29-07-2016 22:41 via cio.com

Black Hat security conference trims insecure features from its mobile app

Black Hat has disabled features of its mobile application because attackers could have logged in as legitimate attendees, posted messages in their names and spied on the messages they sent.
The problem was discovered by mobile security vendor Lookout who detail the problem in a blog that says the method of registration and password resets were flawed.
“[W]e've removed user-to-user messaging functionality and activity feed updates out of an abundance of caution,” a spokesperson for t
Read more »