<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Pinger.com instant voice messaging for your mobile</title>
	<atom:link href="http://www.mobileindustryreview.com/2006/08/pingercom_insta.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.mobileindustryreview.com/2006/08/pingercom_insta.html</link>
	<description>Daily news and opinion for 250,000 industry executives and mobile fanatics</description>
	<lastBuildDate>Tue, 14 Feb 2012 22:09:00 +0100</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: CallerID Spoofy</title>
		<link>http://www.mobileindustryreview.com/2006/08/pingercom_insta.html/comment-page-1#comment-15060</link>
		<dc:creator>CallerID Spoofy</dc:creator>
		<pubDate>Thu, 21 Dec 2006 18:27:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.smstextnews.co.uk/2006/08/pingercom_instant_voice_messaging_for_your_mobile.html#comment-15060</guid>
		<description>Do you know the companies PINGER and SNAPVINE?

Pinger and Snapvine are highly INSECURE!!!!

What this means:  I can break into your Pinger and Snapvine phone accounts.  I can listen to your messages.  I can send out messages as you.  

How do I do this?  Easy.  I mask / spoof CALLER ID / ANI.  Anyone can do this, amateur hacks, etc.

Well, there are others, but suffice to say that these companies are doing new things with social networking sites and phones that help to connect people.

The problem is that these companies have a scalability problem based on inbound calling.

You see, if you have hundreds of thousands or millions of users, you canâ€™t give everyone a unique dial in phone number.

SECURITY PROBLEM

What these companies have done is based user identification on Caller ID / ANI â€“ meaning that you call their service, and their systems recognize your phone via Caller ID.

The problem is that Caller ID is highly insecure and can be faked.

The problem that these â€œdial inâ€ companies are trying to solve is one of scalability.  They simply cannot have enough dial in numbers for each user.

Therefore, they have architected a way to recognize each caller by Caller ID and to base the entire user authentication system on this insecure method.

This can easily be hacked.

SOLUTION

The solution is funny â€“ both Pinger and SnapVine make you enter in a PIN CODE when you dial in without validating your phone.

After you validate your phone, you no longer need to enter the PIN CODE.

So in effect, when you validate your phone, you make your account INSECURE.

What Pinger and SnapVine need to do is always require the PIN CODE.</description>
		<content:encoded><![CDATA[<p>Do you know the companies PINGER and SNAPVINE?</p>
<p>Pinger and Snapvine are highly INSECURE!!!!</p>
<p>What this means:  I can break into your Pinger and Snapvine phone accounts.  I can listen to your messages.  I can send out messages as you.  </p>
<p>How do I do this?  Easy.  I mask / spoof CALLER ID / ANI.  Anyone can do this, amateur hacks, etc.</p>
<p>Well, there are others, but suffice to say that these companies are doing new things with social networking sites and phones that help to connect people.</p>
<p>The problem is that these companies have a scalability problem based on inbound calling.</p>
<p>You see, if you have hundreds of thousands or millions of users, you canâ€™t give everyone a unique dial in phone number.</p>
<p>SECURITY PROBLEM</p>
<p>What these companies have done is based user identification on Caller ID / ANI â€“ meaning that you call their service, and their systems recognize your phone via Caller ID.</p>
<p>The problem is that Caller ID is highly insecure and can be faked.</p>
<p>The problem that these â€œdial inâ€ companies are trying to solve is one of scalability.  They simply cannot have enough dial in numbers for each user.</p>
<p>Therefore, they have architected a way to recognize each caller by Caller ID and to base the entire user authentication system on this insecure method.</p>
<p>This can easily be hacked.</p>
<p>SOLUTION</p>
<p>The solution is funny â€“ both Pinger and SnapVine make you enter in a PIN CODE when you dial in without validating your phone.</p>
<p>After you validate your phone, you no longer need to enter the PIN CODE.</p>
<p>So in effect, when you validate your phone, you make your account INSECURE.</p>
<p>What Pinger and SnapVine need to do is always require the PIN CODE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peter</title>
		<link>http://www.mobileindustryreview.com/2006/08/pingercom_insta.html/comment-page-1#comment-7455</link>
		<dc:creator>peter</dc:creator>
		<pubDate>Mon, 13 Nov 2006 02:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.smstextnews.co.uk/2006/08/pingercom_instant_voice_messaging_for_your_mobile.html#comment-7455</guid>
		<description>does gotvoice.com offer the same service? I know it will retrieve voicemail&#039;s and send them to my e-mail which is way cool, but will it do the reverse like pinger will?</description>
		<content:encoded><![CDATA[<p>does gotvoice.com offer the same service? I know it will retrieve voicemail&#8217;s and send them to my e-mail which is way cool, but will it do the reverse like pinger will?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jonb</title>
		<link>http://www.mobileindustryreview.com/2006/08/pingercom_insta.html/comment-page-1#comment-1439</link>
		<dc:creator>jonb</dc:creator>
		<pubDate>Tue, 17 Oct 2006 13:41:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.smstextnews.co.uk/2006/08/pingercom_instant_voice_messaging_for_your_mobile.html#comment-1439</guid>
		<description>Good point Rich.  Only time I can see that it has more than MMS is if youre abroad and dont want to pay roaming charges, or flat battery I guess.</description>
		<content:encoded><![CDATA[<p>Good point Rich.  Only time I can see that it has more than MMS is if youre abroad and dont want to pay roaming charges, or flat battery I guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rich</title>
		<link>http://www.mobileindustryreview.com/2006/08/pingercom_insta.html/comment-page-1#comment-465</link>
		<dc:creator>rich</dc:creator>
		<pubDate>Wed, 30 Aug 2006 13:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.smstextnews.co.uk/2006/08/pingercom_instant_voice_messaging_for_your_mobile.html#comment-465</guid>
		<description>Doesnt voice mms work the same way?  I can record a voice message and mms it to a friend now. Yes theres no web interface but is there something else Im missing. 
</description>
		<content:encoded><![CDATA[<p>Doesnt voice mms work the same way?  I can record a voice message and mms it to a friend now. Yes theres no web interface but is there something else Im missing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

