back to article Identity protection outfit LifeLock picked, popped

Security researchers Eric Taylor and Blake Welsh have disclosed a cross-site scripting vulnerability in US identity protection company LifeLock. The duo from US outfit Cinder say the vulnerability allows attackers to target the company's three million users with malware and phishing attacks, session jacking, among other acts …

  1. Mark 85 Silver badge

    Irony alert maybe?

    Am I the only one who's chuckling at the irony of this?* After all their ads and fear mongering... they were insecure also.

    * Given the insecurity revelations of late, I might also be either cynical or jaded...

    1. jake Silver badge

      @ Mark 85 (was: Re: Irony alert maybe?)

      "I might also be either cynical or jaded ... "

      Me, I'm both. Hazard of 40ish years in the business ;-)

  2. JP19


    Never heard of them so looked at the site - some people actually pay 10 bucks a month for that crap?

    I can get a similar identity theft alert service for free with one of my credit cards. I didn't think it was worth the bother of going through the registration process never mind 10 bucks a month.

    1. Peter Simpson 1

      Re: Lol

      I believe their CEO is aware of the attitude of people like you.

      So, in a bid to demonstrate how well his offering worked, he publicised his own social security number.

      ...and his identity was promptly stolen.

  3. jake Silver badge

    "picked, popped"

    Shirley you mean "cracked"?

    Again, I have an honest question: Where did the "popped" meme originate?

    1. Tony Haines

      Re: "picked, popped"

      I don't know, but I think weasels were involved.

    2. ItsNotMe

      Re: "picked, popped"

      Shirley you mean "cracked"?

      @jake...I thought I told you to NEVER call me Shirley!!

  4. thexfile

    What a bunch of L-holes.

