https://null.pink/ Freedom Mobile's 4 digit password limit It has come to my attention that Freedom Mobile, a company currently under investigation by the Competition Bureau, has a security vulnerability that affects all of its customers and their contacts. This vulnerability was brought to the attention of Freedom Mobile in February 2018, but the company has refused to take action to implement the suggested fixes and has instead chosen to continue operating without properly addressing the issue. The severity of this vulnerability cannot be overstated, and we urge Freedom Mobile to prioritize the safety and security of its customers by taking immediate steps to fix this issue. The security vulnerability at Freedom Mobile is alarmingly simple to exploit. Customers' accounts are protected by a four and five-digit PIN, but there are no limits on the number of attempts an attacker can make to guess the correct PIN. The four digit PIN can be guessed infinitely. The five-digit PIN allows for 10 attempts before resetting to a new five-digit PIN, but this is still insufficient to protect against determined attackers. As a customer or reseller of Freedom Mobile, it is currently not possible to opt out of this system or take any preventative measures to protect against unauthorized access. This leaves all Freedom Mobile accounts vulnerable to compromise. About 1800 days ago, I created a proof-of-concept (PoC) that demonstrated the ease with which an attacker could exploit the security vulnerability at Freedom Mobile. The PoC was designed to guess four-digit PINs and specifically focused on 1234 (Top PIN for iPhone users). Despite its simplicity, the PoC was able to override rate limits(which don't exist) and successfully guess the PIN for a large number of accounts within a short period of time. No records were kept and no accounts were accessed during this demonstration, and the PoC was promptly deleted and all knowledge of the affected accounts was erased to ensure the security of those accounts. Freedom Mobile(Shaw Communications Inc.)'s vice-president of external affairs, Chethan Lakshman: ----------------------------------------------------------------- "The security measures we have in place cannot protect against guessing common passwords. We continue to strongly encourage our customers to use unique PIN numbers that are not easy to guess, and to change their PINs frequently to best protect their personal account information." If an attacker is able to successfully log in to a Freedom Mobile account, they will have access to a wide range of sensitive information, including financial details, full names, SIN numbers, email addresses, phone and SMS histories, and the ability to perform SIM swaps without human interaction. In addition, the attacker can use the account's PIN(easier to obtain) to access support channels for a more direct approach to accessing sensitive information. A review of the Freedom Mobile subreddit reveals a number of reports from users experiencing login issues over an extended period of time. This information suggests that the security vulnerability may be actively being exploited, highlighting the urgent need for Freedom Mobile to take action to fix the issue and protect its customers. I have made efforts to bring this information to the attention of the Government of Canada in a secure manner, and I am committed to ensuring that it is properly addressed. If you are a Freedom Mobile customer, I recommend closing your account as a precautionary measure to protect your personal information.