Uber Said to Ignore Bug in Its Two-Factor Authentication

Advertisement
By Indo-Asian News Service | Updated: 22 January 2018 17:12 IST

Ride-hailing app Uber has reportedly ignored a security flaw -- discovered by a New Delhi-based security researcher -- that can allow an attacker to hack into user accounts via bypassing its two-factor authentication feature.

"Two-factor authentication is a vital part of protecting online accounts that adds a second layer of security on top of your username and password -- which can be stolen -- by sending a code by text message to your phone which only you would have access to," tech website ZDNet reported late on Sunday.

"That two-factor code can be bypassed, making the second layer of security protection effectively useless," security researcher Karan Saini was quoted as saying by ZDNet.

Advertisement

The security bug works by exploiting a weakness in how the app authenticates a user when they log in to the platform, thereby letting the user log in to an account and easily defeat the two-factor prompt, without entering the correct code.

Advertisement

Uber reportedly said the security bug "is not a particularly severe" issue.

"This isn't a particularly severe report and is likely expected behaviour," Rob Fletcher, Security Engineering Manager at Uber, said in his correspondence with Saini about the bug report.

Advertisement

Uber began testing two-factor authentication on its systems in 2015 but the company has yet to widely push the security feature to its users.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Uber, Apps, India
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Poco X8 Pro Series Display, Chipset, Battery Details Leak Online
  3. WhatsApp's New Feature Allows New Members to View Past Group Messages
  4. Nothing Confirms the Upcoming Phone 4a Series Will Sport a Snapdragon Chip
  5. Vivo V70 Elite, V70 Launched in India With 6,500mAh Batteries: See Prices
  6. New JioHotstar Feature: Use ChatGPT to Discover Live Sports and Shows
  7. MakeMyTrip Will Add These OpenAI-Powered Features to Its Myra Trip Assistant
  8. First User Report of iPhone Air's C1X Modem Failure Surfaces Online
  9. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  10. Tu Meri Main Tera Main Tera Tu Meri Streaming Online: See Details
  1. Sony to Shut Down Demon's Souls Remake Developer Bluepoint Games in March
  2. Amazfit T-Rex Ultra 2 Launched With BioTracker 6.0 Sensor, 1.5-Inch AMOLED Display
  3. iPhone Air User Complains of C1X Modem Failure, Claims Mobile Diagnostics Suggests Hardware Issue
  4. Redmi Buds 8 Active Price, Design, Key Features Leaked Ahead of Anticipated Launch
  5. Samsung's One UI 8.5 Update Will Introduce Upgraded Bixby With Natural Voice Commands, Real-Time Web Access
  6. Poco X8 Pro and Poco X8 Pro Max to Feature 1.5K OLED Screens, 100W Charging Support, Tipster Claims
  7. WhatsApp Rolls Out Group Message History Feature for Easy Onboarding of New Members
  8. Lunar Surface Is Cracking as New Tectonic Map Reveals Recent Ridges Stretching Across the Moon, Study Suggests
  9. Nothing Phone 4a Series Confirmed to Launch With Snapdragon Chipsets: Expected Specifications, Features
  10. Tu Meri Main Tera Main Tera Tu Meri Out on OTT: Where to Watch Kartik Aaryan, Ananya Panday’s Rom-Com?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.