed cell phones recently or believe you have received this message in error, please contact Customer Care at 1-800-639-6111.</P>
<P>Thank you.</P>
<P>This email has been automatically generated. Please do not reply to this message.<BR><span class="longWord" title="------------------------------------">------------------------------------...</span>-</P> <p>midwestkel</p>]]></description>
			<dc:creator><![CDATA[midwestkel]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087697]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:40:12 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087306]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5086837">FightOnTrojans</a>:</p>
<p>Oh, so what - the account is PAST DUE.  Who cares?</p> <p>pillow_fight_girl</p>]]></description>
			<dc:creator><![CDATA[pillow_fight_girl]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087306]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:27:53 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087123]]></link>
										
		    <description><![CDATA[<p>even if you are a determined idiot, you can get in via brute force in 125 tries or less (5*5*5).</p>
<p>But the offered answers make it very easy to narrow down.</p> <p>unklegwar</p>]]></description>
			<dc:creator><![CDATA[unklegwar]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087123]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:22:26 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087083]]></link>
										
		    <description><![CDATA[<p>I actually like one of the security features that Bank of America recently added to their website.  When you want to log in you not only provide your account number &amp; PIN but you have to click on a button that will send a text message containing a random 6 digit number to your cell phone.  You also have to enter that number into the website to log in.  The number only works once and is active for only 10 minutes.  The chances of a scammer grabbing my account number, PIN, AND that text message sent to my cell phone, and logging into the site before I do is virtually non-existant.</p> <p>IphtashuFitz</p>]]></description>
			<dc:creator><![CDATA[IphtashuFitz]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087083]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:21:06 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5087037]]></link>
										
		    <description><![CDATA[<P>Ok, I have already registered with Sprint's online account and I just did it again doing this method. It even told me the answer to my secret question and now my other user name is gone but I have full access with the new user name. So even if someone is already registered they still can have this happen! I am shocked!!!!!</P> <p>midwestkel</p>]]></description>
			<dc:creator><![CDATA[midwestkel]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5087037]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:19:55 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5086837]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5083742">Ben Popken</a>: Ok, but you still haven't addressed something else.  At the "Welcome back to My Sprint" screen grab, under the blacked out account number in the upper left corner, there's a bit of info there that should be blacked out as it is slightly embarrassing (IMO).  Look for the red triangle with the exclamation point.</p> <p>FightOnTrojans</p>]]></description>
			<dc:creator><![CDATA[FightOnTrojans]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5086837]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:13:58 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5086797]]></link>
										
		    <description><![CDATA[<p>can we possibly hijack every sprint account in existence and cancel walkie talkie service permanently? No more "BADEEP!".</p> <p>unklegwar</p>]]></description>
			<dc:creator><![CDATA[unklegwar]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5086797]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:12:45 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5086724]]></link>
										
		    <description><![CDATA[<p>Oooh! It was "used by the federal government". Oh great!</p>
<p>And it says something about Katrina. I'm sure this had a hand in THAT mess of fraud as well.</p> <p>unklegwar</p>]]></description>
			<dc:creator><![CDATA[unklegwar]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5086724]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 16:11:26 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085882]]></link>
										
		    <description><![CDATA[<p>I nearly got into someone else's account doing this, I now know their pin number and their security question. <br>
It won't let me progress further to register their account, I guess I have to use their email and their correct last name in order to do it.</p>
<p>Still, it's sad that I got this far, and I totally guessed on every question.</p> <p><a href="n/a">NigerianScammer</a></p>]]></description>
			<dc:creator><![CDATA[NigerianScammer]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085882]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:45:41 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085725]]></link>
										
		    <description><![CDATA[<P>I can't wait to get away from sprint</P> <p><a href="n/a">KD17</a></p>]]></description>
			<dc:creator><![CDATA[KD17]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085725]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:40:03 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085520]]></link>
										
		    <description><![CDATA[<p>I'm a Sprint customer.</p>
<p>I've just Emailed the entire marketing team of sprint highlighting this post.</p>
<p>If you are a Sprint customer I urge you to do the same.</p>
<p>Let's make sure these guys address this security hole.</p>
<p>You can find Marketing Emails here:<br>
<a href="http://www2.sprint.com/mr/cda_mcList.do">[www2.sprint.com]</a></p>
<p>I suggest sending it to all of them.</p> <p>opticnrv</p>]]></description>
			<dc:creator><![CDATA[opticnrv]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085520]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:32:53 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085209]]></link>
										
		    <description><![CDATA[<p>Wow. Good work, guys.</p> <p><a href="http://unchained.nu/blog/">pengie</a></p>]]></description>
			<dc:creator><![CDATA[pengie]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085209]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:23:38 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085134]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5083350">Joseph</a>: They did remove it :P</p> <p><a href="n/a">cde</a></p>]]></description>
			<dc:creator><![CDATA[cde]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085134]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:21:01 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5085065]]></link>
										
		    <description><![CDATA[<p>I have already set up my online account with sprint, including the pin.  However, i went to sprint.com and was able to request a new pin by answering similar verification questions.  I supplied only my phone number to get to this option.</p>
<p>1: Which of the following properties have you NEVER owned?</p>
<p>All of the above is an answer.  Easily cracked considering I'm 25.  I'd have owned 3 different properties in order to qualify for one of the other answers (you can only pick one answer).</p>
<p>2: In which of the following cities have you NEVER lived or used in your address?</p>
<p>This one gets slightly tougher, but anyone with who knows me could answer this.  It also has the All of the above answer, which means in order for one of the specific cities to be correct I'd have lived in three of the others.</p>
<p>3: Which of the following people have resided with you or used the same address as you at [redacted]?</p>
<p>If someone knew me reasonably well, they'd answer this right.  If they dug through my trash, they'd answer this right.  If they guessed, they'd still have a 20% chance of hacking my account.</p>
<p>Luckily, when I try to reset the pin I get, "Due to a systems problem, we are unable to display questions that confirm your identity at this time."  So I guess I'm safe for now.  None the less, that's one of the more retarded verification system's I've ever seen.  Furthermore, why even leave this option available after I've already selected my pin?  I entered a security question of my choosing, just stick to that one Sprint.</p> <p>imsupermattt</p>]]></description>
			<dc:creator><![CDATA[imsupermattt]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5085065]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:18:55 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5084591]]></link>
										
		    <description><![CDATA[<P>I' starting to think that the paranoid nutjobs who live totally off the grid are onto something! Sheesh!</P> <p>MissTic</p>]]></description>
			<dc:creator><![CDATA[MissTic]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5084591]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 15:03:32 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5084306]]></link>
										
		    <description><![CDATA[<p>hey he COULD have a lotus. really. i mean i totally have a hot car like that.</p>
<p>*drives off in civic*</p> <p>katylostherart</p>]]></description>
			<dc:creator><![CDATA[katylostherart]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5084306]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:54:03 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5084248]]></link>
										
		    <description><![CDATA[<p>Consumerist: 1      Sprint: Sero</p> <p>Imaginary_Friend</p>]]></description>
			<dc:creator><![CDATA[Imaginary_Friend]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5084248]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:52:24 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5084185]]></link>
										
		    <description><![CDATA[<p>This is why I like security tokens/key fobs or whatever you want to call them. In order to log into the website, you need your user name, password, and this key fob which generates a new random 6 digit code every 30 seconds. Adds much more security to online banking and such transactions.</p> <p><a href="http://www.anksconsulting.com/news/">Anks329</a></p>]]></description>
			<dc:creator><![CDATA[Anks329]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5084185]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:50:40 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083786]]></link>
										
		    <description><![CDATA[<p>I'm a Sprint customer and Gary Forsee is the president of the university I attend and work at.  Do you think he still has any pull with Sprint?  I'll drop by and chew him out for you.</p> <p><a href="http://">mgy</a></p>]]></description>
			<dc:creator><![CDATA[mgy]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083786]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:37:00 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083742]]></link>
										
		    <description><![CDATA[<P>@<A href="http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083099">scoosdad</A>: Nope, Daniels is not part of his name at all. It's just what I inputted when I set up the online account access. But thanks for playing anyway.</P> <p><a href="http://www.consumerist.com">Ben Popken</a></p>]]></description>
			<dc:creator><![CDATA[Ben Popken]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083742]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:35:19 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083588]]></link>
										
		    <description><![CDATA[<p>T-Mobile sends a free text message to your phone with a PIN to activate the online access.  That seems to make sense.</p> <p>amejr999</p>]]></description>
			<dc:creator><![CDATA[amejr999]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083588]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:30:08 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083428]]></link>
										
		    <description><![CDATA[<p>just for the record... The GPS feature sends a text to the phone you're trying to locate every time you use the service.</p> <p>bugout99</p>]]></description>
			<dc:creator><![CDATA[bugout99]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083428]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:24:24 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083350]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5081898">cde</a>: Now all they need to do is take the link to the original image with the account number down too :).</p> <p><a href="http://www.vroomtrap.com">Vroomtrap</a></p>]]></description>
			<dc:creator><![CDATA[Vroomtrap]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083350]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:22:08 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083198]]></link>
										
		    <description><![CDATA[<p>If only the took the issue seriously...</p> <p><a href="http://thedrunkenblog.com">rbf2000</a></p>]]></description>
			<dc:creator><![CDATA[rbf2000]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083198]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:17:06 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083103]]></link>
										
		    <description><![CDATA[<P>I hate these questions. "What is your nephew's name." "What kind of car do you drive" (I have neither). Why can't I just type in a goddam password?</P>
<P>Some sites make you remember a picture of a puppy to log in, and you can't check your Chase account without registering on that computer.</P>
<P>hate it hate it hate it.</P> <p>jamesdenver</p>]]></description>
			<dc:creator><![CDATA[jamesdenver]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083103]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:13:58 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083099]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5082810">Ben Popken</a>: Ah, Nathan Daniels! LOL</p> <p>scoosdad</p>]]></description>
			<dc:creator><![CDATA[scoosdad]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083099]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:13:51 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5083006]]></link>
										
		    <description><![CDATA[<P>Well, interesting. But sprint sends a text message to the phone that is being tracked, so the user would have a heads up.</P> <p>mikesfree</p>]]></description>
			<dc:creator><![CDATA[mikesfree]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5083006]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:10:50 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082810]]></link>
										
		    <description><![CDATA[<P>@<A href="http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082699">scoosdad</A>: Guess what, his name is Nathan, not Dan.</P> <p><a href="http://www.consumerist.com">Ben Popken</a></p>]]></description>
			<dc:creator><![CDATA[Ben Popken]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082810]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:05:35 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082787]]></link>
										
		    <description><![CDATA[<p>Sprint is in the process of converting accounts over to a pin code system that is good security.  But for the millions of accounts that are not converted yet, all you need is the last four of the customer's social security number and their name and address and you can pretty much do what you want including change of address and order phones.</p> <p>deepsprint</p>]]></description>
			<dc:creator><![CDATA[deepsprint]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082787]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:05:01 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082767]]></link>
										
		    <description><![CDATA[<p>I actually just tried this for my dad's Blackberry, but it didn't work.</p> <p>shorty63136</p>]]></description>
			<dc:creator><![CDATA[shorty63136]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082767]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:04:21 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082699]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5082107">FightOnTrojans</a>: Yeah and Dan's full name appears all over those screen grabs too.  No point in blacking it out on the form when it appears elsewhere on just about every screen that was shown.</p> <p>scoosdad</p>]]></description>
			<dc:creator><![CDATA[scoosdad]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082699]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 14:02:13 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082601]]></link>
										
		    <description><![CDATA[<P>It might have been more useful to see what would happen if even only one question was answered incorrectly: would that trigger the account being locked? Ben made some intelligent guesses based on previous knowledge and luck. The answer for the type of vehicle, for instance, could easily have been "None of the above." Would that incorrect answer lock the account?</P> <p>FooKoo</p>]]></description>
			<dc:creator><![CDATA[FooKoo]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082601]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:59:27 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082446]]></link>
										
		    <description><![CDATA[<P>I went through this this weekend with my Sprint account. This identification process is definately prone to error. Not only can someone pretend to be you, but some of the questions they asked me made me scratch my head. I got a similar question to the who's shared your address one above. But in my case it was which of the following hadn't shared an address with you. The answers were a misspelling of my name, the person I sold my old house too a couple of years ago, the person I had bought that house from 10 years ago, and some name I didn't recognize. Since the house I live in now has had several owners before me the unknown name could have been one of those, I wasn't sure what the "correct" answer was. None of these people had ever lived in the house with me at the same time, its just lucky I had a good enough memory to recognize names from the closing paperwork. I eventually went with the misspelling, since it wasn't one I'd seen on any mail sent to me before. And they let me in. So maybe the correct answer is always pick the misspelled name.</P> <p>Bramble73</p>]]></description>
			<dc:creator><![CDATA[Bramble73]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082446]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:53:13 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082332]]></link>
										
		    <description><![CDATA[<p>@<a href="#c5082107">FightOnTrojans</a>: ya know what's funny? I didn't notice it the first time I read through the post either.</p>
<p>Sorta funny that the consumerist accidentally gave out an acct number while trying to point out a security flaw with sprint.</p> <p>What The Geek</p>]]></description>
			<dc:creator><![CDATA[What The Geek]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082332]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:50:20 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082325]]></link>
										
		    <description><![CDATA[<p>Given the passwords people come up with, it might be easier to guess their current password on a site for someone you know.  Once you have one password, you likely have all of their online passwords.  So, while I appreciate the fact that Sprint is hardly making a huge barrier to breaking into an account, I am still convinced that the login/password system used on most sites is the first problem.</p>
<p>I have often wondered if some web developers try using the passwords users set up for their web site on other sites to see if they are one of the majority of people that use the same password on all web sites.</p>
<p>In any case, I hope Sprint improves their security, but I will not hold this against them.  Their ridiculous customer service, on the other hand, is unforgivable.</p> <p><a href="http://www.sanitypages.com/">Monty</a></p>]]></description>
			<dc:creator><![CDATA[Monty]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082325]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:50:11 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082261]]></link>
										
		    <description><![CDATA[<p>I think that name is supposed to be "Jerry Stefl III" (as in, "The Third"), but the automatic formatting screwed it up.</p> <p>rmz</p>]]></description>
			<dc:creator><![CDATA[rmz]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082261]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:48:06 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082184]]></link>
										
		    <description><![CDATA[<P>I love Sprint!</P> <p>Pro-Pain</p>]]></description>
			<dc:creator><![CDATA[Pro-Pain]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082184]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:46:00 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082107]]></link>
										
		    <description><![CDATA[<p>Yah, y'all forgot to black out an account number where it says "Change Billing Information."</p>
<p>Also, you might want to black out that red text at the beginning.  I'm pretty sure Dan doesn't want that little bit of personal business broadcast out to the Consumerist community and beyond.</p> <p>FightOnTrojans</p>]]></description>
			<dc:creator><![CDATA[FightOnTrojans]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082107]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:43:39 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5082024]]></link>
										
		    <description><![CDATA[<P>I have a Sprint account and they have been sending out postcards for months now requesting people to activate their online accounts. Yes, even I put it off for too long... Once you establish your account you should be safe, but the people who neglect to do this for whatever reason are the ones at risk. You'd think it might make more sense for Sprint to send a temporary PIN to the phone first so that there's less ability for random people to weasel their way into an account so easily.</P> <p>GiltProto</p>]]></description>
			<dc:creator><![CDATA[GiltProto]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5082024]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:41:15 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5081921]]></link>
										
		    <description><![CDATA[<P>This does not surprise me. That new CEO of Sprint doesn't seem to be doing anything new or useful. Sprint to this day has NO security in place.</P>
<P>You can open up the phone book, pick a name and address, randommly creat a SSN, and get a phone/plan via a 3rd party retailer.</P>
<P>You pay NOTHING upfront. The person's name you used and/or the SSN number you provided (if it's real) would then get a bill in the mail some months later.</P>
<P>In fact, if the SSN is invalid...they will use the name provided...and apply that SSN to the bill (provided you were EVER a Sprint/Nextel customer).</P>
<P>Happened to me twice. TWICE. Got a bill...told 'em it was fraud. Sprint said okay...taken care of.</P>
<P>Month later...another bill...with a different number.</P>
<P>Idiots. They let someone open an account AGAIN in my name even though it was done fraudulently a month prior.</P>
<P>Fraud department at Sprint is aware of this, and as of last summer...still done nothing about it.</P>
<P>I paid nothing and nothing was put against me on my credit report...but Sprint can still burn in hell.</P> <p>ConsumerAdvocacy1010</p>]]></description>
			<dc:creator><![CDATA[ConsumerAdvocacy1010]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5081921]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:38:32 EDT]]></pubDate>
		</item>
		<item>
		    <title><![CDATA[Flawed Security Lets Sprint Accounts Get Easily Hijacked]]></title>
		    <link><![CDATA[http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked#c5081510]]></link>
										
		    <description><![CDATA[<p>well damn - that's just weak. With a little bit of social engineering, the world opens up to you in ways it just shouldn't.</p>
<p>You know what else is weak?<br>
This:</p>
<p><a href="http://www.eggxpert.com/forums/thread/301228.aspx">[www.eggxpert.com]</a></p>
<p>I actually sent that to the consumerist earlier today, but I fear I may have gotten lost in a spam filter or something of that nature.</p> <p>What The Geek</p>]]></description>
			<dc:creator><![CDATA[What The Geek]]></dc:creator>
		    <guid isPermaLink="false"><![CDATA[31:376845:c5081510]]></guid>
		    <pubDate><![CDATA[Tue, 08 Apr 2008 13:25:58 EDT]]></pubDate>
		</item>
	</channel>
</rss>